Advertisement
G0dR4p3

Gozi_Ursnif_Dreambot_04-07-2019

Jul 4th, 2019
369
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.49 KB | None | 0 0
  1. #Gozi #Ursnif #Dreambot
  2. -------------------------------------
  3. 04-07-2019
  4. -------------------------------------
  5. Main object- "31f70ab76648198e031b767815027a5db81ed856408a1634371ba473f1280906.bin.gz"
  6. sha256 dd95a5726337bef005cc05859a71d37a3de4e3fbbf9d46d8fa692c0cf1888078
  7. sha1 904e95a7684fbecb8f3c39906d203689cb6a0585
  8. md5 600e95687e556fd6588078c1caf9eeb4
  9. ssdeep_parts [object Object]
  10. Dropped executable file
  11. sha256 C:\Users\admin\GcgFtS.exe fa5c557e2509843701dbdfcfa80daf37e72dbc107ba511e45922af7a35e0e1c9
  12. DNS requests
  13. domain hbartonkwiey.xyz
  14. domain cio12y21e99.top
  15. domain resolver1.opendns.com
  16. domain myip.opendns.com
  17. domain 222.222.67.208.in-addr.arpa
  18. domain taniyahfabiola.info
  19. domain www.fallasa.it
  20. domain fallasa.it
  21. Connections
  22. ip 45.89.230.184
  23. ip 208.67.222.222
  24. ip 85.143.218.95
  25. ip 5.39.119.175
  26. ip 62.149.140.21
  27. HTTP/HTTPS requests
  28. url http://fallasa.it/js/client.rar
  29. url http://hbartonkwiey.xyz/iwq/wpsk.php?l=hom1.ks
  30. url http://www.fallasa.it/js/client.rar
  31. url http://cio12y21e99.top/images/tYY2sOozXDzvMrB1SjbjVCE/XN9XppLwql/3DLCbThel9ZlPR4vl/gVyvc4PE_2Bl/Xuz9ch14avN/ws7xC5TiIRP3E_/2Bu1yutDL83wx1Smc0Dy9/J70HKYO64JjADhh8/q9GdodcWkY_2FX8/7_2FWQGESmUIHiJEFk/IUULKGZP9/YReQkZ9ZX4Ou_2/F.avi
  32. url http://cio12y21e99.top/favicon.ico
  33. url http://cio12y21e99.top/images/3eu_2F4wv66z9/fSBu6KIX/vpgr_2B0GkUznG7xNJymXS0/V92Nyga_2F/GeqNSbwZOfIHAy9wS/hWXk_2BSJ3wb/81MgnvRFg0h/xQ0j4uew6TcsL4/zlXIzRx0YnsKm3d0xrtGt/WH9ZmJNuK_2Fyol5/N75L8FS4/LDGluZm.avi
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement