Advertisement
G0dR4p3

Shade_Ransomware_IOCs_11-02-2019

Feb 11th, 2019
731
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. #Shade #Troldesh #Ransomware #Trojan
  2. ----------------------------------------
  3. 11-02-2019 IOC's
  4. ----------------------------------------
  5. Main object- "e577944c48edfc65b6f59630b0b0ac625b997f26af3d4bdbe2f534be0fff6f34.bin.gz"
  6. sha256 70b0f9b0d235d8edddaac7f5074e7273265f2335da455e1b6cd4d965ca1a4acc
  7. sha1 3aadb876abefc7269dfb450fef8349dca2aff4b5
  8. md5 864c5dfc4af43b932126ebbcc375e905
  9. Dropped executable file
  10. sha256 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\messg[1].jpg 26fec998b7b9ad941a346184b1eaaf7fc603abf8f8f96da025ba96f7021e7351
  11. sha256 C:\ProgramData\Adobe\ARM\S\618\AdobeARM.msi 2339ee197758a31ef70ea19a7a11413e08341c34d34a07a11029f8003114080f
  12. sha256 C:\ProgramData\Adobe\ARM\S\618\AdobeARMHelper.exe f9b595f657589a25f6f247b4cdd0de7f2ba0319b015d33f000728bfc11d0a1c2
  13. DNS requests
  14. domain projectmmo.ru
  15. domain equiracing.fr
  16. domain whatismyipaddress.com
  17. domain whatsmyip.net
  18. Connections
  19. ip 31.31.198.12
  20. ip 51.255.235.153
  21. ip 154.35.32.5
  22. ip 194.109.206.212
  23. ip 131.188.40.189
  24. ip 104.16.155.36
  25. ip 163.172.149.122
  26. ip 82.251.167.192
  27. ip 217.182.196.65
  28. ip 104.18.34.131
  29. HTTP/HTTPS requests
  30. url http://whatismyipaddress.com/
  31. url http://equiracing.fr/templates/rhuk_milkyway_equiracing/css/messg.jpg
  32. url http://projectmmo.ru/blog/slavneft.zakaz.zip
  33. url http://whatsmyip.net/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement