APT_CyberCriminal_Campagin_.../2014/Arachnophobia.md
CyberMonitor 7cd6ba7319 go
2017-02-11 15:00:00 +08:00

211 lines
9.5 KiB
Markdown

# Hashes
## md5
* 435bd4f04b2ee7cb05ce402f2bcea85e
* 03f528e752dee57b1ff050a72d30de60
* f689d9990a23fbde3b8688b30ff606da
* d224f39f8e20961b776c238731821d16
* a21f2cb65a3467925c1615794cce7581
* c47d4980c1c152eba335bed5076e8a6f
* 44abc22162c50fcc8dc8618241e3cd1a
* be7de2f0cf48294400c714c9e28ecdd1
* 2458ee58d046f14cad685e6c9c66f109
* ccca290b8ab75a5b29f61847fb882c20
* 801c8bac8aea4d0226e47551c808a331
* 66021803390d0a48d02fad93dc11fa15
* 6f7010a28f33be02d85deb9ba40ec222
* 35663e66d02e889d35aa5608c61795eb
* 7e940115988d64fbf7cd3b0d86cd2440
* 4e96e86db5a8a025b996aefdc218ff74
* 610893cd57631d1708d5efbc786bd9df
* 6e8c4d2d5d4e5e7853a1842b04a6bfdf
* 529f921790578a96acac4c027120e0c5
* 58758cb068583736ef33a09a2c4665de
* fd3a713ebf60150b99fb09de09997a24
* bd0665ffedcf2a9ded36a279d08e4752
* 328adb01fb4450989ee192107a765792
* 7588ff900e32145cbcbc77837237aef8
* cf63bfee568869182bd91a3cb8e386ce
* 5ccb43583858c1c6f41464ee21a192ba
* 5b1bebadb5713018492b1973ab883c25
* 8878162cf508266f6be1326da20171df
* 828d4a66487d25b413cb19ef8ee7c783
* eb66d7e1625059d2f149707ecd11f9c0
* b9a062e84ab64fc55dedb4ba72f62544
* 26616e6662b390ebdb588cdaaae5e4f6
* 5b943bec7d2a589adfe0d3ff2a30bfe5
* b249ca637ef7cc55a0136bcda9dca0d3
## sha1
* 7e940115988d64fbf7cd3b0d86cd2440529f9217
* f689d9990a23fbde3b8688b30ff606da66021803
* b9a062e84ab64fc55dedb4ba72f62544eb66d7e1
## sha256
* b9a062e84ab64fc55dedb4ba72f62544eb66d7e1625059d2f149707ecd11f9c0
* f689d9990a23fbde3b8688b30ff606da66021803390d0a48d02fad93dc11fa15
* 7e940115988d64fbf7cd3b0d86cd2440529f921790578a96acac4c027120e0c5
# countries
* India
* Malaysia
* Mali
* New Zealand
* Pakistan
* Philippines
* Saudi Arabia
* United Kingdom
* United States
# ips
* 46.4.139.225
* 46.4.139.224
* 199.91.173.43
* 199.91.173.45
* 199.91.173.44
* 199.91.173.431
* 184.75.214.10
* 202.125.143.67
# urls
* http://www.motors.pk/used-cars/suzuki-baleno-2004-for-sale-in-islamabad-22.htm
* http://www.motors.pk/ak-22.htm
* http://www.londonpresence.com/contact-us/
* https://dazzlepod.com/rootkit/?page=284
* http://youtube.com/watch?v=w3DjOuEI0vs.mov
* http://www.privatebox.co.nz/virtual-office/virtual-office-address.php
* http://tranchulas.com
* http://tranchulas.com/contact-us/
* http://www.blackhatworld.com/blackhat-seo/hosting/430705-unmetered-vps-hosting-get-50-off-your-first-month-exclusive-coupons-bhw.html
* http://www.blackhatworld.com/blackhat-seo/members/32481-agnosticon.html
* http://saudi.emc.com/contact/contact-us.htm
* https://whois.domaintools.com/saadiakhan.net
* http://whois.domaintools.com/v-billing.com
* http://whois.domaintools.com/vgriffins.com
* https://whois.domaintools.com/textcrypter.com
* https://whois.domaintools.com/defiantmarketing.com
* https://whois.domaintools.com/abunasar.net
* https://whois.domaintools.com/whitehate.org
* https://whois.domaintools.com/vpsnoc.com
* https://whois.domaintools.com/digitallinx.com
* https://whois.domaintools.com/taggnation.com
* http://whois.domaintools.com/my-server.co
* http://whois.domaintools.com/abunasar.net
* https://whois.domaintools.com/bookadoconline.com
* https://whois.domaintools.com/digitallinx.net
* http://whois.domaintools.com/vbilling.org
* http://whois.domaintools.com/zeusadnetwork.com
* http://www.know-hosting.com/view/27108-digitallinx.html
* http://shootingsawk.lescigales.org/misc/owneddarknet.txt
* https://github.com/digitallinx/vBilling/blob/master/CHANGELOG
* http://<c2_location>/is_array_pal.php?compname=<%COMPUTERNAME%>_<%USERNAME%>
* http://<c2_location>/is_array_own.php?compname=
* http://<c2_location>/checkpkg.php?compname=
* http://<c2_location>/is_array_pal.php?compname=
* http://<c2_location>/vtris1.php?srs=436712384
* http://<c2_location>/vtris1.php?srs=
* http://<c2_location>/version_petal.php?srs=
* http://<c2_location>/checkpkg.php?compname=<%COMPUTERNAME%>_<%USERNAME%>
* http://<c2_location>/petal_active.php?compname=
* http://<c2_location>/versionchk.php?srs=
* http://<c2_location>/is_array.php?compname=
* http://<c2_location>/checkpkg_petal.php?compname=
* http://<c2_location>/fetch_updates_8765.php?compname=
* http://<c2_location>/versionchk.php?srs=436712384
* http://<c2_location>/fetch_updates_m.php?compname=
* http://<c2_location>/maxell_active.php?compname=
* http://<c2_location>/fetch_updates_petal.php?compname=
* http://<c2_location>/version_own.php?srs=
* http://<c2_location>/version_maxell.php?srs=
* http://<c2_location>/path_active.php?compname=<%COMPUTERNAME%>_<%USERNAME%>
* http://<c2_location>/fetch_updates_8765_tb.php?compname=
* http://<c2_location>/vtris.php?srs=436712384
* http://<c2_location>/is_array_max.php?compname=
* http://<c2_location>/fetch_updates_flex.php?compname=
* http://<c2_location>/is_array_max.php?compname=<%COMPUTERNAME%>_<%USERNAME%>
* http://<c2_location>/fetch_updates_pops.php?compname=
* http://<c2_location>/path_active.php?compname=
* http://<c2_location>/checkpkg_maxell.php?compname=
* http://<c2_location>/vtris.php?srs=
* http://<c2_location>/fetch_updates_flex.php?compname=<%COMPUTERNAME%>_<%USERNAME%>
* http://<c2_location>/fetch_updates_pret.php?compname=
* http://pk.linkedin.com/pub/hamza-qamar/22/6b8/109
* http://pk.linkedin.com/in/umairaziz27
* https://lists.debian.org/debian-www/2009/01/msg00186.html
* http://bluechipmag.com/qa-with-zubair-khan/
* http://whatmyip.co/info/whois/46.4.139.225
* http://vpsnoc.com
* http://vpsnoc.com/order.png
* https://plus.google.com/105774284158907153401/about
* https://plus.google.com/103436628630566104748/posts
* https://plus.google.com/105855064276291727409/posts
* https://plus.google.com/105059395104464629441/about
* http://www.webhostingtalk.com/showthread.php?t=723658
* https://twitter.com/vpsnoc
* https://twitter.com/umairaziz27
* https://twitter.com/umairaziz27/status/332049978878996481
* https://twitter.com/abunasar
* http://sa.linkedin.com/pub/muhammad-naseer-bhatti/9/18a/815
* http://www.senate.gov.pk/uploads/documents/questions/1317711132_399.pdf
* https://bsd.sos.mo.gov/BusinessEntity/BusinessEntityDetail.aspx?page=beSearch&ID=2936099
* https://reversewhois.domaintools.com/?email=b249ca637ef7cc55a0136bcda9dca0d3
* http://www.nust.edu.pk/INSTITUTIONS/Directortes/ilo/Download%20Section/Graduate%20Profile%20SEECS%20%20BICSE.pdf
* http://www.nust.edu.pk/INSTITUTIONS/Directortes/ilo/Download%20Section/Graduate%20Profiles%20booklet-%202013%20(SEECS).pdf
* http://www.nust.edu.pk/INSTITUTIONS/Directortes/ilo/Download%20Section/Graduate%20Pro
* http://www.shodanhq.com/search?q=93c546-b1-4dbcbc6438380
* http://digitallinx.net/Contact.html
* https://www.privateinternetaccess.com
* http://world.time.com/2013/12/18/us-to-review-devyani-khobragade-arrest-and-strip-search/
* https://www.youtube.com/watch?v=FAM6JxOHdo8
* http://bgp.he.net/dns/defiantmarketing.com
* http://lists.horde.org/archives/horde/Week-of-Mon-20061225/032545.html
* http://www.businessinsider.com/mh370-investigators-find-evidence-of-a-mysterious-power-
* http://www.businessinsider.com/mh370-investigators-find-evidence-of-a-mysterious-power-outage-during-the-early-part-of-its-flight-2014-6
* http://www.pakwheels.com/forums/user/abunasark
* http://www.pakwheels.com/forums/members-member-rides/99428-white-baleno-not-anymore-comments-please-p-4
* http://www.zoominfo.com/s/
* http://abunasar.net
* http://nextspace.us/nextspace-union-square-san-francisco/
* https://www.virustotal.com/en/file/7e940115988d64fbf7cd3b0d86cd2440529f921790578a96acac4c027120e0c5/analysis/
* https://www.virustotal.com/en/ip-address/199.91.173.43/information/
* https://www.virustotal.com/en/file/f689d9990a23fbde3b8688b30ff606da66021803390d0a48d02fad93dc11fa15/analysis/
* https://www.virustotal.com/en/ip-address/199.91.173.45/information/
* https://www.virustotal.com/en/file/b9a062e84ab64fc55dedb4ba72f62544eb66d7e1625059d2f149707ecd11f9c0/analysis/
* https://www.robtex.com/dns/digitallinx.com.html
* http://www.prnewswire.co.uk/news-releases/tranchulas-steps-into-the-global-cyber-strategy-market-with-launch-of-the-offensive-cyber-
* http://www.thenews.com.pk/Todays-News-2-22150-Bureaucrats-journalists-avail-cheaper-accommodation
* http://pashaictawards.com/?page_id=1644
* http://www.sitetrail.com/clubaleno.co.uk
* http://www.dgmarket.com/tenders/np-notice.do?noticeId=2466880
* https://www.facebook.com/media/set/?set=a.542485719112184.135023.132987340062026&type=3
* https://www.facebook.com/EvacueeTrustComplex/photos/a.554791821273808.1073741825.404981572921501/554791824607141/
* https://www.facebook.com/EvacueeTrustComplex
* http://www.theregister.co.uk/2013/08/07/india_cyberespionage/
* http://www.linkedin.com/groups/Tranchulas-Handson-Ethical-Hacking-Training-2616369.S.75237952
* https://www.google.com/maps/dir/Tranchulas,+Islamabad,+Pakistan/Gulshan-e-Jinnah+Complex,+Islamabad,+Pakistan/@33.7327466,7
* http://forums.cpanel.net/f5/help-yum-broke-rpm-db-broke-somehow-httpd-wont-start-238511.html
* http://webcache.googleusercontent.com/search?q=cache:CtCiQUGgUaoJ:www.digitallinx.net/sitemap.xml+&cd=1&hl=en&ct=clnk&gl=us
* http://seecs.nust.edu.pk/Seminars_workshops/pages/tranchulas_hacking_workshop/index.php
* http://eandt.theiet.org/magazine/2012/06/
* http://eandt.theiet.org/magazine/2012/06/et-podcast-18.cfm
* https://groups.google.com/forum/
* http://pastebin.com/rqVGqh1q
* http://pastebin.com/F261NfYa
* http://pastebin.com/ktR3qM3K
* http://dawhois.com/site/clubaleno.co.uk.html
* http://curl.haxx.se/libcurl/
* http://www.redlinegti.com/forum/viewtopic.php?f=3&t=41719&p=401115
* http://vpsnoc.
* http://wikimapia.org/425791/Evacuee-Trust-Complex
# emails
* abunasar@army.com.72
* abunasar@army.com
* naseer@digitallinx.com
* abunasar@yahoo.com
* support@vpsnoc.com
* nbhatti@gmail.com
* admin@digitallinx.org.13
* zubair@tranchulas.com137
* zubair@tranchulas.com