Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Suspicious Urls
- Reported by neonprimetime security
- http://neonprimetime.blogspot.com
- ****
- Snort rule triggered, Mazilla/5.0 - Win.Backdoor.Upatre (1:33207)
- ****
- GET http://checkip.dyndns.org/ HTTP/1.1
- Accept: text/*, application/*
- User-Agent: Mazilla/5.0
- Host: checkip.dyndns.org
- Pragma: no-cache
- Proxy-Connection: Keep-Alive
- Cookie: BCSI-CS-77e191ded1bdeae1=2
- Proxy-Authorization: Negotiate TlRMTVNTUAABAAAAl4II4gAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw==
- NTLMSSP.................................
- ****
- Payloads to follow
- 31.43.236.251
- http://31.43.236.251:14024/1802us11/WORKSTATIONNAME/0/61-SPM/0/EMLBEMDBFGEBEI
- 5.172.196.207
- http://noizeradio.gr/mandoc/sw_doca.pdf
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement