MalwareQuinn

QakbotIOCs_Oct192020

Oct 19th, 2020
11,789
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.48 KB | None | 0 0
  1. Qakbot spun up 2 different excel docs for today's tr01. Today's app.any will have both docs executed. Additionally, a VT link will be supplied with 99 docs that I caught.
  2.  
  3. VT archive: https://www.virustotal.com/gui/file/b8973717c17700847fcb71474c67f45a86b08b77dbe86c1aca3f0c5797a13e3e/detection
  4. Sandbox: https://app.any.run/tasks/edba1a6d-7d59-448f-a8a8-e22b9ceee830/
  5.  
  6. Urls:
  7. https://armaturenregister.nl/18.bat
  8. https://www.notamuzikaletleri.com/19.gif
  9. https://giovannigameria.com/r19.bat
  10. https://bjmerchandising.com.au/1610.gif
  11. https://procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg
  12. https://procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg
  13.  
  14. IPs:
  15. 73.228.1.246:443
  16. 74.109.219.145:443
  17. 76.111.128.194:443
  18. 90.175.88.99:2222
  19. 108.191.28.158:443
  20. 68.225.60.77:443
  21. 75.136.40.155:443
  22. 5.193.181.221:2078
  23. 72.204.242.138:20
  24. 118.160.162.234:443
  25. 68.14.210.246:22
  26. 148.101.74.12:443
  27. 74.222.204.82:443
  28. 96.30.198.161:443
  29. 140.82.27.132:443
  30. 2.50.131.64:443
  31. 45.32.155.12:995
  32. 45.63.104.123:443
  33. 45.32.165.134:443
  34. 217.162.149.212:443
  35. 207.246.70.216:443
  36. 200.75.136.78:443
  37. 187.155.58.60:443
  38. 166.62.183.139:2078
  39. 35.134.202.234:443
  40. 67.170.137.8:443
  41. 70.45.126.135:443
  42. 173.21.10.71:2222
  43. 96.247.181.229:443
  44. 76.167.240.21:443
  45. 67.165.206.193:993
  46. 71.80.66.107:443
  47. 81.98.133.106:443
  48. 190.63.182.214:443
  49. 71.197.126.250:443
  50. 71.220.191.200:443
  51. 24.71.28.247:443
  52. 71.56.53.127:443
  53. 24.43.22.220:993
  54. 81.133.234.36:2222
  55. 69.47.239.10:443
  56. 80.195.103.146:2222
  57. 78.96.199.79:443
  58. 65.131.47.228:995
  59. 86.121.121.14:2222
  60. 96.243.35.201:443
  61. 173.70.165.101:995
  62. 80.14.209.42:2222
  63. 2.51.221.138:995
  64. 76.170.77.99:995
  65. 46.53.38.174:443
  66. 68.116.193.239:443
  67. 187.213.152.50:995
  68. 50.244.112.10:995
  69. 2.88.42.65:995
  70. 69.47.26.41:443
  71. 151.73.121.31:443
  72. 108.46.145.30:443
  73. 71.187.170.235:443
  74. 75.136.26.147:443
  75. 134.0.196.46:995
  76. 98.118.156.172:443
  77. 199.116.241.147:443
  78. 75.137.239.211:443
  79. 103.238.231.35:443
  80. 74.75.216.202:443
  81. 184.21.136.237:443
  82. 71.182.142.63:443
  83. 78.97.3.6:443
  84. 108.190.151.108:2222
  85. 85.121.42.12:995
  86. 67.6.55.77:443
  87. 141.158.47.123:443
  88. 98.240.24.57:443
  89. 68.46.142.48:995
  90. 151.205.102.42:443
  91. 172.87.134.226:443
  92. 187.213.186.154:443
  93. 72.204.242.138:443
  94. 72.240.200.181:2222
  95. 72.36.59.46:2222
  96. 24.229.150.54:995
  97. 100.4.179.64:443
  98. 190.85.91.154:443
  99. 31.215.98.218:443
  100. 47.28.131.209:443
  101. 207.255.161.8:993
  102. 207.246.75.201:443
  103. 77.159.149.74:443
  104. 45.77.193.83:443
  105. 71.19.217.23:443
  106. 86.121.215.99:443
  107. 207.255.161.8:995
  108. 184.180.157.203:2222
  109. 108.35.13.206:443
  110. 24.122.0.90:443
  111. 67.209.195.198:443
  112. 68.190.152.98:443
  113. 72.204.242.138:465
  114. 65.30.213.13:6882
  115. 188.27.178.166:443
  116. 207.255.161.8:32103
  117. 186.154.182.103:443
  118. 72.190.101.70:443
  119. 208.99.100.129:443
  120. 63.155.8.102:995
  121. 72.204.242.138:443
  122. 178.222.13.77:995
  123. 70.123.92.175:2222
  124. 108.5.33.110:443
  125. 70.168.130.172:995
  126. 45.32.154.10:443
  127. 199.247.22.145:443
  128. 80.240.26.178:443
  129. 85.204.189.105:443
  130. 102.190.183.108:443
  131. 207.255.161.8:443
  132. 66.215.32.224:443
  133. 71.28.7.23:443
  134. 86.176.25.92:2222
  135. 61.230.0.156:443
  136. 207.255.161.8:32100
  137. 41.228.59.195:443
  138. 67.60.113.253:2222
  139. 117.218.208.239:443
  140. 206.183.190.53:993
  141. 184.98.103.204:995
  142. 134.228.24.29:443
  143. 66.97.247.15:443
  144. 72.204.242.138:50001
  145. 72.204.242.138:32100
  146. 66.26.160.37:443
  147. 86.98.89.172:2222
  148. 72.82.15.220:443
  149. 24.37.178.158:443
  150. 47.44.217.98:443
  151. 72.204.242.138:995
  152. 95.179.247.224:443
  153. 172.78.30.215:443
  154. 39.36.156.196:995
  155. 24.234.86.201:995
  156. 71.163.222.203:443
  157. 72.204.242.138:53
  158. 93.149.253.201:2222
  159. 108.30.125.94:443
  160. 84.247.55.190:443
  161. 89.42.142.35:443
  162. 98.16.204.189:995
  163. 45.32.155.12:2222
  164. 72.204.242.138:32102
  165.  
Add Comment
Please, Sign In to add comment