sysopfb

Decoded strings from jim332 trickbot

Oct 16th, 2018
430
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.69 KB | None | 0 0
  1. 1
  2. DIAL
  3. NAT status
  4. failed
  5. client is behind NAT
  6. client is not behind NAT
  7. DNSBL
  8. listed
  9. not listed
  10. SINJ
  11. %s %s
  12. spk
  13. tmp
  14. .tmp
  15. config.conf
  16. user
  17. RES
  18. group_tag
  19. %s sTart
  20. SYSTEM
  21. <?xml version="1.0" encoding="UTF-16"?>
  22. <Task version="1.2"
  23. xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
  24. <RegistrationInfo>
  25. <Version>1.0.1</Version>
  26. <Description>Ms_Net_Cash</Description>
  27. <URI></URI>
  28. </RegistrationInfo>
  29. <Triggers>
  30.  
  31. <TimeTrigger>
  32. <Repetition>
  33. <Interval>PT10M</Interval>
  34. <Duration>P415DT15H59M</Duration>
  35. <StopAtDurationEnd>false</StopAtDurationEnd>
  36. </Repetition>
  37. <StartBoundary>
  38. </StartBoundary>
  39. <Enabled>true</Enabled>
  40. </TimeTrigger>
  41. </Triggers>
  42. <Principals>
  43. <Principal id="Author">
  44.  
  45. </Principal>
  46. </Principals>
  47. <Settings>
  48. <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
  49. <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
  50. <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
  51. <AllowHardTerminate>false</AllowHardTerminate>
  52. <StartWhenAvailable>true</StartWhenAvailable>
  53. <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
  54. <IdleSettings>
  55. <StopOnIdleEnd>true</StopOnIdleEnd>
  56. <RestartOnIdle>false</RestartOnIdle>
  57. </IdleSettings>
  58. <AllowStartOnDemand>true</AllowStartOnDemand>
  59. <Enabled>true</Enabled>
  60. <Hidden>true</Hidden>
  61. <RunOnlyIfIdle>false</RunOnlyIfIdle>
  62. <WakeToRun>false</WakeToRun>
  63. <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>
  64. <Priority>7</Priority>
  65. </Settings>
  66. <Actions Context="Author">
  67. <Exec>
  68. <Command>
  69. </Command>
  70. </Exec>
  71. </Actions>
  72. </Task>
  73.  
  74. <BootTrigger>
  75. <Enabled>true</Enabled>
  76.  
  77. </BootTrigger>
  78.  
  79. <RunLevel>HighestAvailable</RunLevel>
  80. <GroupId>NT AUTHORITY\SYSTEM</GroupId>
  81. <LogonType>InteractiveToken</LogonType>
  82.  
  83. <LogonType>InteractiveToken</LogonType>
  84. <RunLevel>LeastPrivilege</RunLevel>
  85. <UserId>
  86. </UserId>
  87.  
  88. %Y-%m-%dT%H:%M:%S
  89. %s.%s
  90. %s.%s.%s.%s
  91. Msnetcs
  92. module
  93. name
  94. ctl
  95. srv
  96. /%s/%s/0/%s/%s/%s/%s/%s/
  97. /%s/%s/1/%s/
  98. /%s/%s/5/%s/
  99. /%s/%s/10/%s/%s/%d/
  100. /%s/%s/14/%s/%s/0/
  101. /%s/%s/23/%d/
  102. /%s/%s/25/%s/
  103. %s/%s/63/%s/%s/%s/%s/
  104. noname
  105. %s/%s/64/%s/%s/%s/
  106. data
  107. info
  108. No params
  109. Invalid params count
  110. Win32 error
  111. Decode from BASE64 error
  112. start
  113. Unable to load module from server
  114. GetParentInfo error
  115. Process was unloaded
  116. Start failed
  117. release
  118. Process has been finished
  119. Module was unloaded
  120. Process has been finished
  121. Control failed
  122. Module already unloaded
  123. %d%d%d.
  124. servconf
  125. expir
  126. plugins
  127. psrv
  128. Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
  129. Windows 10 Server
  130. Windows 10
  131. Windows Server 2012 R2
  132. Windows 8.1
  133. Windows Server 2012
  134. Windows 8
  135. Windows Server 2008 R2
  136. Windows 7
  137. Windows Server 2008
  138. Windows Vista
  139. Windows Server 2003
  140. Windows XP
  141. Windows 2000
  142. Unknown
  143. x64
  144. x86
  145. %s %s SP%d
  146. Ncrypt.dll
  147. Bcrypt.dll
  148. NCryptOpenStorageProvider
  149. NCryptImportKey
  150. NCryptDeleteKey
  151. NCryptFreeObject
  152. BCryptOpenAlgorithmProvider
  153. BCryptImportKeyPair
  154. BCryptGetProperty
  155. BCryptVerifySignature
  156. BCryptCloseAlgorithmProvider
  157. BCryptDestroyKey
  158. shlwapi
  159. UrlEscapeW
  160. GET
  161. POST
  162. 0.0.0.0
  163. kernel32.dll
  164. HeapAlloc
  165. GetProcessHeap
  166. HeapFree
  167. HeapReAlloc
  168. Data\
  169. %s%s_configs\
  170. %s%s
  171. <moduleconfig>*</moduleconfig>
  172. autostart
  173. yes
  174. sys
  175. processname
  176. autoconf
  177. autocontrol
  178. needinfo
  179. control
  180. arg
  181. conf
  182. file
  183. period
  184. name
  185. id
  186. ip
  187. parentfiles
  188. Module has already been loaded
  189. Create ZP failed
  190. Find P failed
  191. Load to P failed
  192. Run D failed
  193. Load to M failed
  194. Start
  195. Control
  196. FreeBuffer
  197. Release
  198. svchost.exe
  199. SignalObjectAndWait
  200. WaitForSingleObject
  201. CloseHandle
  202. ResetEvent
  203. ExitProcess
  204. LoadLibraryW
  205. GetProcAddress
  206. wtsapi32
  207. WTSEnumerateSessionsA
  208. WTSFreeMemory
  209. WTSGetActiveConsoleSessionId
  210. WTSQueryUserToken
  211. winsta0\default
  212. ------Boundary%08X
  213. Content-Type: multipart/form-data; boundary=%s
  214. Content-Length: %d
  215.  
  216.  
  217.  
  218. --%s
  219. Content-Disposition: form-data; name="%S"
  220.  
  221.  
  222.  
  223. --%s--
  224.  
  225.  
  226.  
  227. Global\Muta
  228. D:(A;;GA;;;WD)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;RC)
  229. ssert
  230. expir
  231. checkip.amazonaws.com
  232. ipecho.net
  233. ipinfo.io
  234. api.ipify.org
  235. icanhazip.com
  236. myexternalip.com
  237. wtfismyip.com
  238. ip.anysrc.net
  239. /plain
  240. /ip
  241. /raw
  242. /text
  243. /plain/clientip
  244. 1045
  245. client_id
  246. Module is not valid
  247. GetNativeSystemInfo
  248. zen.spamhaus.org
  249. cbl.abuseat.org
  250. b.barracudacentral.org
  251. dnsbl-1.uceprotect.net
  252. spam.dnsbl.sorbs.net
  253. ECDSA_P384
  254. ECCPUBLICBLOB
  255. SignatureLength
  256. VERS
  257. InitializeCriticalSection
  258. EnterCriticalSection
  259. LeaveCriticalSection
  260. ModuleQuery
  261. ver.txt
  262. path
  263. working
  264. Global\%08lX%04lX%lu
  265. WinDefend
  266. MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
  267. MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths
  268. MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths
  269. DEBG
  270. FAQ
  271. README.md
  272. %s%s
  273. info.dat
  274. .onion
  275. %s %S HTTP/1.1
  276. Host: %s%s%S
  277. POST
  278. GET
  279.  
  280.  
  281.  
  282.  
  283. Content-Length:
  284. 174.127.217.73:55554
  285. 162.247.72.201:443
  286. 185.13.39.197:443
  287. 88.99.216.194:9001
  288. 185.22.172.237:443
  289. 199.249.223.62:443
  290. 2.137.16.245:9001
  291. 84.40.112.70:9001
  292. 212.47.246.229:9003
  293. 159.89.151.231:9001
  294. 69.163.34.173:443
  295. 83.163.164.15:9003
  296. 82.118.17.235:443
  297. 37.252.190.176:443
  298. 185.41.154.130:9001
  299. cmd.exe
  300. fifty
  301. WantRelease
  302. \iocopy
  303. api.ipify.org
  304. api.ip.sb
  305. ident.me
  306. www.myexternalip.com
  307. /?format=text
  308. path
  309. CI failed, 0x%x
  310. pIT NULL
  311. pIT connect failed, 0x%x
  312. pIT GetFolder failed, 0x%x
  313. Win10, Reg success
  314. Win10, Reg failed
  315. Create xml failed
  316. Create xml2 failed
  317. Register u failed, 0x%x
  318. Register s failed, 0x%x
  319. autorun
  320. <LogonTrigger>
  321. <Enabled>true</Enabled>
  322.  
  323. </LogonTrigger>
  324.  
  325. CreateThread
  326. GetComputerNameW
  327. lstrcmpW
  328. lstrlenW
  329. GetFullPathNameW
  330. FindFirstFileW
  331. FindResourceW
  332. FreeLibrary
  333. LoadResource
  334. GetModuleHandleW
  335. SetFileTime
  336. lstrcpynW
  337. GetLastError
  338. FindClose
  339. LockResource
  340. GetSystemInfo
  341. FindNextFileW
  342. GetFileTime
  343. LoadLibraryA
  344. lstrcmpA
  345. SetFileAttributesW
  346. CreateDirectoryW
  347. WaitForSingleObject
  348. SignalObjectAndWait
  349. SetEvent
  350. CreateRemoteThread
  351. OpenProcess
  352. VirtualFreeEx
  353. ReadProcessMemory
  354. TerminateProcess
  355. VirtualProtectEx
  356. VirtualAllocEx
  357. ResetEvent
  358. GetExitCodeThread
  359. CreateEventW
  360. DuplicateHandle
  361. WriteProcessMemory
  362. ResumeThread
  363. CreateMutexW
  364. LocalFree
  365. lstrcpyW
  366. DeleteFileW
  367. SetCurrentDirectoryW
  368. EnterCriticalSection
  369. MoveFileW
  370. GetTempPathW
  371. GetStartupInfoW
  372. GetModuleFileNameW
  373. GetFileAttributesW
  374. LeaveCriticalSection
  375. Sleep
  376. InitializeCriticalSectionAndSpinCount
  377. GetTickCount
  378. MoveFileExW
  379. CreateProcessW
  380. GetTempFileNameW
  381. lstrcmpiW
  382. CreateFileW
  383. ReadFile
  384. WriteFile
  385. SetFilePointer
  386. GetVersion
  387. CloseHandle
  388. GetVersionExW
  389. GetCurrentProcess
  390. GetSystemTimeAsFileTime
  391. GetCurrentProcessId
  392. lstrlenA
  393. UnhandledExceptionFilter
  394. SetUnhandledExceptionFilter
  395. GetCurrentThreadId
  396. QueryPerformanceCounter
  397. GetModuleHandleA
  398. WideCharToMultiByte
  399. MultiByteToWideChar
  400. Process32FirstW
  401. Process32NextW
  402. CreateToolhelp32Snapshot
  403. ADVAPI32.dll
  404. GetUserNameW
  405. GetTokenInformation
  406. LookupAccountSidW
  407. DuplicateTokenEx
  408. CreateProcessAsUserW
  409. EqualSid
  410. OpenProcessToken
  411. FreeSid
  412. AllocateAndInitializeSid
  413. CryptDestroyKey
  414. CryptHashData
  415. CryptDestroyHash
  416. CryptDecrypt
  417. CryptCreateHash
  418. CryptImportKey
  419. ConvertStringSecurityDescriptorToSecurityDescriptorW
  420. CryptReleaseContext
  421. CryptSetKeyParam
  422. CryptAcquireContextW
  423. CryptGetHashParam
  424. LookupPrivilegeValueW
  425. AdjustTokenPrivileges
  426. RevertToSelf
  427. RegCreateKeyExW
  428. RegCloseKey
  429. RegOpenKeyExW
  430. RegSetValueExW
  431. SetNamedSecurityInfoW
  432. SetSecurityInfo
  433. GetSecurityInfo
  434. SetEntriesInAclW
  435. GetLengthSid
  436. CopySid
  437. InitializeSecurityDescriptor
  438. SetSecurityDescriptorDacl
  439. ole32.dll
  440. CoCreateInstance
  441. CoUninitialize
  442. CRYPT32.dll
  443. CryptStringToBinaryW
  444. CryptBinaryToStringW
  445. SHLWAPI.dll
  446. PathFindFileNameW
  447. PathAddBackslashW
  448. PathRenameExtensionW
  449. StrStrIW
  450. PathRemoveBackslashW
  451. PathRemoveFileSpecW
  452. PathFindExtensionW
  453. ntdll.dll
  454. NtQueryInformationProcess
  455. IPHLPAPI.dll
  456. GetAdaptersInfo
  457. USERENV.dll
  458. CreateEnvironmentBlock
  459. DestroyEnvironmentBlock
  460. LoadUserProfileW
  461. UnloadUserProfile
Add Comment
Please, Sign In to add comment