Skip to content

Commit 577ed7f

Browse files
committed
add grandoreiro c2s and hashes
1 parent 010bdbc commit 577ed7f

File tree

2 files changed

+56
-0
lines changed

2 files changed

+56
-0
lines changed

grandoreiro/c2s.txt

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
Embedded Domains: (Same used for Check-In Request)
2+
3+
http[:]//barusgorlerat[.]me
4+
http[:]//damacenapirescontab[.]com
5+
http[:]//assesorattlas[.]me
6+
http[:]//perfomacepnneu[.]me
7+
8+
Grandoreiro Loader URLs:
9+
10+
35[.]181[.]59[.]254/info99908hhzzb.zip
11+
35[.]180[.]117[.]32/$FISCALIGENERAL3489213839012
12+
35[.]181[.]59[.]254/$FISCALIGE54327065410839012?id_JIBBRS=DR-307494
13+
52[.]67[.]27[.]173/deposito(1110061313).zip
14+
54[.]232[.]38[.]61/notificacion(flfit48202).zip
15+
54[.]232[.]38[.]61/notificacion(egmux24178).zip
16+
17+
18+
Final Grandoreiro Payload URLs with Check-In URL:
19+
20+
15[.]188[.]63[.]127/$TIME
21+
167[.]114[.]137[.]244/$TIME
22+
15[.]188[.]63[.]127:36992/zxeTYhO.xml
23+
15[.]188[.]63[.]127:36992/vvOGniGH.xml
24+
15[.]188[.]63[.]127[:]36992/eszOscat.xml
25+
15[.]188[.]63[.]127:36992/YSRYIRIb.xml
26+
167[.]114[.]137[.]244:48514/eyGbtR.xml
27+
barusgorlerat[.]me/MX/
28+
assesorattlas[.]me/MX/
29+
assesorattlas[.]me/AR/
30+
atlasassessorcontabilidade[.]com/BRAZIL/
31+
vamosparaonde[.]com/segundona/
32+
mantersaols[.]com/MEX/MX/
33+
premiercombate[.]eastus.cloudapp.azure.com/PUMA/
34+
35+
Grandoreiro CnC:
36+
37+
Pcbbcrjcgbcghjpbcgkccbjorkhhjcjj[.]fantasyleague[.]cc -> fantasyleague[.]cc
38+
jmllmedvhgmhldjgmhvmmlljhvgdzvzz[.]dynns[.]com
39+
ciscofreak[.]com
40+
chjjhjmomaoheoojjbynnyjiidfcncc.cable-modem.org -> cable-modem.org
41+
odbbdbmgmagdfggbbnynnyjiidfcncc.blogsyte.com -> blogsyte.com
42+
ifnnfnmcmacfdccnnjynnyjiidfcncc.collegefan.org -> collegefan.org

grandoreiro/hashes.txt

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
Grandoreiro Loader:
2+
970f00d7383e44538cac7f6d38c23530
3+
724f26179624dbb9918609476ec0fce4
4+
2ec2d539acfe23107a19d731a330f61c
5+
6433f9af678fcd387983d7afafae2af2
6+
56416fa0e5137d71af7524cf4e7f878d
7+
7ea19ad38940ddb3e47c50e622de2aae
8+
9+
Grandoreiro Final Payload:
10+
11+
e02c77ecaf1ec058d23d2a9805931bf8
12+
6ab9b317178e4b2b20710de96e8b36a0
13+
5b7cbc023390547cd4e38a6ecff5d735
14+
531ac581ae74c0d2d59c22252aaac499

0 commit comments

Comments
 (0)