vk_intel

6-5-2018: RE: #PandaBanker #malware config

Jun 4th, 2018
535
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.75 KB | None | 0 0
  1. "BotInfo": {
  2. "systime": “TIME_UNIX”,
  3. "process": "svchost.exe",
  4. "user": “USER”,
  5. "id": “N/A”,
  6. "botnet": "2.6.9",
  7. "version": "2.6.10"
  8. }
  9.  
  10. {
  11. "botnet": "2.6.9",
  12. "check_config": 327685,
  13. "send_report": 327685,
  14. "check_update": 327685,
  15. "url_config": "https://ioxicjkdkc.abkhazia.su/1ishuwuycywgeacqylyik.dat",
  16. "url_webinjects": "https://ioxicjkdkc.abkhazia.su/webinjects.dat",
  17. "url_update": "https://ioxicjkdkc.abkhazia.su/1ishuwuycywgeacqylyik.exe",
  18. "url_plugin_webinject32": "https://ioxicjkdkc.abkhazia.su/webinject32.bin",
  19. "url_plugin_webinject64": "https://ioxicjkdkc.abkhazia.su/webinject64.bin",
  20. "remove_csp": 1,
  21. "inject_vnc": 1,
  22. "url_plugin_vnc32": "https://ioxicjkdkc.abkhazia.su/vnc32.bin",
  23. "url_plugin_vnc64": "https://ioxicjkdkc.abkhazia.su/vnc64.bin",
  24. "url_plugin_vnc_backserver": "niZ/YUcKekwvK43NAKh8c9O8lCQ=",
  25. "url_plugin_backsocks": "https://ioxicjkdkc.abkhazia.su/backsocks.bin",
  26. "url_plugin_backsocks_backserver": "niZ/YUcKekwvK43NAKh8c9O8lCQ=",
  27. "url_plugin_grabber": "https://ioxicjkdkc.abkhazia.su/grabber.bin",
  28. "grabber_pause": 1,
  29. "grab_softlist": 1,
  30. "grab_pass": 1,
  31. "grab_form": 1,
  32. "grab_cert": 1,
  33. "grab_cookie": 1,
  34. "grab_del_cookie": 0,
  35. "grab_del_cache": 0,
  36. "url_plugin_keylogger": "https://ioxicjkdkc.abkhazia.su/keylogger.bin",
  37. "keylog_process": "ZmlyZWZveC5leGUAY2hyb21lLmV4ZQBpZXhwbG9yZS5leGUAb3BlcmEuZXhlAAA=",
  38. "screen_process": "cHV0dHkuZXhlAAA=",
  39. "reserved": "JxZpa8bZHbYND7TCk20lXXoXuwGmEB3i0TqqBJeBg3Hu2XiR/ig48ujvYputnbWoSYH5X/s90QVl9S45nyQ/qXiSIsYWe1lr3rs2qDqt4TV/DcfGieIG1RM3KWCntnZZDHlD7TymDqs4mozbR8OU+MDNOvuQz084/iyLlS/pT3pbjjUHK4zPwTH5beefZWRvnbFyfVEero04OqXMmw6JS9nNhCAKDSjxp2SefvGgTzRsB8cavYKkWm0JGAzgA90M8MfRa7fQ6F/kHZeYGXeFNhCQL8lgTrq8fryGK99/O9cnwolGKxCqBFa8dxWQqYM8YMhVjkl+LoDMIZfR4MS1qHEztD5eYV+kbQc="
  40. }
Add Comment
Please, Sign In to add comment