Rewterz
Rewterz Threat Alert – Multiple Malspam Campaigns Dropping Different Malware – IoCs
March 19, 2019
Rewterz
Rewterz Threat Alert – Multiple Phishing Campaigns – Indicators of Compromise
March 19, 2019

Rewterz Threat Alert – Malicious IPs and Domains

Severity

Medium

Analysis Summary

Following threat indicators have been retrieved from multiple malware and phishing campaigns. These malicious IPs and domains are involved in dropping various Trojans and malware.

Impact

Andromeda
Generic Trojan
RETADUP
DarkGate
VBS.Unk
Chthonic
IcedID
Worm
Infostealer
Banking Trojan

Indicators of Compromise

IP(s) / Hostname(s) 75.183.130[.]158
69.89.31[.]139
192.185.5[.]208
162.241.218[.]118
173.50.48[.]59
169.207.67[.]14
URLs disorderstatus[.]ru
differentia[.]ru
changetheworld[.]bit
newage[.]newminersage[.]com
newage[.]radnewage[.]com
utorrentsp2p[.]nz
top[.]theandroidstore[.]tv
atomary[.]bit
centechnya[.]pw
enversial[.]com
jq[.]syrusdesign[.]com
melbourg[.]ooo
rogersbvrly0123.ddns[.]net
Email Address mmswholesaleltd[@]homdpot[.]com
Malware Hash (MD5/SHA1/SH256) 36ace63e783dd0ca36cb1e441c8ff249
132b9d25754543036c8913c35bea1c47

Remediation

Block the threat indicators at their respective controls.