Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Table 1: List of potential web inject source
- Web Inject Sources
- hxxps://144[.]76[.]111[.]43:443/5/amex_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/bbt_biz_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/bbt_corp_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/bmo_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/bnycash_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/bremer_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/pnc_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/scotiabank_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/5/tdbank_tdetreasury_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/510/tiquani_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/amama_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/amunba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/atonbu_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/bacana_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/bahaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/bokafi_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/bomobo_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/buliba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/camaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/camaci_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/camana_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/cibaca_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/cobaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/cobuba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/emriba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/ewaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/facosa_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/famaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/finiba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/fumaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/hacaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/hasaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/hasaba_uk_pers_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/iboaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/inruba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/irisoba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/katata_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/lakala_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/lemiba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/madaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/magaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/matawa_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/mecoma_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/moboma_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/osv_cetiba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/osv_fasaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/osv_sabatu_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/osv_tobipu_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/pawaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/peniba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/pocoba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/povaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/rabaca2_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/rabaca_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/rasaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/satara_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/secaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/sigaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/socoba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/synova_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/tadaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/todoba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/ubatra_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/unbaba_l4R5Ej69o91Bc3ja/
- hxxps://144[.]76[.]111[.]43:443/520/wabaca_l4R5Ej69o91Bc3ja/
- hxxps://akamai-static5[.]online/appleadmin/gate[.]php
- hxxps://akamai-static5[.]online/bestbuyadmin/gate[.]php
- hxxps://akamai-static5[.]online/costcoadmin/gate[.]php
- hxxps://akamai-static5[.]online/ebayadmin/gate[.]php
- hxxps://akamai-static5[.]online/neweggadmin/gate[.]php
- hxxps://akamai-static5[.]online/ppadmin/gate[.]php
- hxxps://akamai-static5[.]online/samsclubadmin/gate[.]php
- hxxps://akamai-static5[.]online/walmartadmin/gate[.]php
- hxxps://bustheza[.]com/lob[.]php
- hxxps://cachejs[.]com/lob[.]php
- hxxps://46[.]105[.]131[.]77:443/B88U86giIPyD55RK/
- hxxps://46[.]105[.]131[.]77:443/ehf9i7ywh5kdyu50/
- hxxps://46[.]105[.]131[.]77:443/xobj6j20x84lhk3x/
- Table 2: Command and control hosts (C2)
- RMS RAT C2
- 217[.]12[.]201[.]159:5655
- Dridex C2
- hxxps://71[.]217[.]15[.]111:443/
- hxxps://97[.]76[.]245[.]131:443/
- hxxps://24[.]40[.]243[.]66:443/
- hxxps://159[.]69[.]89[.]90:3389/
- hxxps://159[.]89[.]179[.]87:3389/
- hxxps://62[.]210[.]26[.]206:3389/
- Table 3: Payload locations
- Office Macro Payloads
- hxxp://topdalescotty[.]top/filexxx/wiskkk[.]exe
- hxxp://topdalescotty[.]top/filexxx/wotam[.]exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement