Advertisement
G0dR4p3

Redaman_Trojan_IOCs_06-02-2019

Feb 6th, 2019
236
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. #Redaman #Trojan
  2. -----------------------
  3. 06-02-2019 IOC's
  4. -----------------------
  5. Main object- "b0b865f0fd6cea141d23cb00d6c3b909fd361f633a11c9ff7adb964288f9a745.bin.gz"
  6. sha256 27d8c78b82530e26d001d84fdd8a5a6e94d8b3c428ea29a183fc8400e20eb69d
  7. sha1 b3e352e515931d6a32e139c8dd808e2ba2581f3e
  8. md5 526b5ba068a5439c86b968ad2588f9dd
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Temp\Rar$EXa1036.1989\Çàêðûâàþùèå äîê-û ôåâðàëü.exe df86acbc23343f0634fed0c78464ba72cb7f0ad58c7b68232f349a5a68b5c7bb
  11. sha256 C:\Users\admin\AppData\Local\Temp\AB8.tmp 48f7706ea1cf48f53bcd1c14186c1e572f2e70ad6dc9277ed69d90bf025ec476
  12. DNS requests
  13. domain peername.net
  14. domain namecoin.cyphrs.com
  15. Connections
  16. ip 52.36.204.116
  17. ip 93.123.80.47
  18. ip 185.203.117.161
  19. ip 188.165.200.156
  20. HTTP/HTTPS requests
  21. url http://185.203.117.161/index.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement