Dridex Malware

From us-cert.gov

Indicators of Compromise

The following indicators are associated with the activity described in this report:

Indicator TypeIndicator ValueAssociated Activity
Email addressinfo[@]antonioscognamiglio[.]itDridex
Email addressinfo[@]golfprogroup[.]comDridex
Email addresscariola72[@]teletu[.]itDridex
Email addressfaturamento[@]sudestecaminhoes[.]com.brDridex
Email addressinfo[@]melvale[.]co.ukDridex
Email addressfabianurquiza[@]correo.dalvear[.]com.arDridex
Email addressweb1587p16[@]mail.flw-buero[.]atDridex
Email addressbounce[@]bestvaluestore[.]orgDridex
Email addressfarid[@]abc-telecom[.]azDridex
Email addressbounce[@]bestvaluestore[.]orgDridex
Email addressadmin[@]sevpazarlama[.]comDridex
Email addressfaturamento[@]sudestecaminhoes[.]com.brDridex
Email addresspranab[@]pdrassocs[.]comDridex
Email addresstom[@]blackburnpowerltd[.]co.ukDridex
Email addressyportocarrero[@]elevenca[.]comDridex
Email addresss.palani[@]itifsl.co[.]inDridex
Email addressfaber[@]imaba[.]nlDridex
Email addressadmin[@]belpay[.]byDridex
IP address62[.]149[.]158[.]252Dridex
IP address177[.]34[.]32[.]109Dridex
IP address2[.]138[.]111[.]86Dridex
IP address122[.]172[.]96[.]18Dridex
IP address69[.]93[.]243[.]5Dridex
IP address200[.]43[.]183[.]102Dridex
IP address79[.]124[.]76[.]30Dridex
IP address188[.]125[.]166[.]114Dridex
IP address37[.]59[.]52[.]64Dridex
IP address50[.]28[.]35[.]36Dridex
IP address154[.]70[.]39[.]158Dridex
IP address108[.]29[.]37[.]11Dridex
IP address65[.]112[.]218[.]2Dridex

Read more…