Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- http://0.le4net00.net
- http://ipb.securedserverspace.ltd
- http://compute.deutschlandaws.com
- http://deploy.static.blazingtechnologies.io
- http://bc.fastusercontent.nl
- exodus
- bitcoin
- electrum
- binance
- kraken
- bittrex
- litecoin
- monero
- myether
- coinbase
- bitfinex
- bitmex
- kucoin
- coinmarket
- blockchain
- cryptom
- cryptonator
- coinomi
- poloniex
- jaxx
- #########################################################################################
- rule HfsVibisi_E172_bin
- {
- meta:
- description = "HfsVibisi.E172"
- author = "James_inthe_box"
- reference = "https://app.any.run/tasks/2755e852-6113-44b8-a3d9-e421234c33c5"
- date = "2019/06"
- maltype = "Bot"
- strings:
- $string1 = "FileZilla\\"
- $string2 = "sitemanager.xml"
- $string3 = "recentservers.xml"
- $string4 = "U_BotUpdate"
- $string5 = "botsfolder"
- $string6 = "logsfolder"
- $string7 = "UnitKeyLogger"
- $string8 = "untBotUtils"
- condition:
- uint16(0) == 0x5A4D and all of ($string*) and filesize < 800KB
- }
- rule HfsVibisi_E172_mem
- {
- meta:
- description = "HfsVibisi.E172"
- author = "James_inthe_box"
- reference = "https://app.any.run/tasks/2755e852-6113-44b8-a3d9-e421234c33c5"
- date = "2019/06"
- maltype = "Bot"
- strings:
- $string1 = "FileZilla\\"
- $string2 = "sitemanager.xml"
- $string3 = "recentservers.xml"
- $string4 = "U_BotUpdate"
- $string5 = "botsfolder"
- $string6 = "logsfolder"
- $string7 = "UnitKeyLogger"
- $string8 = "untBotUtils"
- condition:
- all of ($string*) and filesize > 800KB
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement