Advertisement
Guest User

10-18-2018: Gozi ISFB v2.18 Build 1

a guest
Oct 18th, 2018
420
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.63 KB | None | 0 0
  1. Unpacked Loader MD5: 022dd7910e3ea283596ba23fec4508bb
  2.  
  3. Bot ['2.18']
  4. Build ['01']
  5. Botnet/Group ID ['3087’]
  6. DGA TLDs ['com', 'ru', 'org']
  7. Server [’12’]
  8. Encryption key ['10291029JSJUYNHG']
  9. DGA CRC ['0x4eb7d2ca']
  10. DGA Base URL ['constitution.org/usdeclar.txt']
  11. Domains ['announcillon.com', 'dhsiwyqdlskwsqo.com', 'hq92lmdlcdnandwuq.com']
  12. Path: ['/images/']
  13.  
  14.  
  15. Blocklist 2nd Stage:
  16. tapretriat[.]com/RUI/levond.php?l=goks[1-7].xap
  17. derwagiete[.]com/RUI/levond.php?l=goks[1-7].xap
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement