Advertisement
vk_intel

2018-12-14: ISFB v215 & v214 & v300

Dec 14th, 2018
393
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.62 KB | None | 0 0
  1. MD5 (2018-12-14.isfbv215.loader.unpacked.vk.exe) = 8a4303afcee39635be826d6bbac1e50c
  2.  
  3. Bot ['2.15']
  4. Build ['165']
  5. Botnet/Group ID ['3154', '3155']
  6. DGA TLDs ['com', 'ru', 'org']
  7. Server [’12’]
  8. Encryption key ['10291029JSJUYNHG']
  9. DGA CRC ['0x4eb7d2ca']
  10. DGA Base URL ['constitution.org/usdeclar.txt']
  11. Domains ['roevinguef.com', 'sfernacrif.com', 'abregeousn.com']
  12. Path: ['/images/']
  13.  
  14. MD5 (2018-12-14.isfbv214.loader.unpacked.vk.exe) = a8c1709ca7becd32d79dd7fb2e219b40
  15.  
  16. Bot ['2.14']
  17. Build ['056']
  18. Botnet/Group ID ['4000']
  19. DGA TLDs ['com', 'ru', 'org']
  20. Server [’12’]
  21. Encryption key ['10291029JSJUYNHG']
  22. DGA CRC ['0x4eb7d2ca']
  23. DGA Base URL ['constitution.org/usdeclar.txt']
  24. Domains ['http://allooalel.club']
  25. Path: ['/images/']
  26.  
  27. MD5 (2018-12-14.isfbv300.loader.unpacked.vk.exe) = 41fff120955f52a2f92c20280feca376
  28.  
  29. Bot ['3.00']
  30. Build ['667']
  31. Botnet/Group ID ['40002']
  32. DGA TLDs ['com', 'ru', 'org']
  33. Encryption key ['ynL8iuZPneH9NUz5']
  34. DGA CRC ['0x4eb7d2ca']
  35. DGA Base URL ['constitution.org/usdeclar.txt']
  36. Domains ['https://brentleybag.com']
  37.  
  38. Payload Domains (ISFB v215):
  39.  
  40. tubpariang.com/KHZ/diuyz.php?l=skeb[1-14].tkn
  41. usteouraph.com/KHZ/diuyz.php?l=lyfx[1-14].tkn
  42. altwativar.com/KHZ/diuyz.php?l=skeb[1-14].tkn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement