Skip to content

Commit a008ada

Browse files
committed
add apt-36 iocs
1 parent 1615085 commit a008ada

File tree

2 files changed

+41
-0
lines changed

2 files changed

+41
-0
lines changed

apt36/c2s.txt

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# Limepad C2 domains
2+
ncloudup[.]com
3+
gcloudsvc[.]com
4+
5+
# Credential harvesting sites
6+
nic-updates[.]in
7+
kavachmail-govin[.]rf[.]gd
8+
9+
# Attacker-registered domains spoofing Kavach site
10+
kavach-app[.]com
11+
kavachguide[.]com
12+
kavach-app[.]in
13+
get-kavach[.]in
14+
getkavach[.]com
15+
kavachsupport[.]com
16+
kavachdownload[.]in
17+
kavachauthentication.blogspot[.]com
18+
19+
# Post-infection IOCs
20+
139.59.79[.]86
21+
139.59.79[.]86/song.mp3
22+
139.59.79[.]86/OneDriveHandler45_bf.zip
23+
139.59.79[.]86/OneDriveHandler45.zip
24+
139.59.79[.]86/C2L!Dem0&PeN/A@llPack3Ts/Cert.php
25+
26+
# wzxdao[.]com
27+
wzxdao[.]com/onedrivehandlerx86.zip
28+
wzxdao[.]com/OnrDriveHandlerx86.zip
29+
30+
# Decoy file URLs
31+
hxxp://139.59.23[.]88/confirmation_id.pdf
32+
hxxps://ncloudup[.]com/trendmic/details.pdf
33+
hxxp://wzxdao[.]com/resultupdate.jpg
34+
http://139.59.79[.]86/Pictures.jpg

apt36/hashes.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
123b180ed44531bfbac27c6eb0bbe01d
2+
3817590cf8bec4a768bb84405590272f
3+
0ed6451ffe34217e44355706f4900ecc
4+
94daa776792429d1cb65edc1d525e2fc
5+
c195d6bb06c93b94d39e5c1a2dfc6792
6+
889c5c98e88c4889220617f57f5480f7
7+
ac3f2c8563846134bb42cb050813eac8

0 commit comments

Comments
 (0)