Advertisement
Guest User

2019-04-29: Emotet Loader -> Gozi ISFB Loader Tor (DreamBot)

a guest
Apr 29th, 2019
2,242
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.61 KB | None | 0 0
  1. ht/ @James_inthe_box
  2. Emotet:
  3. md5: 9d80bffaafa1f3896555a4bd63bb73e8
  4.  
  5. GOZI ISFB TOR: (Possible DreamBot):
  6.  
  7. md5: 25a93a644b901224448baf90c9b8b6ae
  8. url: ['http://aaxvkah7dudzoloq[.]onion', 'http://alfa-sentavra[.]at', 'http://miska-server[.]at', 'http://anti-doping[.]at']
  9. dga_url: ['constitution.org/usdeclar.txt']
  10. dga_see: ['0x4eb7d2ca']
  11. dga_tld: ['com', 'ru', 'org']
  12. tor_1: ['interruption.ru/key/t32.bin', 'file://%appdata%/system32.dll']
  13. tor_2: ['interruption.ru/key/t64.bin','file://%appdata%/system64.dll']
  14. ip_check: ['curlmyip.net']
  15. id: ['Gu9foUnsY506KSJ1']
  16.  
  17. Inject Server:
  18. https://classpana[.]host
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement