Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Creates:
- C:\Users\<user>\AppData\Local\<40 bit hex>\container.dat <- encrypted, small
- C:\Users\<user>\AppData\Local\<40 bit hex>\<UUID>
- Network:
- Connects to https://google.com
- Uses UA of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36" <-only seen with MITM
- May attempt to c2 without querying DNS
- c2 traffic is https 443
- c2's at time of writing:
- 37.220.31.120:443
- 89.223.29.34:443
- 89.223.26.215:443
- checkbox.bit:443
- Small activity footprint, does not appear to do much when using procmon or after executing for 2+ minutes.
Add Comment
Please, Sign In to add comment