Advertisement
vk_intel

10-30-2018: Gozi ISFB

Oct 30th, 2018
518
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.66 KB | None | 0 0
  1. MD5 (10-30-2018.isfb.loader.decoded.vk.exe) = 15305122f52d3347e3c7f459ad063c7b
  2.  
  3.  
  4. Bot ['2.17']
  5. Build ['39']
  6. Botnet/Group ID ['3096’, '3097']
  7. DGA TLDs ['com', 'ru', 'org']
  8. Server [’12’]
  9. Encryption key ['10291029JSJUYNHG']
  10. DGA CRC ['0x4eb7d2ca']
  11. DGA Base URL ['constitution.org/usdeclar.txt']
  12. Domains ['qibrandiat.com ', 'dhsiwyqdlskwsqo.com', 'hq92lmdlcdnandwuq.com']
  13. Path: ['/images/']
  14.  
  15. ISFB 2nd Stage Domains:
  16.  
  17. wolthorifi.com/TYJ/wwnox.php?l=juxe[1-10].xap
  18. yaticaterm.com/TYJ/wwnox.php?l=juxe[1-10].xap
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement