Skip to content

Instantly share code, notes, and snippets.

@jstrosch
Created October 22, 2021 16:22
Show Gist options
  • Save jstrosch/c07ad8f59e50b21a7304aa34044a5b92 to your computer and use it in GitHub Desktop.
Save jstrosch/c07ad8f59e50b21a7304aa34044a5b92 to your computer and use it in GitHub Desktop.
password-protected webshells and PE payloads from Dridex-tagged URLs via URLHaus
<===== WEBSHELLS =====>
[*] Shell SHA256: 6abf737186523a962f94e0e6b6bed5f5ab9238d3fddfc173d8ef83b67400d4ca
[HOST] https://regiontreasure.com/js/vendor/option.php
[HOST] https://reportingdashboard.mobilisedev.co.uk/includes/app.core.php
[HOST] https://eflcc.in/images/prettyPhoto/dark_rounded/authorize.php
[HOST] https://chains.lookarma.com.br/wp-includes/sodium_compat/src/Core/Base64/class.core.php
[HOST] https://reviewgrenade.com/wp-content/themes/blossom-fashion/inc/css/lib.php
[HOST] https://www.turksagroup.com/wp-content/plugins/redux-framework/redux-core/appsero/app.class.php
[HOST] https://stockmanager.upd.work/themes/default/views/auth/email/lib.api.php
[HOST] https://demo.usa-mycard.com/sql/class.cache.php
[*] Shell SHA256: d387223330e850143e296316e8834bb3b381ca3450c1afc38e62b40c6c717058
[HOST] https://f1netce.net.br/f1netce.net.br/philiped/api.service.php
[HOST] https://final.mentorline.org/et-corporis/lib.php
[*] Shell SHA256: 5e805f08cebfb2652e1c480a3d6fd82035f905d83bb5a60e8b6b6bbca7eab126
[HOST] https://mos-app.myitas.net/arak-queen/option.php
[HOST] https://mos-app.myitas.net/restobetawi/service.php
[HOST] https://mos-app.myitas.net/bakmi-gm/lib.php
[HOST] https://mos-app.myitas.net/bendega/type.php
[HOST] https://mos-app.myitas.net/beauty-princess/default.php
[*] Shell SHA256: 09a510f03e798b25ed97a2fb24e054d17fada5df5c0ef843fa73a02d39091f97
[HOST] https://mos-app.myitas.net/bakmi-gm/view.php
[HOST] https://chains.lookarma.com.br/wp-includes/class-wp-query-page.php
[HOST] https://mos-app.myitas.net/restobetawi/app.core.php
[HOST] https://mos-app.myitas.net/beauty-princess/class.engine.php
[*] Shell SHA256: 75520d2bb86140c272b8ab15fb4ae55621e3b64828a0fd1393c31a00ea3a426b
[HOST] https://demo.usa-mycard.com/sql/class.php
[*] Shell SHA256: 06e1bc999bb5df10b2472be1822312e7fe229394cdaf652b41bcebd171d63f2f
[HOST] https://safa.support/help/authorize.php
[*] Shell SHA256: 825ae6835c175c1eed83c2ee4aa2f4065ca87b93d97b2854af55c863b0decddc
[HOST] https://safa.support/help/security.php
[HOST] https://saarimoveis.com/wp-content/plugins/houzez-theme-functionality/statistics/css/core.process.php
<===== PE =====>
[*] PE SHA256:ac1dd32c41f6002bdf2eb564653ff23e069594ce55f9e22093355084ee28a6fd
[HOST] https://reviewgrenade.com/wp-content/themes/blossom-fashion/inc/css/SDGBOep8
[*] PE SHA256:044dba2cb102eb631f8bb519b483e6c5b640e2b3e542053f29949e13bb142df2
[HOST] https://f1netce.net.br/f1netce.net.br/philiped/f1j7m5.zip
[*] PE SHA256:63b166d743b92d781ffb3dff55c0c8b56868d66b3862b9e3a2f45b05a4fe4872
[HOST] https://iqdigitalmarket.com/j042uubb4.rar
[*] PE SHA256:60a4ae60ba10e2cc2a893d399da1d2ffa9ec6d2c03e855b834571159f84bbf04
[HOST] https://regiontreasure.com/js/vendor/E9nEBWeL
[*] PE SHA256:5682a1f152cb6775fff81257507d59351bc447b41722872adef21afbf72bf48a
[HOST] https://regiontreasure.com/js/vendor/lqqq1YZFsdSDX
[*] PE SHA256:7cec53f15d92b3b6bec3ad9552f1b7f2e2c569c3b4bbf2c199624628c2842328
[HOST] https://regiontreasure.com/js/vendor/ulxtbbJ2
[*] PE SHA256:c7db717f9d8ba478c54b9337931c181a99e325f978feab57e1f5aa15125efc51
[HOST] https://stockmanager.upd.work/themes/default/views/auth/email/E6eHQQyjXCzYF
[*] PE SHA256:5321d938958fdb9ddc055df072e8fb9b7c7326a3a9cb259d825e9d695212b364
[HOST] https://stockmanager.upd.work/themes/default/views/auth/email/ZU6ejfqvP2i5VM
[*] PE SHA256:322ce2c2170237a0ebbe689bc1a558c72c7305fce09b3a66cb444ba826c7d771
[HOST] https://reportingdashboard.mobilisedev.co.uk/includes/5kzdvQmPg
[*] PE SHA256:ff90f27bbe6d476a7811731b2137adf17b7dfa6e542a9055a81a5ce1b89dafae
[HOST] https://reportingdashboard.mobilisedev.co.uk/includes/JZs5PqMAq
[*] PE SHA256:95faca2ce9771fe75300ab542b919fb68549816e7a5163579e1459ff9e619d96
[HOST] https://reportingdashboard.mobilisedev.co.uk/includes/mcEiZOqpxIFds
[*] PE SHA256:d5c12460c45c2acf2e39280d34a2cc8685a1dbde40862350aca7725311023a0b
[HOST] https://reportingdashboard.mobilisedev.co.uk/includes/v9XEDSvHqHh7cg5
[*] PE SHA256:c7155bf158241ce27d7b2219afe7dc3a51e5f38621350bc5f764d50691f1d011
[HOST] https://mos-app.myitas.net/pob44p15o.rar
[*] PE SHA256:48d267f875bca7301f079a283305cba11ec8106e9ed76758c780ddb2cf847a59
[HOST] https://demo.usa-mycard.com/sql/E0JISV7xIHoSYfK
[*] PE SHA256:966795489278e05ad878d4d25381cdb32131987766700eb7c0cb65731838019d
[HOST] https://demo.usa-mycard.com/sql/R9TBKBSQzb
[*] PE SHA256:aa5facafb1d9615fb220d6251a608d1713c4a5bee7e62e48f7826145014cdeb3
[HOST] https://safa.support/help/EPLORnyiPk3r
[*] PE SHA256:56a9028cd894a48cd34db924d153bf2c65895a5793c187c2a9b7a91f3f5f63cf
[HOST] https://safa.support/help/WHKJtXhn
[*] PE SHA256:58f28b8a4678f6e9a5c7c54094795d891eea89081b734c4b808f290f7c72b16d
[HOST] https://safa.support/help/WJzEfqkk
[*] PE SHA256:fcae5f89c4c1aeed2730febdbf64573268a12c83f355ea770c18336049379ab0
[HOST] https://safa.support/help/yalMICy1aEW1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment