Advertisement
Matthewm

Dridex 3/31/2015 for botnets 120 and 125

Mar 31st, 2015
860
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.91 KB | None | 0 0
  1. Dridex 3/31/2015 for botnets 120 and 125. Note that these are found in the malware. Some may already be inactive
  2.  
  3. Loader IPs for 125:
  4. 91.230.60.219:8080
  5. 202.44.54.5:8080
  6. 176.108.1.17:8080
  7. 66.110.179.66:8080
  8.  
  9. Redirects for 125:
  10. <redirects>
  11. <redirect name="1st" vnc="0" socks="0" uri="http://192.254.174.231:8080/userexperiences" timeout="20">webstsomni.js</redirect>
  12. <redirect name="2nd" vnc="1" socks="1" uri="http://192.254.174.231:8080/gatheredstats" timeout="20">userexperiences30.js</redirect>
  13. <redirect name="vbv1" vnc="0" socks="0" postfwd="1" uri="http://37.59.96.74:8080/logs/dtukvbv/js.php" timeout="20">/logs/dtukvbv/js.php</redirect>
  14. <redirect name="vbv2" vnc="0" socks="0" postfwd="1" uri="http://37.59.96.74:8080/logs/dtukvbv/in.php" timeout="20">/logs/dtukvbv/in.php</redirect>
  15. </redirects>
  16.  
  17. Nodes for 125
  18. <node>
  19. 87.236.215.103:80
  20. 107.191.46.222:80
  21. 107.191.46.222:8000
  22. 185.91.175.39:80
  23. 128.199.203.165:80
  24. 95.163.121.178:80
  25. 46.101.38.178:80
  26. </node>
  27.  
  28. Loader IPs for 120:
  29. 188.120.225.17:8080
  30. 82.151.131.129:8080
  31. 95.163.121.33:80
  32. 121.50.43.175:8080
  33. 92.63.88.83:80
  34.  
  35. Redirects for 120
  36. <redirects>
  37. <redirect name="1st" vnc="0" socks="0" uri="http://62.109.4.230:8080/addons" timeout="20">twister5.js</redirect>
  38. <redirect name="2nd" vnc="1" socks="1" uri="http://62.109.4.230:8080/webuibuilder" timeout="20">commonuifunc.js</redirect>
  39. <redirect name="tgp" vnc="1" socks="1" uri="http://62.109.4.230:8080/webuibuilder" timeout="20">notracking.js</redirect>
  40. <redirect name="rbs_fake" vnc="0" socks="0" uri="http://188.226.168.84:8080/rbs_logon/index.php" timeout="40">https://www.bankline.rbs.com/</redirect>
  41.  
  42. <node>
  43. 5.135.28.104:80
  44. 192.64.11.232:80
  45. 27.54.174.181:80
  46. 2.194.41.9:8000
  47. 222.234.230.239:8000
  48. 1.164.114.195:80
  49. 46.8.136.213:8000
  50. 176.223.48.44:1016
  51. 77.74.103.150:80
  52. 107.191.46.222:80
  53. 188.226.129.49:80
  54. 46.19.143.151:80
  55. 45.55.154.235:80
  56. 87.236.215.105:80
  57. 199.201.121.169:80
  58. </node>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement