James_inthe_box

Agenttesla strings

Jul 30th, 2018
1,714
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.30 KB | None | 0 0
  1. Windows\System32\WindowsPowerShell\v1.0\powershell.exe
  2. SOFTWARE\Classes\mscfile\shell\open\command
  3. eventvwr.exe
  4. SOFTWARE\Classes\mscfile
  5. Windows 7
  6. Windows 8
  7. Windows 10
  8. 0
  9. %startupfolder%
  10. \%insfolder%\
  11. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
  12. Shutdown -r -t 5
  13. True
  14. Player
  15. temp
  16. \
  17. .exe
  18. Johnson
  19. Miller
  20. michael
  21. Abby
  22. Emily
  23. John
  24. Length
  25. root\CIMV2
  26. type={0}
  27. hwid={1}
  28. time={2}
  29. pcname={3}
  30. logdata={4}
  31. screen={5}
  32. ipadd={6}
  33. webcam_link={7}
  34. client={8}
  35. link={9}
  36. username={10}
  37. password={11}
  38. screen_link={12}
  39. site_username={13}
  40. webcam
  41. /
  42. Webcam Capture From:
  43. https://api.imgur.com/3/upload.xml
  44. \ScreenShot
  45. \ScreenShot\screen.jpeg
  46. screenshots
  47. Screen Capture From:
  48. Screenshot_
  49. /log.tmp
  50. keylog
  51. [SavedLog (
  52. [Saved Log]
  53. Keystrokes From:
  54. <html><span style=font-family:Courier New;font-size:14px;font-style:normal;font-weight:bold;text-decoration:none;text-transform:none;color:#000000;>Local&nbsp;Time&nbsp;&nbsp;&nbsp;&nbsp;:
  55. </span></html>
  56. Keystrokes_
  57. update
  58. info
  59. uninstall
  60. type={0}
  61. hwid={1}
  62. time={2}
  63. pcname={3}
  64. logdata={4}
  65. screen={5}
  66. ipadd={6}
  67. webcam_link={7}
  68. screen_link={8}
  69. site_username={9}
  70. [passwords]
  71. passwords
  72. Count
  73. HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites\
  74. Host
  75. REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
  76. HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
  77. DisableCMD
  78. REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoControlPanel /t REG_DWORD /d 1 /f
  79. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
  80. DisableSR
  81. REG add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 1 /f
  82. E+MTWs/(En()a3456d3h99sdf9sjdgA&%/+vkm&FGNBDSFs5(TRS%cxv
  83. p=
  84. %PostURL%/api.php
  85. application/x-www-form-urlencoded
  86. http://checkip.dyndns.org/
  87. <font color=#008000>{BACK}</font>
  88. </font>
  89. <font color=#008000>{ALT+F4}</font>
  90. <font color=#008000>{ESC}</font>
  91. <font color=#008000>{CAPSLOCK}</font>
  92. <font color=#008000>&darr;</font>
  93. <font color=#008000>&rarr;</font>
  94. <font color=#008000>{END}</font>
  95. <font color=#008000>{Insert}</font>
  96. <font color=#008000>{PageDown}</font>
  97. <font color=#008000>{ENTER}</font>
  98. <font color=#008000>{F1}</font>
  99. <font color=#008000>{F2}</font>
  100. <font color=#008000>{F3}</font>
  101. <font color=#008000>{F4}</font>
  102. <font color=#008000>{F5}</font>
  103. <font color=#008000>{F6}</font>
  104. <font color=#008000>{F7}</font>
  105. <font color=#008000>{F8}</font>
  106. <font color=#008000>{F9}</font>
  107. <font color=#008000>{F11}</font>
  108. <font color=#008000>{CTRL}</font>
  109. .lnk
  110. WScript.Shell
  111. CreateShortcut
  112. TargetPath
  113. cmd.exe
  114. WorkingDirectory
  115. Arguments
  116. /c start
  117. " "
  118. &start
  119. & exit
  120. IconLocation
  121. Save
  122. .lnk
  123. &explorer /root,"%CD%
  124. " & exit
  125. Opera Software\Opera Stable\Login Data
  126. Opera
  127. encryptedUsername)":"(.*?)"
  128. Firefox
  129. IELibrary
  130. IELibrary.InternetExplorer
  131. GetSavedPasswords
  132. URL
  133. UserName
  134. Password
  135. Browser
  136. \Apple Computer\Preferences\keychain.plist
  137. seamonkey
  138. SeaMonkey
  139. MapleStudio\ChromePlus\User Data\Default\Login Data
  140. CoolNovo
  141. Torch\User Data\Default\Login Data
  142. Torch Browser
  143. UCBrowser\
  144. *
  145. Login Data
  146. journal
  147. UC Browser
  148. wow_logins
  149. All User Profile * : (?<profile>.*)
  150. profile
  151. Wi-Fi
  152. wlan show profile name="
  153. " key=clear
  154. Key Content * : (?<password>.*)
  155. password
  156. No Password!
  157. ALLUSERSPROFILE
  158. \\
  159. DynDNS\Updater\config.dyndns
  160. username=
  161. =
  162. password=
  163. &H
  164. t6KzXhCh
  165. http://DynDns.com
  166. DynDNS
  167. \FileZilla\recentservers.xml
  168. <Server>
  169.  
  170. <Host>
  171. </Host>
  172. :
  173. <Port>
  174. </Port>
  175. <User>
  176. </User>
  177. <Pass encoding="base64">
  178. </Pass>
  179. <Pass>
  180. FileZilla
  181. \jDownloader\config\database.script
  182. programfiles(x86)
  183. HKEY_CURRENT_USER\Software\Paltalk\
  184. pwd
  185. http://Paltalk.com
  186. Paltalk
  187. \.purple\accounts.xml
  188. <account>
  189. <protocol>
  190. </protocol>
  191. <name>
  192. </name>
  193. <password>
  194. </password>
  195. Pidgin
  196. SmartFTPClient 2.0FavoritesQuick Connect*.xml
  197. <Password>
  198. </Password>
  199. <Name>
  200. </Name>
  201. SmartFTP
  202. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander\UninstallString
  203. uninstall.exe
  204. Ftplist.txt
  205. ;Server=
  206. ;Port=
  207. ;Password=
  208. ;User=
  209. ;Anonymous=
  210. Name=
  211. FTPCommander
  212. HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC
  213. USERname
  214. http://no-ip.com
  215. NO-IP
  216. +-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
  217. Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
  218. Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
  219. HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
  220. Executable
  221. \VirtualStore\Program Files\Foxmail\mail\
  222. ';:,<>/?+=
  223.  
  224. \Pocomail\accounts.ini
  225. POPPass
  226. SMTPPass
  227. SMTP
  228. PocoMail
  229. No data!
  230. [
  231. ]
  232. ;
  233. <array>
  234. <dict>
  235. <string>
  236. </string>
  237. <data>
  238. </data>
  239. Safari Browser
  240. -convert xml1 -s -o "
  241. \fixed_keychain.xml"
  242. A
  243. 10
  244. B
  245. 11
  246. C
  247. 12
  248. D
  249. 13
  250. E
  251. 14
  252. F
  253. 15
  254. ABCDEF
  255. PK11_GetInternalKeySlot
  256. PK11_FreeSlot
  257. ATOB_ConvertAsciiToItem_Util
  258. ATOB_ConvertAsciiToItem
  259. PK11SDR_Decrypt
  260. NSS_Shutdown
  261. PK11_Authenticate
  262. PROGRAMFILES(x86)
  263. \Mozilla Firefox\nss3.dll
  264. \Mozilla Firefox\
  265. PROGRAMFILES
  266. \Postbox\nss3.dll
  267. \Postbox\
  268. \Mozilla Thunderbird\nss3.dll
  269. \Mozilla Thunderbird\
  270. \SeaMonkey\nss3.dll
  271. \SeaMonkey\
  272. \Flock\nss3.dll
  273. \Flock\
  274. \vcruntime140.dll
  275. mozglue.dll
  276. nss3.dll
  277. NSS_Init
  278. Password could not decrypted.
  279. Copy
  280. An error occurred!
  281. \Mozilla\Firefox\
  282. Path=([A-z0-9\/\.]+)
  283. profiles.ini
  284. \Mozilla\SeaMonkey\
  285. \Flock\Browser\
  286. \Thunderbird\
  287. (
  288. IndexOf
  289. UNIQUE
  290. table
  291. No Data
  292. RegRead
  293. Windows\System32\WindowsPowerShell\v1.0\powershell.exe
  294. SOFTWARE\Classes\mscfile\shell\open\command
  295. eventvwr.exe
  296. SOFTWARE\Classes\mscfile
  297. Windows 7
  298. Windows 8
  299. Windows 10
  300. 0
  301. %startupfolder%
  302. \%insfolder%\
  303. SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
  304. Shutdown -r -t 5
  305. True
  306. Player
  307. temp
  308. \
  309. .exe
  310. Johnson
  311. Miller
  312. michael
  313. Abby
  314. Emily
  315. John
  316. Length
  317. root\CIMV2
  318. type={0}
  319. hwid={1}
  320. time={2}
  321. pcname={3}
  322. logdata={4}
  323. screen={5}
  324. ipadd={6}
  325. webcam_link={7}
  326. client={8}
  327. link={9}
  328. username={10}
  329. password={11}
  330. screen_link={12}
  331. site_username={13}
  332. webcam
  333. /
  334. Webcam Capture From:
  335. https://api.imgur.com/3/upload.xml
  336. \ScreenShot
  337. \ScreenShot\screen.jpeg
  338. screenshots
  339. Screen Capture From:
  340. Screenshot_
  341. /log.tmp
  342. keylog
  343. [SavedLog (
  344. [Saved Log]
  345. Keystrokes From:
  346. <html><span style=font-family:Courier New;font-size:14px;font-style:normal;font-weight:bold;text-decoration:none;text-transform:none;color:#000000;>Local&nbsp;Time&nbsp;&nbsp;&nbsp;&nbsp;:
  347. </span></html>
  348. Keystrokes_
  349. update
  350. info
  351. uninstall
  352. type={0}
  353. hwid={1}
  354. time={2}
  355. pcname={3}
  356. logdata={4}
  357. screen={5}
  358. ipadd={6}
  359. webcam_link={7}
  360. screen_link={8}
  361. site_username={9}
  362. [passwords]
  363. passwords
  364. Count
  365. HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites\
  366. Host
  367. REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
  368. HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
  369. DisableCMD
  370. REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoControlPanel /t REG_DWORD /d 1 /f
  371. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
  372. DisableSR
  373. REG add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 1 /f
  374. E+MTWs/(En()a3456d3h99sdf9sjdgA&%/+vkm&FGNBDSFs5(TRS%cxv
  375. p=
  376. %PostURL%/api.php
  377. application/x-www-form-urlencoded
  378. http://checkip.dyndns.org/
  379. <font color=#008000>{BACK}</font>
  380. </font>
  381. <font color=#008000>{ALT+F4}</font>
  382. <font color=#008000>{ESC}</font>
  383. <font color=#008000>{CAPSLOCK}</font>
  384. <font color=#008000>&darr;</font>
  385. <font color=#008000>&rarr;</font>
  386. <font color=#008000>{END}</font>
  387. <font color=#008000>{Insert}</font>
  388. <font color=#008000>{PageDown}</font>
  389. <font color=#008000>{ENTER}</font>
  390. <font color=#008000>{F1}</font>
  391. <font color=#008000>{F2}</font>
  392. <font color=#008000>{F3}</font>
  393. <font color=#008000>{F4}</font>
  394. <font color=#008000>{F5}</font>
  395. <font color=#008000>{F6}</font>
  396. <font color=#008000>{F7}</font>
  397. <font color=#008000>{F8}</font>
  398. <font color=#008000>{F9}</font>
  399. <font color=#008000>{F11}</font>
  400. <font color=#008000>{CTRL}</font>
  401. .lnk
  402. WScript.Shell
  403. CreateShortcut
  404. TargetPath
  405. cmd.exe
  406. WorkingDirectory
  407. Arguments
  408. /c start
  409. " "
  410. &start
  411. & exit
  412. IconLocation
  413. Save
  414. .lnk
  415. &explorer /root,"%CD%
  416. " & exit
  417. Opera Software\Opera Stable\Login Data
  418. Opera
  419. encryptedUsername)":"(.*?)"
  420. Firefox
  421. IELibrary
  422. IELibrary.InternetExplorer
  423. GetSavedPasswords
  424. URL
  425. UserName
  426. Password
  427. Browser
  428. \Apple Computer\Preferences\keychain.plist
  429. seamonkey
  430. SeaMonkey
  431. MapleStudio\ChromePlus\User Data\Default\Login Data
  432. CoolNovo
  433. Torch\User Data\Default\Login Data
  434. Torch Browser
  435. UCBrowser\
  436. *
  437. Login Data
  438. journal
  439. UC Browser
  440. wow_logins
  441. All User Profile * : (?<profile>.*)
  442. profile
  443. Wi-Fi
  444. wlan show profile name="
  445. " key=clear
  446. Key Content * : (?<password>.*)
  447. password
  448. No Password!
  449. ALLUSERSPROFILE
  450. \\
  451. DynDNS\Updater\config.dyndns
  452. username=
  453. =
  454. password=
  455. &H
  456. t6KzXhCh
  457. http://DynDns.com
  458. DynDNS
  459. \FileZilla\recentservers.xml
  460. <Server>
  461.  
  462. <Host>
  463. </Host>
  464. :
  465. <Port>
  466. </Port>
  467. <User>
  468. </User>
  469. <Pass encoding="base64">
  470. </Pass>
  471. <Pass>
  472. FileZilla
  473. \jDownloader\config\database.script
  474. programfiles(x86)
  475. HKEY_CURRENT_USER\Software\Paltalk\
  476. pwd
  477. http://Paltalk.com
  478. Paltalk
  479. \.purple\accounts.xml
  480. <account>
  481. <protocol>
  482. </protocol>
  483. <name>
  484. </name>
  485. <password>
  486. </password>
  487. Pidgin
  488. SmartFTPClient 2.0FavoritesQuick Connect*.xml
  489. <Password>
  490. </Password>
  491. <Name>
  492. </Name>
  493. SmartFTP
  494. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander\UninstallString
  495. uninstall.exe
  496. Ftplist.txt
  497. ;Server=
  498. ;Port=
  499. ;Password=
  500. ;User=
  501. ;Anonymous=
  502. Name=
  503. FTPCommander
  504. HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC
  505. USERname
  506. http://no-ip.com
  507. NO-IP
  508. +-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
  509. Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
  510. Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
  511. HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
  512. Executable
  513. \VirtualStore\Program Files\Foxmail\mail\
  514. ';:,<>/?+=
  515.  
  516. \Pocomail\accounts.ini
  517. POPPass
  518. SMTPPass
  519. SMTP
  520. PocoMail
  521. No data!
  522. [
  523. ]
  524. ;
  525. <array>
  526. <dict>
  527. <string>
  528. </string>
  529. <data>
  530. </data>
  531. Safari Browser
  532. -convert xml1 -s -o "
  533. \fixed_keychain.xml"
  534. A
  535. 10
  536. B
  537. 11
  538. C
  539. 12
  540. D
  541. 13
  542. E
  543. 14
  544. F
  545. 15
  546. ABCDEF
  547. PK11_GetInternalKeySlot
  548. PK11_FreeSlot
  549. ATOB_ConvertAsciiToItem_Util
  550. ATOB_ConvertAsciiToItem
  551. PK11SDR_Decrypt
  552. NSS_Shutdown
  553. PK11_Authenticate
  554. PROGRAMFILES(x86)
  555. \Mozilla Firefox\nss3.dll
  556. \Mozilla Firefox\
  557. PROGRAMFILES
  558. \Postbox\nss3.dll
  559. \Postbox\
  560. \Mozilla Thunderbird\nss3.dll
  561. \Mozilla Thunderbird\
  562. \SeaMonkey\nss3.dll
  563. \SeaMonkey\
  564. \Flock\nss3.dll
  565. \Flock\
  566. \vcruntime140.dll
  567. mozglue.dll
  568. nss3.dll
  569. NSS_Init
  570. Password could not decrypted.
  571. Copy
  572. An error occurred!
  573. \Mozilla\Firefox\
  574. Path=([A-z0-9\/\.]+)
  575. profiles.ini
  576. \Mozilla\SeaMonkey\
  577. \Flock\Browser\
  578. \Thunderbird\
  579. (
  580. IndexOf
  581. UNIQUE
  582. table
  583. No Data
  584. RegRead
Add Comment
Please, Sign In to add comment