Advertisement
vk_intel

2018-12-07: ISFB Gozi v215 & v300

Dec 7th, 2018
394
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.01 KB | None | 0 0
  1. MD5 (2018-12-07.isfbv215.loader.decoded.vk.exe) = 432dd31c7fdee2a58e6bad527b3626b0
  2. MD5 (2018-12-07.isfbv300.loader.decoded.vk.exe) = a1d90e56a7084ae5f006397b5d4de002
  3.  
  4. Bot ['2.15']
  5. Build ['165']
  6. Botnet/Group ID ['3146', '3147']
  7. DGA TLDs ['com', 'ru', 'org']
  8. Server [’12’]
  9. Encryption key ['10291029JSJUYNHG']
  10. DGA CRC ['0x4eb7d2ca']
  11. DGA Base URL ['constitution.org/usdeclar.txt']
  12. Domains ['nublatoste.com', 'jabbellabi.com', 'zeurnatine.com']
  13. Path: ['/images/']
  14.  
  15.  
  16.  
  17. Bot ['3.00']
  18. Build ['665']
  19. Botnet/Group ID ['10000']
  20. DGA TLDs ['com', 'ru', 'org']
  21. Server [’12’]
  22. Encryption key ['2bf79PpFMluZ3xL0']
  23. Domains ['https://akamaicln.com']
  24.  
  25.  
  26. ISFB v215 Payload Domains:
  27.  
  28. ledibermen.com/KHZ/diuyz.php?l=rewb[1-14].tkn
  29. caentivage.com/KHZ/diuyz.php?l=rewb[1-14].tkn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement