13.05.2016 Views

THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER

001398694

001398694

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Destover “MessageThread” C&C IP addresses:<br />

101.76.99.183<br />

112.206.230.54<br />

124.47.73.194<br />

165.138.120.35<br />

175.45.4.158<br />

177.189.204.214<br />

187.176.34.40<br />

202.182.50.211<br />

203.131.222.102<br />

208.105.226.235<br />

209.237.95.19<br />

211.76.87.252<br />

213.42.82.243<br />

31.210.53.11<br />

59.125.119.135<br />

59.125.62.35<br />

61.91.100.211<br />

62.141.29.175<br />

65.117.146.5<br />

71.40.211.3<br />

85.112.29.106<br />

91.183.41.5<br />

93.157.14.154<br />

Destover “WindowsUpdateTracing” real C&C IP addresses (after XOR translation). Addresses in red are inferred<br />

from pDNS only (no sample).<br />

1.202.129.201<br />

110.78.165.32<br />

113.10.158.4<br />

124.81.92.85<br />

140.134.23.140<br />

196.36.64.50<br />

199.83.230.236<br />

201.22.95.127<br />

202.9.100.206<br />

185.20.218.28<br />

200.55.243.150<br />

122.179.175.224<br />

124.123.219.216<br />

108.166.93.13<br />

14.141.129.116<br />

217.128.80.228<br />

58.137.122.226<br />

2.224.202.27<br />

14.2.240.20<br />

59.125.75.217<br />

41.38.151.7<br />

201.203.27.170<br />

64.206.243.35<br />

184.180.159.183<br />

24.77.32.241<br />

64.228.222.61<br />

217.8.95.250<br />

180.26.59.158<br />

41.41.29.214<br />

Destover “RandomDomain” C&C IP addresses:<br />

103.233.121.22<br />

187.111.14.62<br />

187.54.39.210<br />

206.248.59.124<br />

37.34.176.14<br />

94.199.145.55<br />

200.202.169.103<br />

202.152.17.116<br />

203.131.210.247

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!