Advertisement
James_inthe_box

Dridex IOCs

Jan 30th, 2018
3,013
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.17 KB | None | 0 0
  1. Executes:
  2. svchost.exe "C:\Users\Steve\AppData\Local\Temp\<sample>"
  3. C:\Windows\system32\whoami.exe /all
  4. C:\Windows\system32\net.exe view
  5.  
  6. POSTs data via ssl to 443 and 4431
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement