ring0x0

2018-05-01-Hancitor

May 1st, 2018
373
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.07 KB | None | 0 0
  1. Subjects: U.S. Bank Alert, U.S. Bank Notification, U.S. Bank Notice, U.S. Bank Message
  2.  
  3. #Doc Download Domains:
  4. actuneupca.com
  5. chiropracticlibrary.com
  6. clifmays.com
  7. expressairparcel.com
  8. gamification4you.com
  9. ifewholehomefans.com
  10. ifewholehousefan.com
  11. ifewholehousefan.net
  12. ifewholehousefans.com
  13. ifewholehousefans.info
  14. ifewholehousefans.net
  15. interfaithelectricandsolar.co
  16. interfaithelectricnsolar.co
  17. lmperfumes.com
  18. spinalrt.com
  19. superiorcomfortprohvac.com
  20. superiorhvacuniversity.com
  21. triadhangout.com
  22. triadpain.com
  23. triadpaingroup.com
  24.  
  25. #Hancitor C2s
  26. hxxp://supratparfa.com/4/forum.php
  27. hxxp://losupsofof.ru/4/forum.php
  28. hxxp://depeparand.ru/4/forum.php
  29.  
  30. #Hancitor payload links
  31. hxxp://kdprvirtual.com/wp-content/plugins/duplicate-post/1
  32. hxxp://animalhealthcenterinc.com/wp-content/plugins/post-expirator/1
  33. hxxp://rogersonenterprises.com/blog/wp-content/plugins/jetpack/1
  34. hxxp://militaryschools101.com/wp-content/plugins/nofollow-for-external-link/1
  35. hxxp://bestwptricks.com/wp-content/plugins/polldaddy/1
  36. hxxp://kdprvirtual.com/wp-content/plugins/duplicate-post/2
  37. hxxp://animalhealthcenterinc.com/wp-content/plugins/post-expirator/2
  38. hxxp://rogersonenterprises.com/blog/wp-content/plugins/jetpack/2
  39. hxxp://militaryschools101.com/wp-content/plugins/nofollow-for-external-link/2
  40. hxxp://bestwptricks.com/wp-content/plugins/polldaddy/2
  41. hxxp://kdprvirtual.com/wp-content/plugins/duplicate-post/3
  42. hxxp://animalhealthcenterinc.com/wp-content/plugins/post-expirator/3
  43. hxxp://rogersonenterprises.com/blog/wp-content/plugins/jetpack/3
  44. hxxp://militaryschools101.com/wp-content/plugins/nofollow-for-external-link/3
  45. hxxp://bestwptricks.com/wp-content/plugins/polldaddy/3
  46.  
  47. #Pony C2s
  48. hxxp://supratparfa.com/mlu/forum.php
  49. hxxp://losupsofof.ru/mlu/forum.php
  50. hxxp://depeparand.ru/mlu/forum.php
  51.  
  52. #Panda Config
  53. t": "2.6.8",
  54. "check_config": 327685,
  55. "send_report": 655370,
  56. "check_update": 1966110,
  57. "url_config": "hxxps://bithetbuter.ru/1afhecysoduunselisoig.dat",
  58. "url_webinjects": "hxxps://bithetbuter.ru/68webinjects.dat",
  59. "url_update": "hxxps://bithetbuter.ru/1afhecysoduunselisoig.exe",
  60. "url_plugin_webinject32": "hxxps://bithetbuter.ru/68webinject32.bin",
  61. "url_plugin_webinject64": "hxxps://bithetbuter.ru/68webinject64.bin",
  62. "remove_csp": 0,
  63. "inject_vnc": 0,
  64. "url_plugin_vnc32": "hxxps://bithetbuter.ru/68vnc32.bin",
  65. "url_plugin_vnc64": "hxxps://bithetbuter.ru/68vnc64.bin",
  66. "url_plugin_vnc_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  67. "url_plugin_backsocks": "hxxps://bithetbuter.ru/68backsocks.bin",
  68. "url_plugin_backsocks_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  69. "url_plugin_grabber": "hxxps://bithetbuter.ru/68grabber.bin",
  70. "grabber_pause": 2,
  71. "grab_softlist": 1,
  72. "grab_pass": 1,
  73. "grab_form": 1,
  74. "grab_cert": 1,
  75. "grab_cookie": 1,
  76. "grab_del_cookie": 0,
  77. "grab_del_cache": 0,
  78. "url_plugin_keylogger": "hxxps://bithetbuter.ru/68keylogger.bin",
  79. "keylog_process": "cHV0dHkuZXhlAAA=",
  80. "screen_process": "cHV0dHkuZXhlAAA=",
  81. "reserved": "EHWYzK2iP0NgfKxV26oNNeKpEAkvVm8bNJ1SS4imvpKRB25bHco/HcGjwZSyA+OKKL0gGIXEqmWsYkZo7WuMQbSohRkv3P9TCkMJKzx9NL4D9gUNY+VQCBUX01ZU+zZp5E5h"
Add Comment
Please, Sign In to add comment