Advertisement
vk_intel

2018-12-05: Gozi ISFB v215

Dec 5th, 2018
863
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. MD5 (2018-12-05.isfbv215.loader.decoded.vk.exe) = 271bfe3c03e0a31db8efd0adf1f99505
  2.  
  3. Bot ['2.15']
  4. Build ['165']
  5. Botnet/Group ID ['3140', '3141']
  6. DGA TLDs ['com', 'ru', 'org']
  7. Server [’12’]
  8. Encryption key ['10291029JSJUYNHG']
  9. DGA CRC ['0x4eb7d2ca']
  10. DGA Base URL ['constitution.org/usdeclar.txt']
  11. Domains ['isatawatag.com', 'bosototsuy.com', 'atamekihok.com']
  12. Path: ['/images/']
  13.  
  14. Payload Domain:
  15.  
  16. hayaushiru.com/KHZ/diuyz.php?l=boon[1-14].tkn
  17. tazukasash.com/KHZ/diuyz.php?l=gymk[1-14].tkn
  18. dewirasute.com/KHZ/diuyz.php?l=pryc[1-14].tkn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement