File tree Expand file tree Collapse file tree 2 files changed +41
-0
lines changed Expand file tree Collapse file tree 2 files changed +41
-0
lines changed Original file line number Diff line number Diff line change
1
+ # Limepad C2 domains
2
+ ncloudup[.]com
3
+ gcloudsvc[.]com
4
+
5
+ # Credential harvesting sites
6
+ nic-updates[.]in
7
+ kavachmail-govin[.]rf[.]gd
8
+
9
+ # Attacker-registered domains spoofing Kavach site
10
+ kavach-app[.]com
11
+ kavachguide[.]com
12
+ kavach-app[.]in
13
+ get-kavach[.]in
14
+ getkavach[.]com
15
+ kavachsupport[.]com
16
+ kavachdownload[.]in
17
+ kavachauthentication.blogspot[.]com
18
+
19
+ # Post-infection IOCs
20
+ 139.59.79[.]86
21
+ 139.59.79[.]86/song.mp3
22
+ 139.59.79[.]86/OneDriveHandler45_bf.zip
23
+ 139.59.79[.]86/OneDriveHandler45.zip
24
+ 139.59.79[.]86/C2L!Dem0&PeN/A@llPack3Ts/Cert.php
25
+
26
+ # wzxdao[.]com
27
+ wzxdao[.]com/onedrivehandlerx86.zip
28
+ wzxdao[.]com/OnrDriveHandlerx86.zip
29
+
30
+ # Decoy file URLs
31
+ hxxp://139.59.23[.]88/confirmation_id.pdf
32
+ hxxps://ncloudup[.]com/trendmic/details.pdf
33
+ hxxp://wzxdao[.]com/resultupdate.jpg
34
+ http://139.59.79[.]86/Pictures.jpg
Original file line number Diff line number Diff line change
1
+ 123b180ed44531bfbac27c6eb0bbe01d
2
+ 3817590cf8bec4a768bb84405590272f
3
+ 0ed6451ffe34217e44355706f4900ecc
4
+ 94daa776792429d1cb65edc1d525e2fc
5
+ c195d6bb06c93b94d39e5c1a2dfc6792
6
+ 889c5c98e88c4889220617f57f5480f7
7
+ ac3f2c8563846134bb42cb050813eac8
You can’t perform that action at this time.
0 commit comments