Advertisement
vk_intel

2018-11-20: Gozi ISFB v217.38

Nov 20th, 2018
412
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. MD5 (2018-11-20.isfbv217.client.decoded.vk.dll) = 2baddd0f964870bbad7c6e9ad0475dec
  2. MD5 (2018-11-20.isfbv217.loader.decoded.vk.exe) = 8e4f36806dd21b7ca40d20ba11f2fe14
  3.  
  4.  
  5. Bot ['2.17']
  6. Build ['38']
  7. Botnet/Group ID ['1000']
  8. DGA TLDs ['com', 'ru', 'org']
  9. Server [’110’]
  10. Encryption key ['K2u7G0lE4u1VoS0V']
  11. DGA CRC ['0x4eb7d2ca']
  12. DGA Base URL ['constitution.org/usdeclar.txt']
  13. Domains ['in.ledalco.at/wpapi', 'yap.yolopuk.at/wpapi', 'torafy.cn/wpapi', 'io.ledalco.at/wpapi', 'int.nokoguard.at/wpapi', 'rest.relonter.at/wpapi', 'yraco.cn/wpapi', 'apt.melotor.at/wpapi', 'vi.relonter.at/wpapi', 'pr.unoreq.at/wpapi', 'gl.filmboun.at/wpapi', 'arp.sosolop.at/wpapi', 'harent.cn/wpapi', 'a5.sosolop.at/wpapi']
  14. Path: ['/images/']
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement