Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Note: These are domains on these IP addresses are hosting MWIStat word exploit framework as well.
- Hancitor and Dyreza hosting:
- 91.194.254.210
- 91.194.254.211
- 91.194.254.212
- 91.194.254.213
- 91.194.254.214
- 91.194.254.215
- 91.194.254.216
- 91.194.254.217
- 91.194.254.218
- 91.194.254.219
- 91.194.254.220
- 91.194.254.221
- 91.194.254.222
- 91.194.254.223
- 91.194.254.224
- 91.194.254.225
- 91.194.254.226
- 91.194.254.235
- 91.194.254.236
- 91.194.254.237
- 91.194.254.238
- 91.194.254.239
- 91.194.254.240
- 91.194.254.241
- 91.194.254.242
- 91.194.254.243
- 91.194.254.244
- 91.194.254.245
- /ca/file.jpg -hancitor
- /ca/file.exe -hancitor
- /us/file.exe -hancitor
- /us/file.jpg -hancitor
- /us1/file.exe -hancitor
- /us2/file.exe -hancitor
- /us3/file.exe -dyreza
- /us4/file.exe -dyreza
- /us5/file.exe -dyreza
- /uss/file.exe -dyreza
- /usa/file.exe -dyreza
- /us21/filet.exe -dyreza dropper
- /us21/file.exe -dyreza dropper
- /fax_33663232.pdf.zip -dyreza
- /us274/file.exe -dyreza dropper
- /us274/filet.exe -dyreza dropper
- /us28/file.exe -dyreza dropper
- /us28/filet.exe -dyreza dropper
- /us29/file.exe -dyreza dropper
- /us29/filet.exe -dyreza dropper
- /us304/file.exe -dyreza dropper
- /us304/filet.exe -dyreza dropper
- /us405/file.exe -Pony Loader leading to Dyre
- /us405/filet.exe -Pony Loader leading to Dyre
- document-fast-cloud.com/random/img.php?id=35348399&act=1 -MWIStat download of Pony -usergent of: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
- Dead now, but was distributing MWISTAT powered payloads:
- https://www.virustotal.com/en/domain/doqument-view-online.com/information/
Advertisement
Add Comment
Please, Sign In to add comment