Advertisement
vk_intel

7-11-2018: #Gozi #ISFB Bot Version 2.14 Targeting IT

Jul 11th, 2018
1,116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.61 KB | None | 0 0
  1. MD5: 694bfc302dfe1da71c1a5338a1864d43
  2.  
  3. Botnet ID ['1911']
  4. Bot version ['2.14']
  5. Bot build ['999']
  6. Server id ['12']
  7. CRC hash ['67aab']
  8. Encryption key ['10291029JSJUYNHG']
  9. Domains ['foqiweuqwenasjdd.com', 'uhqweuansdjqwndq.com']
  10. DGA Base URL ['com', 'ru', 'org']
  11.  
  12. Domains:
  13. ['95.181.178.128','95.181.179.31','185.161.210.169','185.20.185.228','195.123.218.22', '195.123.209.104', '195.123.224.194', '93.171.216.104', '93.171.216.102']
  14.  
  15. URI Path:
  16.  
  17. /images/
  18.  
  19. Replica/Webinject:
  20.  
  21. https://sitergenis.com/it/
  22.  
  23. VNC Module:
  24.  
  25. clickara.com/images/vnc32sk.rar
  26. clickara.com/images/vnc64sk.rar
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement