vk_intel

6-23-2018: #Panda Banker Chain IOCs

Jun 23rd, 2018
387
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.58 KB | None | 0 0
  1. IOCs:
  2. Word Document Lure MD5:
  3. a49bb89bf2c75c988b187cfc6c0590bb
  4.  
  5. Emotet Loader MD5:
  6. dfe725896c908041ad6c0e1293399265
  7.  
  8. Panda Banker MD5:
  9. c78bf8ed0768f2abe150e5c84c901dd1
  10.  
  11. CONFIG:
  12. {
  13. "botnet": "2.6.9",
  14. "check_config": 327685,
  15. "send_report": 655370,
  16. "check_update": 1966110,
  17. "url_config": "https://RXDirectories.top/2hilufymailnizyxoador.dat",
  18. "url_webinjects": "https://RXDirectories.top/webinjects_new2.dat",
  19. "url_update": "https://RXDirectories.top/2hilufymailnizyxoador.exe",
  20. "url_plugin_webinject32": "https://RXDirectories.top/webinject32_new2.bin",
  21. "url_plugin_webinject64": "https://RXDirectories.top/webinject64_new2.bin",
  22. "remove_csp": 0,
  23. "inject_vnc": 0,
  24. "url_plugin_vnc32": "https://RXDirectories.top/vnc32_new2.bin",
  25. "url_plugin_vnc64": "https://RXDirectories.top/vnc64_new2.bin",
  26. "url_plugin_vnc_backserver": "p8bYQMGmXIahkiYgghgivVRVDg0=",
  27. "url_plugin_backsocks": "https://RXDirectories.top/backsocks_new2.bin",
  28. "url_plugin_backsocks_backserver": "p8bYQMGmXIahkiYgghgivVRVDg0=",
  29. "url_plugin_grabber": "https://RXDirectories.top/grabber_new2.bin",
  30. "grabber_pause": 2,
  31. "grab_softlist": 1,
  32. "grab_pass": 1,
  33. "grab_form": 1,
  34. "grab_cert": 0,
  35. "grab_cookie": 0,
  36. "grab_del_cookie": 0,
  37. "grab_del_cache": 0,
  38. "url_plugin_keylogger": "https://RXDirectories.top/keylogger_new2.bin",
  39. "keylog_process": "cHV0dHkuZXhlAAA=",
  40. "screen_process": "cHV0dHkuZXhlAAA=",
  41. "reserved": "Atzk0Gc0nABj9wUAVmi0tJVRcaUYhRDJXKqmBh2RiSJpq3iDnH6+eNDY06HA9+TQz5H2Tjr+3nu7sHXUZtPt21bC9HI6vMlmMA3X2189ChUX9TV1/K5a25HhUOeM+/FdGOUeXn5a2shKsi68WxPa9OLTxNvDiK6k2yNzbSC99mCKXLt3wsiETCpOe+ncy7OHbVnAQ17Qgp0Fac3gBjb7"
  42. }
Add Comment
Please, Sign In to add comment