Advertisement
vk_intel

10-24-2018: Gozi ISFB

Oct 24th, 2018
469
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.88 KB | None | 0 0
  1. MD5 (10-24-2018.isfb.client.unpacked.exe.vk.dll) = 10887dbdf66fe858fbbbc6254818f76b
  2. MD5 (10-24-2018.isfb.loader.unpacked.exe.vk.exe) = 372116122ca64db56fc02317d5ea4de3
  3.  
  4. Bot ['2.17']
  5. Build ['38']
  6. Botnet/Group ID ['1000]
  7. DGA TLDs ['com', 'ru', 'org']
  8. Server ['110']
  9. Encryption key ['K2u7G0lE4u1VoS0V']
  10. DGA CRC ['0x4eb7d2ca']
  11. DGA Base URL ['constitution.org/usdeclar.txt']
  12. Domains ['doc.rendes.at/wpapi', 'torafy.cn/wpapi', 'io.ledalco.at/wpapi', 'int.gardeon.at/wpapi', 'api.rendes.at/wpapi', 'rest.relonter.at/wpapi', 'yraco.cn/wpapi', 'apt.zorip.at/wpapi', 'vi.relonter.at/wpapi', 'pr.jingletrip.at/wpapi', 'gl.filmbounce.at/wpapi', 'in.ledalco.at/wpapi', 'ht.letosos.at/wpapi', 'harent.cn/wpapi', 'h2.letosos.at/wpapi']
  13. Path: ['/images/']
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement