Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ---= GANDCRAB =--- (unpacked)
- Hash: 7503351b46e00a2ca012bebc4ea6d3271a93a2711f41636753ffb61f2fec64d0
- https://www.virustotal.com/#/file-analysis/ZDY4NGRiMDA0NDJmYTg2N2FiZGNiZTRiYzlkMDNkY2I6MTUxNjk4MTc4NA==
- RANSOMWARE VARIABLE:
- ransom_id
- os_bit
- os_major
- pc_keyb
- pc_lang
- pc_group
- pc_name
- pc_user
- ransom_id=
- {USERID}
- %s%s
- open
- Global\
- Process Check:
- msftesql.exe
- sqlagent.exe
- sqlbrowser.exe
- sqlservr.exe
- sqlwriter.exe
- oracle.exe
- ocssd.exe
- dbsnmp.exe
- synctime.exe
- mydesktopqos.exe
- agntsvc.exeisqlplussvc.exe
- xfssvccon.exe
- mydesktopservice.exe
- ocautoupds.exe
- agntsvc.exeagntsvc.exe
- agntsvc.exeencsvc.exe
- firefoxconfig.exe
- tbirdconfig.exe
- ocomm.exe
- mysqld.exe
- mysqld-nt.exe
- mysqld-opt.exe
- dbeng50.exe
- sqbcoreservice.exe
- excel.exe
- infopath.exe
- msaccess.exe
- mspub.exe
- onenote.exe
- outlook.exe
- powerpnt.exe
- steam.exe
- thebat.exe
- thebat64.exe
- thunderbird.exe
- visio.exe
- winword.exe
- wordpad.exe
- Delete command:
- /c timeout -c 5 & del "%s" /f /q
- cmd.exe
- POST REQUEST:
- Content-Type: application/x-www-form-urlencoded
- curl.php?token=
- POST
- action=result&e_files=%d&e_size=%I64u&e_time=%d&
- action=call&
- &pub_key=
- &priv_key=
- &version=1.0
- Directory Exclusion:
- \ProgramData\
- \Program Files\
- \Tor Browser\
- Ransomware
- \All Users\
- \Local Settings\
- desktop.ini
- autorun.inf
- ntuser.dat
- iconcache.db
- bootsect.bak
- boot.ini
- ntuser.dat.log
- thumbs.db
- GDCB-DECRYPT.txt
- .sql
- %s\GDCB-DECRYPT.txt
- %c:\
- ipv4bot.whatismyipaddress.com
- %x%x
- undefined
- Domain
- SYSTEM\CurrentControlSet\services\Tcpip\Parameters
- WORKGROUP
- LocaleName
- Control Panel\International
- Keyboard Layout\Preload
- 00000419
- productName
- SOFTWARE\Microsoft\Windows NT\CurrentVersion
- SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion
- error
- Itanium
- Unknown
- ProcessorNameString
- HARDWARE\DESCRIPTION\System\CentralProcessor\0
- Identifier
- 2ntdll.dll
- UNKNOWN
- NO_ROOT_DIR
- REMOVABLE
- FIXED
- REMOTE
- CDROM
- RAMDISK
- %I64u/
- %I64u
- AV CHECK:
- AVP.EXE
- ekrn.exe
- avgnt.exe
- ashDisp.exe
- NortonAntiBot.exe
- Mcshield.exe
- avengine.exe
- cmdagent.exe
- smc.exe
- persfw.exe
- pccpfw.exe
- fsguiexe.exe
- cfp.exe
- msmpeng.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement