Advertisement
Bank_Security

Gootkit Banking Trojan is targeting Germany

Dec 1st, 2020
18,666
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.91 KB | None | 0 0
  1. Gootkit Banking Trojan is targeting Germany
  2. Indicators of Compromise
  3. Compromised websites downloading JavaScript loader:
  4.  
  5. docs.anscommerce[.]com
  6. ellsweb[.]net
  7. entrepasteles[.]supercurro.net
  8. m-uhde[.]de
  9. games.usc[.]edu
  10. doedlinger-erdbau[.]at
  11.  
  12. 3rd stage JavaScript C2s:
  13.  
  14. badminton-dillenburg[.]de
  15. alona[.]org[.]cy
  16. aperosaintmartin[.]com
  17.  
  18. Variant 1 (Gootkit):
  19.  
  20. NET loader [973d0318f9d9aec575db054ac9a99d96ff34121473165b10dfba60552a8beed4]
  21. Delphi PE [60aef1b657e6c701f88fc1af6f56f93727a8f4af2d1001ddfa23e016258e333f]
  22. PE stored in resources [327916a876fa7541f8a1aad3c2270c2aec913bc8898273d545dc37a85ef7307f]
  23. Variant 2 (REvil):
  24.  
  25. NET loader [0e451125eaebac5760c2f3f24cc8112345013597fb6d1b7b1c167001b17d3f9f]
  26. Delphi PE [d0e075a9346acbeca7095df2fc5e7c28909961184078e251f737f09b8ef892b6] – the ransomware
  27. PE stored in resources [a7e363887e9a7cc7f8de630b12005813cb83d6e3fc3980f735df35dccf5a1341] – a helper component
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement