Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _____________________ ________ _________ __________ _____ _______ ____ __._____________________
- / _ \__ ___/ \ \_____ \ / _____/ \______ \ / _ \ \ \ | |/ _|\_ _____/\______ \
- / /_\ \| | / \ / \ / | \ \_____ \ | | _/ / /_\ \ / | \| < | __)_ | _/
- / | \ |/ Y \/ | \/ \ | | \/ | \/ | \ | \ | \ | | \
- \____|__ /____|\____|__ /\_______ /_______ / |______ /\____|__ /\____|__ /____|__ \/_______ / |____|_ /
- \/ \/ \/ \/ \/ \/ \/ \/ \/ \/
- ATMOS BANKING TROJAN:
- GATE = ["hxxp://cbiraqi[.]com/smoke/atmos/gate[.]php"]
- BOT = ["hxxp://cbiraqi[.]com/smoke/atmos/file.php|file=us[.]exe"]
- MODULES": { "hvnc_module, atmos_hvnc.module, cookie_module. atmos_ffcookie.module, video_module, atmos_video.module";}
- "URL_REGEX_LIST": {
- *.facebook.com
- *.twitter.com
- *.instagram.com
- *.booking.com
- *.sharepoint.com
- *.yahoo.com
- login.yahoo.com
- *.google.com
- accounts.google.com
- 192.168.*.*
- 127.0.0.1
- */wp-login.php*
- *.ru
- *.ua
- *.kz
- *.il
- *.li
- *.bg
- *.by
- *.az
- *.am
- *.kg
- *.md
- *.tjââ
- *.tm
- *.uz
- *.xn--p1ai
- ";}
- "ZEUS-STYLE_CMD": {
- "â%BOTID%
- %BOTNET%
- %BC-*-*-*-*%
- %VIDEO%
- Psystem
- registry
- setvalue
- getvalue
- hvnc_stop
- hvnc_start
- video_start
- bc_remove
- bc_add
- ";}
- "CONFIG": {
- "dir %windir%\system32\inetsrv\*.xml
- ipconfig /all
- osql -L
- osql -E -Q "exec sp_databases"
- tasklist
- "C:\Program Files\Microsoft Security Client\Setup.exe" /x /s
- netsh firewall set opmode disable
- net share
- c:\windows\system32\inetsrv
- ppcmd.exe list sites /text:name /state:started
- $t;*
- ;*.exe;*.png;*.bmp;*.lnk;*.wer;*.css;*.js;*.wpl;*.mp3;*.avi;*.mkv;*.wav;*.usca;*.ini;*.dll;*.url;*.menu;*.hfx;*.map;*.lng;*.ico;*.icon;*.aml;*.swf;*.man;*.inf;*.cab;*.flv;*.cat;*.lcp;*.scr;*.xml;*.sys;*.cn_;*.dl_;*.jpeg;*.psd;*.ch_;*.ex_;*.wma;*.m4a;*.tiff;*.mp4;*.msi;*.cov;*.gzi;*.cbr;*.wmv;*.ogg;*.h
- $t*.
- *swift*;*manufactur*;*atm*;*.aba;*.p12;*bitcoin*;*.qfx;*.ofx;*.qif;*westernunion*;*moneygram*;*translink*;*.pcf;*DWAF*;*vasco*;*RBAnet*;*diebold*;*wincor*;*.pab;*.MYO;*wupos*;*threatmetrix*;*apca*;*.apk;multibit.wallet;*nixdorf*;*aptra*;*.wallet;*litecoin*
- *.log;*.jpg;*.gif;*.bat;*.exe;*.png;*.bmp;*.lnk;*.wer;*.css;*.js;*.wpl;*.mp3;*.avi;*.mkv;*.wav;*.usca;*.ini;*.dll;*.url;*.menu;*.hfx;*.map;*.lng;*.ico;*.icon;*.aml;*.swf;*.man;*.inf;*.cab;*.flv;*.cat;*.lcp;*.scr;*.xml;*.sys;*.cn_;*.dl_;*.jpeg;*.psd;*.ch_;*.ex_;*.wma;*.m4a;*.tiff;*.mp4;*.msi;*.cov;*.gzi;*.cbr;*.wmv;*.ogg;*.html;*.htm;*Swift_Current*;*.gm;*.epub;*.mov;*.gp5;*.gp3;*bluetooth*;*.torrent;*.class;*.mpg;*.cpp;*.h;*.py;*.pm;*.patch;*.hex;*.col;*book*;*.sol;*Clearwtr.MYO*;*BusinessInABox*;*.rpt;*iswift.dat*;*Taylor Swift*;*.flac;
- %wd%;%td%;%sd1%;%sd2%;%pd1%;%pd2%;%ad%;*AppData*;*Local Settings*;*Application Data*;*Temp*;*Cookies*;*Recycle*;*torrent*;*drivers*;*help*;*movies*;*music*;*cache*;*adobe*;*I386*;*Windows*;*images*;*photo*;*game*;*google*;*ATI*;*acer*;*NVIDIA*;*University*;*sony*;*apple*;*Hewlett*;*cyberlink*;*dvd*;*poker*;*toshiba*;*autocad*;*starcraft*;*spybot*;*Semester*;*school*;*audio*;*maps*;*smitfraud*;*video*;*guitar*;*sound*;*warcraft*;*cygwin*;*Graphics*;*Pinnacle*;*yahoo*;*autodesk*;*android*;*nokia*;*example*;*theme*;*winamp*;*academy*;*demo*;*jre6*;*Windows.old*;*recycle*;*student*;*style*;*Tutorial*;*Spredsht*;*steam*;*samsung*;*java*;*tools*;*Libraries*;*cstrike*;*study*;*book*;*roms*;*Wireless*;*WildTangent*;*UNIVERSITY*
- v{"usblist":[],"infected":[],"activated":false,"inittime":REDACTED}
- Myob.exe;translink.exe
- Myob.exe;translink.exe
- account,bank,balance,transfer
- ";}
- "ANTI-VIRUS": {
- "Rapport
- SafenSoft
- SysWatch
- McAfee
- McAfee
- Symantec
- Symantec
- Norton
- Kaspersky
- avast!
- ESET
- Microsoft
- ";}
Add Comment
Please, Sign In to add comment