Advertisement
James_inthe_box

TTP's

Nov 20th, 2018
437
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.45 KB | None | 0 0
  1. Drops C:\Users\user\AppData\Roaming\<appnam>\<appname>.com
  2. Drops C:\Users\<user>\AppData\Local\Temp\<random>.tmp
  3. Reboots machine
  4. Uses custom dns server to resolve c2
  5. .tmp file above is ntdll.dll
  6.  
  7. "Address","Port","Packets","Bytes","Tx Packets","Tx Bytes","Rx Packets","Rx Bytes"
  8. "5.135.183.146",53,25,1221,0,0,25,1221
  9. "23.94.5.133",53,25,1221,0,0,25,1221
  10. "23.94.60.240",53,25,1221,0,0,25,1221
  11. "31.3.135.232",53,50,2442,0,0,50,2442
  12. "34.240.147.125",53,20,977,0,0,20,977
  13. "45.63.25.55",53,25,1221,0,0,25,1221
  14. "51.254.25.115",53,25,1221,0,0,25,1221
  15. "51.255.48.78",53,25,1221,0,0,25,1221
  16. "52.174.55.168",53,25,1221,0,0,25,1221
  17. "54.236.38.98",53,25,1221,0,0,25,1221
  18. "62.113.203.55",53,25,1221,0,0,25,1221
  19. "62.113.203.99",53,25,1221,0,0,25,1221
  20. "82.196.9.45",53,20,977,0,0,20,977
  21. "87.98.175.85",53,25,1221,0,0,25,1221
  22. "89.18.27.167",53,25,1221,0,0,25,1221
  23. "104.238.186.189",53,25,1221,0,0,25,1221
  24. "130.255.73.90",53,25,1221,0,0,25,1221
  25. "130.255.78.223",53,25,1221,0,0,25,1221
  26. "139.59.23.241",53,25,1221,0,0,25,1221
  27. "151.80.147.153",53,25,1221,0,0,25,1221
  28. "163.53.248.170",53,25,1221,0,0,25,1221
  29. "172.104.136.243",53,20,977,0,0,20,977
  30. "185.121.170.176",53,25,1221,0,0,25,1221
  31. "185.133.72.100",53,25,1221,0,0,25,1221
  32. "188.165.200.156",53,25,1221,0,0,25,1221
  33. "193.183.98.66",53,25,1221,0,0,25,1221
  34. "193.183.98.154",53,25,1221,0,0,25,1221
  35. "195.154.226.249",53,25,1221,0,0,25,1221
  36. "202.46.32.19",53,25,1221,0,0,25,1221
  37. "202.58.192.10",53,25,1221,0,0,25,1221
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement