vk_intel

2018-11-16: Gozi ISFB v2.17

Nov 16th, 2018
602
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.22 KB | None | 0 0
  1. MD5 (2018-11-16.isfbv217.loader.decoded.vk.exe) = 3eada298cbfe1398de64a3d2516c8e31
  2.  
  3. Bot ['2.17']
  4. Build ['39']
  5. Botnet/Group ID ['3113’, '3114']
  6. DGA TLDs ['com', 'ru', 'org']
  7. Server [’12’]
  8. Encryption key ['10291029JSJUYNHG']
  9. DGA CRC ['0x4eb7d2ca']
  10. DGA Base URL ['constitution.org/usdeclar.txt']
  11. Domains ['cjwefrfomatt.com', 'gticgrerfgiff.com', 'dubbumnabb.com']
  12. Path: ['/images/']
  13.  
  14. Bot ['2.17']
  15. Build ['39']
  16. Botnet/Group ID ['3114’, '3115']
  17. DGA TLDs ['com', 'ru', 'org']
  18. Server [’12’]
  19. Encryption key ['10291029JSJUYNHG']
  20. DGA CRC ['0x4eb7d2ca']
  21. DGA Base URL ['constitution.org/usdeclar.txt']
  22. Domains ['abbtggmaazzrt.com', 'ticraphiff.com', 'dubbumnabb.com']
  23. Path: ['/images/']
  24.  
  25. 2nd Stage Payload:
  26.  
  27. zatewitsuk.com/YER/pelim.php?l=ulof[1-10].wos
  28. ninasukash.com/YER/pelim.php?l=ulof[1-10].wos
  29.  
  30. 2nd Stage Payload:
  31.  
  32. lootototic.com/YER/pelim.php?l=marb[1-10].wos
  33. osslusturv.com/YER/pelim.php?l=marb[1-10].wos
Add Comment
Please, Sign In to add comment