Advertisement
vk_intel

10-25-2018: Gozi ISFB & Dridex ID "3101"

Oct 25th, 2018
731
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.85 KB | None | 0 0
  1. MD5 (2018-10-24.isfb.loader.decoded.vk.exe) = 4854c062bd319303e7da1c5eb0e3461c
  2. MD5 (2018-10-24.isfb.client.decoded.vk.dll) = e982180971db1e60b34b084a87f877af
  3.  
  4.  
  5. Bot ['2.17']
  6. Build ['39']
  7. Botnet/Group ID ['3090’, '3091']
  8. DGA TLDs ['com', 'ru', 'org']
  9. Server [’12’]
  10. Encryption key ['10291029JSJUYNHG']
  11. DGA CRC ['0x4eb7d2ca']
  12. DGA Base URL ['constitution.org/usdeclar.txt']
  13. Domains ['eyedosprot.com ', 'dhsiwyqdlskwsqo.com', 'hq92lmdlcdnandwuq.com']
  14. Path: ['/images/']
  15.  
  16. ISFB 2nd Stage Domains:
  17.  
  18. dealadynou.com/RUI/levond.php?l=pory[1-7].xap
  19. fageingles.com/RUI/levond.php?l=pory[1-7].xap
  20.  
  21.  
  22. Dridex Botnet ID "3101" Fist-Stage Config:
  23.  
  24. 213.252.244.233:443
  25. 192.48.88.118:443
  26. 176.10.118.150:443
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement