Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Sender
- docusign@steelecreeksouth.com
- #Subjects
- You got invoice from DocuSign Service
- You got invoice from DocuSign Signature Service
- You received invoice from DocuSign Service
- You received %ROT:notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Signature Service
- You got invoice from DocuSign Electronic Service
- You received %ROT:notification from DocuSign Service
- You got %ROT:notification from DocuSign Electronic Service
- #Doc downloader domains
- wingsfingers.com
- datacntrs.com
- myyobe.biz
- hnigrp.com
- hniltd.com
- thatsocute.us
- dickswingsgrill.com
- total-powers.com
- dcssi.com
- cparealtorinc.com
- #Hancitor C2
- http://torsjogeca.com/4/forum.php
- http://dotorsfito.ru/4/forum.php
- http://hisbutterof.ru/4/forum.php
- #Payloads
- http://orgasmosfemeninos.net/wp-content/plugins/post-types-order/include/1
- http://happyellaafter.com/wp-content/plugins/regenerate-thumbnails/includes/1
- http://lauragordonblog.com/wp-content/plugins/html404/1
- http://grehu.net/wp-content/plugins/easy-tables-vc/lib/1
- http://www.panageries.com/includes/1
- http://orgasmosfemeninos.net/wp-content/plugins/post-types-order/include/2
- http://happyellaafter.com/wp-content/plugins/regenerate-thumbnails/includes/2
- http://lauragordonblog.com/wp-content/plugins/html404/2
- http://grehu.net/wp-content/plugins/easy-tables-vc/lib/2
- http://www.panageries.com/includes/2
- http://orgasmosfemeninos.net/wp-content/plugins/post-types-order/include/3
- http://happyellaafter.com/wp-content/plugins/regenerate-thumbnails/includes/3
- http://lauragordonblog.com/wp-content/plugins/html404/3
- http://grehu.net/wp-content/plugins/easy-tables-vc/lib/3
- http://www.panageries.com/includes/3
- #Panda Config
- t": "2.6.8",
- "check_config": 327685,
- "send_report": 655370,
- "check_update": 1966110,
- "url_config": "https://robwassotdint.ru/1kewoimzatybewoliowof.dat",
- "url_webinjects": "https://robwassotdint.ru/68webinjects.dat",
- "url_update": "https://robwassotdint.ru/1kewoimzatybewoliowof.exe",
- "url_plugin_webinject32": "https://robwassotdint.ru/68webinject32.bin",
- "url_plugin_webinject64": "https://robwassotdint.ru/68webinject64.bin",
- "remove_csp": 0,
- "inject_vnc": 0,
- "url_plugin_vnc32": "https://robwassotdint.ru/68vnc32.bin",
- "url_plugin_vnc64": "https://robwassotdint.ru/68vnc64.bin",
- "url_plugin_vnc_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
- "url_plugin_backsocks": "https://robwassotdint.ru/68backsocks.bin",
- "url_plugin_backsocks_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
- "url_plugin_grabber": "https://robwassotdint.ru/68grabber.bin",
- "grabber_pause": 2,
- "grab_softlist": 1,
- "grab_pass": 1,
- "grab_form": 1,
- "grab_cert": 1,
- "grab_cookie": 1,
- "grab_del_cookie": 0,
- "grab_del_cache": 0,
- "url_plugin_keylogger": "https://robwassotdint.ru/68keylogger.bin",
- "keylog_process": "cHV0dHkuZXhlAAA=",
- "screen_process": "cHV0dHkuZXhlAAA=",
- "reserved": "EHWYzK2iP0NudL9QxrsRIfKqEAkvVm8bPoNaVoe6sIaDCm5FCsU7HMa/0JKyA+OKKL0gGIXEqmWsckB+8m+LUK6ohAJv2qQOTBRVPiJ9P7sN8BMNbfRQFgMayV1dpjMm9C8V7gI="
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement