Skip to content

Instantly share code, notes, and snippets.

@hasherezade
Last active December 6, 2021 13:08
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 1 You must be signed in to fork a gist
  • Save hasherezade/f90b7db3a2c34879c74db4b866c67627 to your computer and use it in GitHub Desktop.
Save hasherezade/f90b7db3a2c34879c74db4b866c67627 to your computer and use it in GitHub Desktop.
TrickBot configs
<mcconf>
<ver>1000028</ver>
<gtag>mac1</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>163.53.206.187:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>93.99.68.140:443</srv>
<srv>190.34.158.250:443</srv>
<srv>195.62.52.55:443</srv>
<srv>37.59.80.96:443</srv>
<srv>5.196.116.238:443</srv>
<srv>37.59.183.143:443</srv>
<srv>95.213.251.135:443</srv>
<srv>195.133.144.100:443</srv>
<srv>37.59.80.98:443</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
<mcconf>
<ver>1000030</ver>
<gtag>tt0002</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>163.53.206.187:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>149.56.35.205:443</srv>
<srv>84.238.198.166:449</srv>
<srv>188.124.66.124:449</srv>
<srv>69.247.60.183:449</srv>
<srv>67.21.78.226:443</srv>
<srv>185.144.156.176:443</srv>
<srv>185.30.144.205:449</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
<mcconf>
<ver>1000031</ver>
<gtag>tt0002</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>84.238.198.166:449</srv>
<srv>69.247.60.183:449</srv>
<srv>185.30.144.205:449</srv>
<srv>194.87.236.184:443</srv>
<srv>151.80.84.15:443</srv>
<srv>172.97.69.140:443</srv>
<srv>23.95.9.152:443</srv>
<srv>131.153.37.30:443</srv>
<srv>93.188.163.163:443</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
<mcconf>
<ver>1000032</ver>
<gtag>tt0002</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>84.238.198.166:449</srv>
<srv>194.87.236.184:443</srv>
<srv>151.80.84.15:443</srv>
<srv>23.95.9.152:443</srv>
<srv>31.220.55.47:443</srv>
<srv>210.16.101.59:443</srv>
<srv>64.15.75.78:443</srv>
<srv>195.62.52.107:443</srv>
<srv>195.88.208.193:443</srv>
<srv>194.87.146.113:443</srv>
<srv>194.87.92.199:443</srv>
<srv>195.133.146.77:443</srv>
<srv>185.82.218.117:443</srv>
<srv>23.95.114.233:443</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
<mcconf>
<ver>1000033</ver>
<gtag>tt0002</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>84.238.198.166:449</srv>
<srv>151.80.84.15:443</srv>
<srv>23.95.9.152:443</srv>
<srv>193.70.125.188:443</srv>
<srv>178.33.150.78:443</srv>
<srv>188.165.62.62:443</srv>
<srv>185.82.218.118:443</srv>
<srv>24.13.179.247:449</srv>
<srv>210.16.102.167:443</srv>
<srv>104.160.176.241:443</srv>
<srv>173.242.115.87:443</srv>
<srv>104.160.176.61:443</srv>
<srv>91.247.37.112:443</srv>
<srv>195.245.112.184:443</srv>
<srv>72.211.215.68:449</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
<mcconf>
<ver>1000028</ver>
<gtag>worm</gtag>
<servs>
<srv>186.103.161.204:443</srv>
<srv>163.53.206.187:443</srv>
<srv>191.7.30.30:443</srv>
<srv>46.160.165.31:443</srv>
<srv>93.99.68.140:443</srv>
<srv>190.34.158.250:443</srv>
<srv>195.62.52.55:443</srv>
<srv>37.59.80.96:443</srv>
<srv>5.196.116.238:443</srv>
<srv>37.59.183.143:443</srv>
<srv>95.213.251.135:443</srv>
<srv>195.133.144.100:443</srv>
<srv>37.59.80.98:443</srv>
</servs>
<autorun>
<module name="systeminfo" ctl="GetSystemInfo"/>
<module name="injectDll"/>
</autorun>
</mcconf>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment