vk_intel

10-22-2018: #Gozi #ISFB #Banker: Version "2.18"

Oct 22nd, 2018
449
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.69 KB | None | 0 0
  1. MD5 (decoded ISFB client): 2f14a20e5495d8b8df2853c727c93864
  2. MD5 (decoded ISFB loader): 4d10ec332aa4a7001d8b46c1230f74de
  3.  
  4.  
  5. Bot ['2.18']
  6. Build ['01']
  7. Botnet/Group ID ['3008’, '3009']
  8. DGA TLDs ['com', 'ru', 'org']
  9. Server [’12’]
  10. Encryption key ['10291029JSJUYNHG']
  11. DGA CRC ['0x4eb7d2ca']
  12. DGA Base URL ['constitution.org/usdeclar.txt']
  13. Domains ['kokeadriab.com ', 'dhsiwyqdlskwsqo.com', 'hq92lmdlcdnandwuq.com']
  14. Path: ['/images/']
  15.  
  16. 2nd Stage Domains:
  17.  
  18. ovellonist.com/RUI/levond.php?l=fewk[1-7].xap
  19. frumiticur.com/RUI/levond.php?l=fewk[1-7].xap
Add Comment
Please, Sign In to add comment