IoC (TT Malware Log)

Malware の IoC(Indicator)情報

◆注意◆ マルウェア解析専析家向けサイト

     FQDN, URL,IPアドレス等はそのまま掲載しています


** Caution ** Malware expert site

                    FQDN, URL, IP address etc. are posted as they are

FlawedAmmyy

【インディケータ情報】

■ハッシュ情報(Sha256)

18436342cab7f1d078354e86cb749b1de388dcb4d1e22c959de91619947dfd63
d82ca606007be9c988a5f961315c3eed1b12725c6a39aa13888e693dc3b9a975
8903d514549aa9568c7fea0123758b954b9703c301b5e4941acb33cccd0d7c57
2b53466eebd2c65f81004c567df9025ce68017241e421abcf33799bd3e827900
0d100ff26a764c65f283742b9ec9014f4fd64df4f1e586b57f3cdce6eadeedcd
9a7fb98dd4c83f1b4995b9b358fa236969e826e4cb84f63f4f9881387bc88ccf
cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541
404d3d65430fbbdadedb206a29e6158c66a8efa2edccb7e648c1dd017de47572
cc0205845562e017ff8b3aafb17de167529d113fc680e07ee9d8753d81487b2f
790e7dc8b2544f1c76ff95e56315fee7ef3fe623975c37d049cc47f82f18e4f2
2d19c42f753dcee5b46344f352c11a1c645f0b77e205c218c985bd1eb988c7ce
6e701670350b4aea3d2ead4b929317b0a6d835aa4c0331b25d65ecbfbf8cb500
3cd39abdbeb171d713ee8367ab60909f72da865dbb3bd858e4f6d31fd9c930d0
1f5d31d41ebb417d161bc49d1c50533fcbff523bb583883b10b14974a3de8984
6877ac35a3085d6c10fa48655cf9c2399bd96c3924273515eaf89b511bbe356a
059c0588902be3e8a5d747df9e91f65cc50d908540bdeb08acf15242cc9a25b5
c8b202e5a737b8b5902e852de730dbd170893f146ab9bbc9c06b0d93a7625e85
927fa5fea13f8f3c28e307ffea127fb3511b32024349b39bbaee63fac8dcded7
6048a55de1350238dfc0dd6ebed12ddfeb0a1f3788c1dc772801170756bf15c7
adfdead4419c134f0ab2951f22cfd4d5a1d83c0abfe328ae456321fccf241eb6
022f662903c6626fb81e844f7761f6f1cbaa6339e391468b5fbfb6d0a1ebf8cb
3f5f5050adcf0d0894db64940299ac07994c4501b361dce179e3d45d9d155adf
cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541

(以上は Proofpoint, の情報: 引用元は https://malware-log.hatenablog.com/entry/2018/03/07/000000 )


【検索】

google: 18436342cab7f1d078354e86cb749b1de388dcb4d1e22c959de91619947dfd63
google: d82ca606007be9c988a5f961315c3eed1b12725c6a39aa13888e693dc3b9a975
google: 8903d514549aa9568c7fea0123758b954b9703c301b5e4941acb33cccd0d7c57
google: 2b53466eebd2c65f81004c567df9025ce68017241e421abcf33799bd3e827900
google: 0d100ff26a764c65f283742b9ec9014f4fd64df4f1e586b57f3cdce6eadeedcd
google: 9a7fb98dd4c83f1b4995b9b358fa236969e826e4cb84f63f4f9881387bc88ccf
google: cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541
google: 404d3d65430fbbdadedb206a29e6158c66a8efa2edccb7e648c1dd017de47572
google: cc0205845562e017ff8b3aafb17de167529d113fc680e07ee9d8753d81487b2f
google: 790e7dc8b2544f1c76ff95e56315fee7ef3fe623975c37d049cc47f82f18e4f2
google: 2d19c42f753dcee5b46344f352c11a1c645f0b77e205c218c985bd1eb988c7ce
google: 6e701670350b4aea3d2ead4b929317b0a6d835aa4c0331b25d65ecbfbf8cb500
google: 3cd39abdbeb171d713ee8367ab60909f72da865dbb3bd858e4f6d31fd9c930d0
google: 1f5d31d41ebb417d161bc49d1c50533fcbff523bb583883b10b14974a3de8984
google: 6877ac35a3085d6c10fa48655cf9c2399bd96c3924273515eaf89b511bbe356a
google: 059c0588902be3e8a5d747df9e91f65cc50d908540bdeb08acf15242cc9a25b5
google: c8b202e5a737b8b5902e852de730dbd170893f146ab9bbc9c06b0d93a7625e85
google: 927fa5fea13f8f3c28e307ffea127fb3511b32024349b39bbaee63fac8dcded7
google: 6048a55de1350238dfc0dd6ebed12ddfeb0a1f3788c1dc772801170756bf15c7
google: adfdead4419c134f0ab2951f22cfd4d5a1d83c0abfe328ae456321fccf241eb6
google: 022f662903c6626fb81e844f7761f6f1cbaa6339e391468b5fbfb6d0a1ebf8cb
google: 3f5f5050adcf0d0894db64940299ac07994c4501b361dce179e3d45d9d155adf
google: cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541


【VT検索】

https://www.virustotal.com/gui/file/18436342cab7f1d078354e86cb749b1de388dcb4d1e22c959de91619947dfd63
https://www.virustotal.com/gui/file/d82ca606007be9c988a5f961315c3eed1b12725c6a39aa13888e693dc3b9a975
https://www.virustotal.com/gui/file/8903d514549aa9568c7fea0123758b954b9703c301b5e4941acb33cccd0d7c57
https://www.virustotal.com/gui/file/2b53466eebd2c65f81004c567df9025ce68017241e421abcf33799bd3e827900
https://www.virustotal.com/gui/file/0d100ff26a764c65f283742b9ec9014f4fd64df4f1e586b57f3cdce6eadeedcd
https://www.virustotal.com/gui/file/9a7fb98dd4c83f1b4995b9b358fa236969e826e4cb84f63f4f9881387bc88ccf
https://www.virustotal.com/gui/file/cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541
https://www.virustotal.com/gui/file/404d3d65430fbbdadedb206a29e6158c66a8efa2edccb7e648c1dd017de47572
https://www.virustotal.com/gui/file/cc0205845562e017ff8b3aafb17de167529d113fc680e07ee9d8753d81487b2f
https://www.virustotal.com/gui/file/790e7dc8b2544f1c76ff95e56315fee7ef3fe623975c37d049cc47f82f18e4f2
https://www.virustotal.com/gui/file/2d19c42f753dcee5b46344f352c11a1c645f0b77e205c218c985bd1eb988c7ce
https://www.virustotal.com/gui/file/6e701670350b4aea3d2ead4b929317b0a6d835aa4c0331b25d65ecbfbf8cb500
https://www.virustotal.com/gui/file/3cd39abdbeb171d713ee8367ab60909f72da865dbb3bd858e4f6d31fd9c930d0
https://www.virustotal.com/gui/file/1f5d31d41ebb417d161bc49d1c50533fcbff523bb583883b10b14974a3de8984
https://www.virustotal.com/gui/file/6877ac35a3085d6c10fa48655cf9c2399bd96c3924273515eaf89b511bbe356a
https://www.virustotal.com/gui/file/059c0588902be3e8a5d747df9e91f65cc50d908540bdeb08acf15242cc9a25b5
https://www.virustotal.com/gui/file/c8b202e5a737b8b5902e852de730dbd170893f146ab9bbc9c06b0d93a7625e85
https://www.virustotal.com/gui/file/927fa5fea13f8f3c28e307ffea127fb3511b32024349b39bbaee63fac8dcded7
https://www.virustotal.com/gui/file/6048a55de1350238dfc0dd6ebed12ddfeb0a1f3788c1dc772801170756bf15c7
https://www.virustotal.com/gui/file/adfdead4419c134f0ab2951f22cfd4d5a1d83c0abfe328ae456321fccf241eb6
https://www.virustotal.com/gui/file/022f662903c6626fb81e844f7761f6f1cbaa6339e391468b5fbfb6d0a1ebf8cb
https://www.virustotal.com/gui/file/3f5f5050adcf0d0894db64940299ac07994c4501b361dce179e3d45d9d155adf
https://www.virustotal.com/gui/file/cafa3466e422dd4256ff20336c1a032bbf6e915f410145b42b453e2646004541




【ブログ】

◆Leaked Ammyy Admin Source Code Turned into Malware (Proofpoint, 2018/03/07)
https://www.proofpoint.com/us/threat-insight/post/leaked-ammyy-admin-source-code-turned-malware


【関連まとめ記事】

◆FlawedAmmyy (まとめ)
https://malware-log.hatenablog.com/entry/FlawedAmmyy