|
| 1 | +Embedded Domains: (Same used for Check-In Request) |
| 2 | + |
| 3 | +http[:]//barusgorlerat[.]me |
| 4 | +http[:]//damacenapirescontab[.]com |
| 5 | +http[:]//assesorattlas[.]me |
| 6 | +http[:]//perfomacepnneu[.]me |
| 7 | + |
| 8 | +Grandoreiro Loader URLs: |
| 9 | + |
| 10 | +35[.]181[.]59[.]254/info99908hhzzb.zip |
| 11 | +35[.]180[.]117[.]32/$FISCALIGENERAL3489213839012 |
| 12 | +35[.]181[.]59[.]254/$FISCALIGE54327065410839012?id_JIBBRS=DR-307494 |
| 13 | +52[.]67[.]27[.]173/deposito(1110061313).zip |
| 14 | +54[.]232[.]38[.]61/notificacion(flfit48202).zip |
| 15 | +54[.]232[.]38[.]61/notificacion(egmux24178).zip |
| 16 | + |
| 17 | + |
| 18 | +Final Grandoreiro Payload URLs with Check-In URL: |
| 19 | + |
| 20 | +15[.]188[.]63[.]127/$TIME |
| 21 | +167[.]114[.]137[.]244/$TIME |
| 22 | +15[.]188[.]63[.]127:36992/zxeTYhO.xml |
| 23 | +15[.]188[.]63[.]127:36992/vvOGniGH.xml |
| 24 | +15[.]188[.]63[.]127[:]36992/eszOscat.xml |
| 25 | +15[.]188[.]63[.]127:36992/YSRYIRIb.xml |
| 26 | +167[.]114[.]137[.]244:48514/eyGbtR.xml |
| 27 | +barusgorlerat[.]me/MX/ |
| 28 | +assesorattlas[.]me/MX/ |
| 29 | +assesorattlas[.]me/AR/ |
| 30 | +atlasassessorcontabilidade[.]com/BRAZIL/ |
| 31 | +vamosparaonde[.]com/segundona/ |
| 32 | +mantersaols[.]com/MEX/MX/ |
| 33 | +premiercombate[.]eastus.cloudapp.azure.com/PUMA/ |
| 34 | + |
| 35 | +Grandoreiro CnC: |
| 36 | + |
| 37 | +Pcbbcrjcgbcghjpbcgkccbjorkhhjcjj[.]fantasyleague[.]cc -> fantasyleague[.]cc |
| 38 | +jmllmedvhgmhldjgmhvmmlljhvgdzvzz[.]dynns[.]com |
| 39 | +ciscofreak[.]com |
| 40 | +chjjhjmomaoheoojjbynnyjiidfcncc.cable-modem.org -> cable-modem.org |
| 41 | +odbbdbmgmagdfggbbnynnyjiidfcncc.blogsyte.com -> blogsyte.com |
| 42 | +ifnnfnmcmacfdccnnjynnyjiidfcncc.collegefan.org -> collegefan.org |
0 commit comments