Advertisement
vk_intel

7-2-2018: #TrickBot 1000221 & module IOCs

Jul 2nd, 2018
332
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.16 KB | None | 0 0
  1. <mcconf>
  2. <ver>1000221</ver>
  3. <gtag>tt0002</gtag>
  4. <servs>
  5. <srv>138.34.32.218:443</srv>
  6. <srv>178.78.202.189:443</srv>
  7. <srv>47.40.90.210:443</srv>
  8. <srv>93.109.242.134:443</srv>
  9. <srv>45.36.155.244:443</srv>
  10. <srv>158.58.131.54:443</srv>
  11. <srv>46.59.89.119:449</srv>
  12. <srv>208.78.58.170:443</srv>
  13. <srv>45.56.2.247:443</srv>
  14. <srv>109.86.227.152:443</srv>
  15. <srv>83.172.125.227:443</srv>
  16. <srv>200.2.126.98:443</srv>
  17. <srv>62.31.150.202:443</srv>
  18. <srv>90.69.224.122:443</srv>
  19. <srv>194.68.23.182:443</srv>
  20. <srv>182.253.210.130:449</srv>
  21. <srv>67.159.157.150:443</srv>
  22. <srv>212.87.169.31:443</srv>
  23. <srv>201.174.70.238:443</srv>
  24. <srv>138.34.32.74:443</srv>
  25. <srv>185.129.193.221:443</srv>
  26. <srv>187.163.215.32:443</srv>
  27. <srv>199.250.230.169:443</srv>
  28. <srv>95.213.199.95:443</srv>
  29. <srv>193.233.60.40:443</srv>
  30. <srv>85.143.216.131:443</srv>
  31. <srv>212.92.98.189:443</srv>
  32. <srv>109.234.34.106:443</srv>
  33. <srv>62.109.26.128:443</srv>
  34. </servs>
  35. <autorun>
  36. <module name="systeminfo" ctl="GetSystemInfo"/>
  37. <module name="injectDll"/>
  38. </autorun>
  39. </mcconf>
  40.  
  41.  
  42. Payload Module Stager IOCs:
  43. http://109.234.36.103/worming.png
  44. http://109.234.36.103/table.png
  45. http://109.234.36.103/toler.png
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement