Advertisement
vk_intel

7-16-2018: Gozi ISFB Botnet ID "1798" IT

Jul 16th, 2018
866
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.52 KB | None | 0 0
  1. MD5: e5c7b986b6fd3733504db3fd6d6faada
  2.  
  3. Botnet ID ['1798']
  4. Encryption key ['10291029JSJUYNHG']
  5. Server ['12']
  6. Domains ['185.20.185.165', '185.161.211.214', '195.123.224.99', '195.123.209.207', '93.171.216.24', '93.171.216.81', '93.179.69.17', '93.171.216.104', '185.20.185.228', '195.123.209.104']
  7. DGA Base URL ['com', 'ru', 'org']
  8.  
  9.  
  10. URI Path:
  11.  
  12. /images/
  13.  
  14. Replica/Webinject:
  15.  
  16. https://sitergenis.com/it/
  17. https://guardnet.review/
  18.  
  19. VNC Module:
  20.  
  21. clickara.com/images/vnc32sk.rar
  22. clickara.com/images/vnc64sk.rar
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement