forked from executemalware/Malware-IOCs
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path2021-09-21 Squirrel Waffle IOCs
48 lines (36 loc) · 1.13 KB
/
2021-09-21 Squirrel Waffle IOCs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
THREAT IDENTIFICATION: SQUIRREL WAFFLE
SUBJECTS OBSERVED
Reused email threads
SENDERS OBSERVED
ZIP FILE DISTRIBUTION URLS
https://banyanproductosacupuntura.com/voluptates-consectetur/omnis.zip
https://banyanproductosacupuntura.com/voluptates-consectetur/documents.zip
https://panel.top-gaming.ro/omnis-doloremque/occaecati.zip
https://panel.top-gaming.ro/omnis-doloremque/documents.zip
ZIP FILE HASHES
omnis.zip
932dbef475840bd24f10fdce3943c194
occaecati.zip
3538dcb012a21941d8810ee3d1aeef57
MALDOC FILE HASHES
chart-1370132943.xls
6bdea269e62ad46ea44c6a2aa06da9f9
chart-398227237.xls
031a1d0be3b41b239ac6ea9499809120
CONTACTED DOMAINS/PAYLOAD DOWNLOAD DOMAINS
generatorulubabanu.ro
ottawaprocessservers.ca
totallybaked.ca
PAYLOAD FILE HASHES
test1.test
3a5ea4c159d47bfb5720d2eb86b1f6e0
test2.test
1f6c33771d79228f2d232c72edaeb3e7
SQUIRREL WAFFLE C2 (POST DATA)
http://arimeto.lv/Nm70oAfwB
http://gitamschool.com/oZbs0Oqw7uv
http://eresourcesmoneymarket.com/JbVwdgaV6l
http://flyershipmanager.com/SGAsORYsywt
http://deanandwilconstruction.com/UXEvfuIlhws