IOCs 1_7_2021

 




(1)

File Name

4f4f40b9a8984267f8bcb1d9f4ad10c76dd2e9d5461bfc9509da014c426b359f.exe

Created process

4f4f40b9a8984267f8bcb1d9f4ad10c76dd2e9d5461bfc9509da014c426b359f.exe

Connected (Ip/Dns)

Coroteblue[.]duckdns[.]org

MD5

6e67389af17b30df470ee353694d334b

SHA256

4f4f40b9a8984267f8bcb1d9f4ad10c76dd2e9d5461bfc9509da014c426b359f

Family

njRAT

 


(2)

File Name

MwGGI872VsQ4Vw.exe

Created process

MwGGI872VsQ4Vw.exe

Connected (Ip/Dns)

Dsfsdfsdfsdfsdfsff[0].ddns[.]net

MD5

3569d225fabd9c32438464f9b387ebea

SHA256

51339a3256d483db70ac04682e10dd44b5b103ed1e812b09fa763cf1fc51827e

Family

njRAT

 

(3)

File Name

Invoice..exe

Created process

Invoice..exe

Connected (Ip/Dns)

www[.]mutieudao[.]online, www[.]fluatrec[.]com, www[.]veritasfertilityandsurgery[.]com, www[.]freeagencevoyage[.]com, www[.]cn-liangyu[.]com, www[.]americanprimativeguitar[.]com, www[.]rep[.]place, www[.]homefittness[.]com, www[.]eggbeaterhub[.]xyz

MD5

a2720e17c54697f94a6fc28a3b505cfc

SHA256

c5b56bcdb7672777ac9f2ed52d73eb7645310d54d93582f48296277efa006561

Family

Formbook

 

(4)

File Name

Documents - V-21-170-090-E04.pdf.exe

Created process

Documents - V-21-170-090-E04.pdf.exe

Connected (Ip/Dns)

www[.]sat-lite[.]com

MD5

46f88471151a0c69481bfa77f60aa1ba

SHA256

3506ed727e44f3c97a0b9eb31f6c9d06d44c84fc4898e7f65d4d1cede84a2e00

Family

Formbook

 

(5)

File Name

cotización.pdf.exe

Created process

cotización.pdf.exe

Connected (Ip/Dns)

63[.]141[.]228[.]141/32[.]php/ocGTdeFq2SWdX

MD5

38a303790a8133746a7c6662615ca5bc

SHA256

bb5df503b48b02b896b19231964a2aa53e48f2f1bf4e0abadf69dc1cfe1f6427

Family

Lokibot

 

(6)

File Name

4b96dba8c6dcc5e1d17cd816f9e017fe.exe

Created process

4b96dba8c6dcc5e1d17cd816f9e017fe.exe

Connected (Ip/Dns)

185[.]110[.]190[.]5/gugufdre[.]php/NHNmTUOdS6fzz

MD5

4b96dba8c6dcc5e1d17cd816f9e017fe

SHA256

8bc25adb8d1b8d86275ab9c85cb619deae71b1694809ee9f14f11a03dd6b739a

Family

Lokibot

 

(7)

File Name

IMG.09949030049.PNG.scr

Created process

jsns.pif

Connected (Ip/Dns)

Strongodss[.]ddns[.]net

MD5

ad0c72111abc4983dc9281668fe04054

SHA256

1d8d1ed93e2bb02931e7184988ad25b149d75beaaf5c4604144aef7981352109

Family

Nanocore

 

(8)

File Name

c0e0c339e6dbbd1d1565de4da39e4925.exe

Created process

c0e0c339e6dbbd1d1565de4da39e4925.exe

Connected (Ip/Dns)

Luda[.]ydns[.]eu

MD5

c0e0c339e6dbbd1d1565de4da39e4925

SHA256

42d293cf86f774218bf7751f1001e0a57883a1c7c90c6c1e8803a061094860cf

Family

NanoCore

 

(9)

File Name

INVOICE-COVID-fdp.com

Created process

INVOICE-COVID-fdp.com

Connected (Ip/Dns)

4[.]tcp[.]ngrok[.]io

MD5

b5e438833c0851e71b590f409d4bf164

SHA256

7c6ffc841e4a737e7ed7ef534f531b71b952c082372eff2d5e65f721de4750c0

Family

Orcus RAT

 


(10)

File Name

ajhvxcgdfsd.exe

Created process

ajhvxcgdfsd.exe

Connected (Ip/Dns)

Lizzzqua[.]ac[.]ug, lizard[.]ac[.]ug

MD5

182d417728e3b8da39249e7691bdef16

SHA256

44205e4cf223ec528c507423db81ea8dce460b243e4dfa14088c5686b78590b3

Family

Vidar


(11)

File Name

ALCALINFPROVINCPDF46983638950001 ALCALINFPROVINCPDF46983638950003.exe

Created process

ALCALINFPROVINCPDF46983638950001 ALCALINFPROVINCPDF46983638950003.exe

Connected (Ip/Dns)

suiza762[.]duckdns[.]org

MD5

e222b49d8382076064c0268b0635f75b

SHA256

d70782171c4d41a10a0fb684dbe71656f1195bbaca2c8f33deb868f1ec4a40c9

Family

Remcos


(12)

File Name

FA_KLJOL40SFTHFV_01102019.doc.zip

Created process

FA_KLJOL40SFTHFV_01102019.doc.exe

Connected (Ip/Dns)

escs-sarl[.]com

MD5

fb0eb780163627a693acd46cdfcece6c

SHA256

5e6f2aeb04e0aba892350d1fdae4b6063f1500aaa28f8472f4ab7ab61e621afe

Family

Emotet


(13)

File Name

ajhvxcgdfsd.exe

Created process

ajhvxcgdfsd.exe

Connected (Ip/Dns)

Lizzzqua[.]ac[.]ug, lizard[.]ac[.]ug

MD5

182d417728e3b8da39249e7691bdef16

SHA256

44205e4cf223ec528c507423db81ea8dce460b243e4dfa14088c5686b78590b3

Family

Vidar


(14)

File Name/Url

0701_1321069402195.doc

Created process

0701_1321069402195.exe

Connected (Ip/Dns)

Raeonoran[.]com, pospvisis[.]com

MD5

8d6bb87ed6f61dd8759adea2392b21b3

SHA256

14aee46fedef47b7aad209e05e3afc76c9e197b604cf29c7e51003fbebce3afe

Family

Hancitor


(15)

File Name

C5A6211FE9AB12EB4D85BFB61E9495F5.exe

Created process

C5A6211FE9AB12EB4D85BFB61E9495F5.exe

Connected (Ip/Dns)

Netno[.]ddns[.]net

MD5

c5a6211fe9ab12eb4d85bfb61e9495f5

SHA256

cbf703cf139fbeffc482036fed72e4bcae042a92c769cbb3de5219209b56553f

Family

Netwire


(16)

File Name

3f1eb883bca3190418d1905ed4b017f4.vir

Created process

3f1eb883bca3190418d1905ed4b017f4.vir.exe

Connected (Ip/Dns)

Abemuggs[.]com/forum/viewtopic.php

MD5

3f1eb883bca3190418d1905ed4b017f4

SHA256

ac4662fd3a9989138cdd56723d590b1ae41de9b55e497368d601d9e747fa1a83

Family

Pony


If you wanna learn malware analysis you can check my YouTube channel I'm trying publish analysis of malware and some methods to analysis malwares.
Please don't forgot subscribe my channel Than you ♥  

YouTube channel 
https://www.youtube.com/channel/UCParXHaBXBmqRdHuVUg21pA


Comments

Popular posts from this blog

Sunburst Solarwinds Backdoor

Phishing Attacks 9_4_2021

Conti Ransomware