Skip to content

Instantly share code, notes, and snippets.

@adelmas
Created August 22, 2017 20:31
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save adelmas/2645a6dc89510506f6a6ee73e935caee to your computer and use it in GitHub Desktop.
Save adelmas/2645a6dc89510506f6a6ee73e935caee to your computer and use it in GitHub Desktop.
Trickbot ver. 1000041, gtag tt0002 - Decrypted configs
--------------------
Main conf :
--------------------
<mcconf>
<ver>1000041</ver>
<gtag>tt0002</gtag>
<servs>
<srv>84.238.198.166:449</srv>
<srv>91.139.236.92:449</srv>
<srv>84.40.65.85:449</srv>
<srv>51.254.164.249:443</srv>
<srv>194.87.144.16:443</srv>
<srv>149.56.122.114:443</srv>
<srv>46.105.238.157:443</srv>
<srv>194.87.103.84:443</srv>
<srv>188.165.62.15:443</srv>
<srv>79.124.78.83:443</srv>
<srv>67.21.74.228:443</srv>
<srv>94.140.116.13:443</srv>
<srv>185.86.151.205:443</srv>
<srv>149.56.167.227:443</srv>
<srv>37.59.80.97:443</srv>
<srv>195.133.147.213:443</srv>
<srv>194.87.92.207:443</srv>
<srv>5.152.210.170:443</srv>
<srv>217.12.221.9:443</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
--------------------
Plugin conf :
--------------------
<servconf>
<expir>1514678400</expir>
<plugins>
<psrv>188.165.62.11:447</psrv>
<psrv>5.152.210.165:447</psrv>
<psrv>172.93.37.143:447</psrv>
<psrv>79.124.78.81:447</psrv>
<psrv>210.16.101.88:447</psrv>
</plugins>
</servconf>
--------------------
Bot update :
--------------------
http://213.252.246.182/374.png (AES encrypted)
--------------------
Dpost :
--------------------
<dpost>
<handler>http://93.123.73.16:8082</handler>
</dpost>
--------------------
Mail conf :
--------------------
<mail>
<handler>93.123.73.16:443</handler>
</mail>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment