Advertisement
vk_intel

2018-12-03: ISFB Gozi v215

Dec 3rd, 2018
890
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.35 KB | None | 0 0
  1. MD5 (2018-12-03.isfbv215.client.decoded.vk.dll) = c4762475ada82c2108a291b02c56a270
  2. MD5 (2018-12-03.isfbv215.loader.decoded.vk.exe) = 96f738c787dbfd3c3ad7d217e758664e
  3.  
  4. Bot ['2.15']
  5. Build ['165']
  6. Botnet/Group ID ['3135', '3137']
  7. DGA TLDs ['com', 'ru', 'org']
  8. Server [’12’]
  9. Encryption key ['10291029JSJUYNHG']
  10. DGA CRC ['0x4eb7d2ca']
  11. DGA Base URL ['constitution.org/usdeclar.txt']
  12. Domains ['oshokasara.com', 'chokatawan.com', 'guridorosh.com']
  13. Path: ['/images/']'
  14.  
  15. Bot ['2.15']
  16. Build ['165']
  17. Botnet/Group ID ['3133', '3134']
  18. DGA TLDs ['com', 'ru', 'org']
  19. Server [’12’]
  20. Encryption key ['10291029JSJUYNHG']
  21. DGA CRC ['0x4eb7d2ca']
  22. DGA Base URL ['constitution.org/usdeclar.txt']
  23. Domains ['zweideckei.com', 'ziebelschr.com', 'endetztera.com']
  24. Path: ['/images/']
  25.  
  26.  
  27. Payload Domains:
  28.  
  29. hayaushiru.com/KHZ/diuyz.php?l=boon[1-14].tkn
  30. tazukasash.com/KHZ/diuyz.php?l=gymk[1-14].tkn
  31. navectrece.com/SXC/ptyie.php?l=geor[1-14].tkn
  32. wizoidiazi.com/SXC/ptyie.php?l=geor[1-14].tkn
  33. koentacist.com/KHZ/diuyz.php?l=bebu[1-14].tkn
  34. thipissney.com/KHZ/diuyz.php?l=bebu[1-14].tkn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement