PepperPotts

agentesla encrypted strings

Feb 19th, 2019
388
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.42 KB | None | 0 0
  1. Sample: 5bef6695ab6acdf941e1e7efef27941cb050256771a2b585d80716a673a1b938
  2. ---------
  3.  
  4. Software\\Classes
  5. ms-settings\\shell\\open\\command
  6. Software\\Classes\\ms-settings\\shell\\open\\command
  7. DelegateExecute
  8. C:\\Windows\\System32\\computerdefaults.exe
  9. Software\\Classes\\ms-settings\\shell
  10. open\\command
  11. mscfile\\shell\\open\\command
  12. C:\\Windows\\System32\\eventvwr.exe
  13. Software\\Classes\\mscfile\\shell
  14. IsInRole
  15. \\
  16. Windows 7
  17. Windows 8
  18. Windows 10
  19. \\temp.tmp
  20. 1
  21. %startupfolder%
  22. \\%insfolder%\\
  23. Software\\Microsoft\\Windows\\CurrentVersion\\Run
  24. %insregname%
  25. SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run
  26. Shutdown -r -t 5
  27. True
  28. Johnson
  29. Miller
  30. michael
  31. Abby
  32. Emily
  33. John
  34. Player
  35. playerf4
  36. C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\MSBuild.exe
  37. C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\MSBuild.exe
  38. root\\CIMV2
  39. SELECT * FROM Win32_VideoController
  40. SELECT * FROM Win32_Processor
  41. Name
  42. MB
  43. AdapterRAM
  44. Unknown
  45. WebCap
  46. \\CamCampture
  47. \\CamCampture\\webcam.jpeg
  48. /
  49. Webcam Capture From:
  50. <span style=font-family:Courier New;font-size:14px;font-style:normal;font-weight:bold;text-decoration:none;text-tra
  51. nsform:none;color:#000000;>Local Time :
  52. young@inquiry.space
  53. yyyy_MM_dd_HH_mm_ss
  54. Webcam_
  55. -
  56. _IP_Adress_
  57. _
  58. .jpeg
  59. \\ScreenShot
  60. \\ScreenShot\\screen.jpeg
  61. screenshots
  62. Screen Capture From:
  63. Screenshot_
  64. /log.tmp
  65. keylog
  66. [SavedLog (
  67. [Saved Log]
  68. Keystrokes From:
  69. </span>
  70. Saved_Log_From_
  71. .html
  72. <html><span style=font-family:Courier New;font-size:14px;font-style:normal;font-weight:bold;text-decoration:none;te
  73. xt-transform:none;color:#000000;>Local Time :
  74. </span></html>
  75. Keystrokes_
  76. update
  77. info
  78. uninstall
  79. Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows
  80. Load
  81. %ftphost%/
  82. %ftpuser%
  83. %ftppassword%
  84. STOR
  85. Length
  86. Write
  87. Close
  88. type={0}hwid={1}time={2}pcname={
  89. Port
  90. User
  91. PW
  92. CoreFTP
  93. Passwords Recovered From:
  94. Local Time :
  95. Password_Recoveries_
  96. </html>
  97. ^HJBanD5
  98. smtp.inquiry.space
  99. :Zone.Identifier
  100. %DownLink%
  101. /%filename%
  102. HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System
  103. EnableLUA
  104. 0
  105. REG add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
  106. REG add HKCU\\Software\\Policies\\Microsoft\\Windows\\System /v DisableCMD /t REG_DWORD /d 1 /f
  107. HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System
  108. DisableCMD
  109. REG add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer /v NoRun /t REG_DWORD /d 1 /f
  110. REG add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer /v NoControlPanel /t REG_DWORD /d 1
  111. /f
  112. HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System
  113. DisableRegistryTools
  114. HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore
  115. DisableSR
  116. REG add HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer /v NoFolderOptions /t
  117. REG_DWORD /d 1 /f
  118. REG add HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer /v NoFolderOptions /t
  119. REG_DWORD /d 1 /f
  120. SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths
  121. MSCONFIG.EXE
  122. \\tmpG
  123. .tmp
  124. Length
  125. length must be > 0
  126. anubis
  127. a2servic
  128. ashWebSv
  129. hvk
  130. avgemc
  131. bdagent
  132. avp
  133. keyscrambler
  134. mbam
  135. ekrn
  136. egui
  137. npfmsg
  138. ollydbg
  139. outpost
  140. Wireshark
  141. mcagent
  142. mcuimgr
  143. clamauto
  144. cpf
  145. ewido
  146. FPAVServer
  147. SbieSvc
  148. antigen
  149. ccapp
  150. tmlisten
  151. pccntmon
  152. earthagent
  153. spysweeper
  154. %filter_list%
  155. p=
  156. %PostURL%
  157. Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/4.0 (.NET CLR 3.5.30729)
  158. POST
  159. +
  160. %2B
  161. application/x-www-form-urlencoded
  162. http://checkip.dyndns.org/
  163. \\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}
  164. &
  165. &
  166. <
  167. <
  168. >
  169. >
  170. "
  171. "
  172. :
  173. ]<span style=font-style:normal;text-decoration:none;text-transform:none;color:#000000;> (
  174. False
  175. <font color=#008000>{BACK}</font>
  176. </font>
  177. <font color=#008000>{ALT+TAB}</font>
  178. <font color=#008000>{ALT+F4}</font>
  179. <font color=#008000>{TAB}</font>
  180. <font color=#008000>{ESC}</font>
  181. <font color=#008000>{Win}</font>
  182. <font color=#008000>{CAPSLOCK}</font>
  183. <font color=#008000>↑</font>
  184. <font color=#008000>↓</font>
  185. <font color=#008000>←</font>
  186. <font color=#008000>→</font>
  187. <font color=#008000>{DEL}</font>
  188. <font color=#008000>{END}</font>
  189. <font color=#008000>{HOME}</font>
  190. <font color=#008000>{Insert}</font>
  191. <font color=#008000>{NumLock}</font>
  192. <font color=#008000>{PageDown}</font>
  193. <font color=#008000>{PageUp}</font>
  194. <font color=#008000>{ENTER}</font>
  195. <font color=#008000>{F1}</font>
  196. <font color=#008000>{F2}</font>
  197. <font color=#008000>{F3}</font>
  198. <font color=#008000>{F4}</font>
  199. <font color=#008000>{F5}</font>
  200. <font color=#008000>{F6}</font>
  201. <font color=#008000>{F7}</font>
  202. <font color=#008000>{F8}</font>
  203. <font color=#008000>{F9}</font>
  204. <font color=#008000>{F10}</font>
  205. <font color=#008000>{F11}</font>
  206. <font color=#008000>{F12}</font>
  207. control
  208. <font color=#008000>{CTRL}</font>
  209. .lnk
  210. WScript.Shell
  211. CreateShortcut
  212. TargetPath
  213. cmd.exe
  214. WorkingDirectory
  215. Arguments
  216. /c start
  217. " "
  218. &start;
  219. & exit
  220. IconLocation
  221. Save
  222. .lnk
  223. &explorer; /root,"%CD%
  224. " & exit
  225. %SystemRoot%\\system32\\SHELL32.dll,3
  226. Software\\Classes\\
  227. OpenSubKey
  228. GetValue
  229. \\DefaultIcon\\
  230. ,
  231. ,0
  232. None
  233. win32_processor
  234. processorID
  235. WinMgmts:
  236. InstancesOf
  237. Win32_BaseBoard
  238. SerialNumber
  239. x2
  240. origin_url
  241. username_value
  242. password_value
  243. \\Google\\Chrome\\User Data\\
  244. Profile
  245. Default
  246. \\Login Data
  247. Chrome
  248. logins
  249. Opera Software\\Opera Stable\\Login Data
  250. Opera
  251. Yandex\\YandexBrowser\\User Data\\Default\\Login Data
  252. Yandex
  253. firefox
  254. logins.json
  255. \\"(hostname|encryptedPassword|encryptedUsername)":"(.*?)"
  256. firefox
  257. temp
  258. .exe
  259. firefoxf4
  260. @@@
  261. IELibrary
  262. IELibrary.InternetExplorer
  263. GetSavedPasswords
  264. URL
  265. UserName
  266. Password
  267. Browser
  268. \\Common Files\\Apple\\Apple Application Support\\plutil.exe
  269. \\Apple Computer\\Preferences\\keychain.plist
  270. seamonkey
  271. seamonkey
  272. Comodo\\Dragon\\User Data\\Default\\Login Data
  273. Comodo Dragon
  274. MapleStudio\\ChromePlus\\User Data\\Default\\Login Data
  275. CoolNovo
  276. Chromium\\User Data\\Default\\Login Data
  277. SRWare Iron
  278. Torch\\User Data\\Default\\Login Data
  279. Torch Browser
  280. UCBrowser\\
  281. *
  282. Login Data
  283. journal
  284. UC Browser
  285. wow_logins
  286. PopPassword
  287. SmtpPassword
  288. Software\\IncrediMail\\Identities\\
  289. \\Accounts_New
  290. EmailAddress
  291. SmtpServer
  292. incredimail
  293. HKEY_CURRENT_USER\\Software\\Qualcomm\\Eudora\\CommandLine
  294. current
  295. Settings
  296. SavePasswordText
  297. ReturnAddress
  298. Eudora
  299. thunderbird
  300. signons.sqlite
  301. moz_logins
  302. hostname
  303. encryptedUsername
  304. encryptedPassword
  305. thunderbird
  306. postbox
  307. postbox
  308. flock
  309. signons3.txt
  310. ---
  311. .
  312. Flock Browser
  313. netsh
  314. wlan show profile
  315. All User Profile
  316. All User Profile * : (?<profile>.*)
  317. Profile
  318. Wi-Fi
  319. wlan show profile name="
  320. " key=clear
  321. Key Content * : (?<password>.*)
  322. Password
  323. No Password!
  324. ALLUSERSPROFILE
  325. \\\\
  326. DynDNS\\Updater\\config.dyndns
  327. username=
  328. =
  329. password=
  330. &H;
  331. t6KzXhCh
  332. http://DynDns.com
  333. DynDNS
  334. \\FileZilla\\recentservers.xml
  335. <Server>
  336. <Host>
  337. </Host>
  338. :
  339. <Port>
  340. </Port>
  341. <User>
  342. </User>
  343. <Pass encoding="base64">
  344. </Pass>
  345. <Pass>
  346. FileZilla
  347. SOFTWARE\\\\Martin Prikryl\\\\WinSCP 2\\\\Sessions
  348. hostname
  349. PublicKeyFile
  350. PortNumber
  351. 22
  352. [PRIVATE KEY LOCATION: "{0}"]
  353. WinSCP
  354. UserName
  355. All Users
  356. \\FlashFXP\\3quick.dat
  357. IP=
  358. port=
  359. user=
  360. pass=
  361. created=
  362. FlashFXP
  363. SystemDrive
  364. \\FTP Navigator\\Ftplist.txt
  365. Server
  366. No Password
  367. FTP Navigator
  368. Programfiles(x86)
  369. programfiles
  370. \\jDownloader\\config\\database.script
  371. Programfiles(x86)
  372. INSERT INTO CONFIG VALUES('AccountController','
  373. sq
  374. .
  375. t
  376. xt
  377. JDownloader
  378. Software\\Paltalk
  379. HKEY_CURRENT_USER\\Software\\Paltalk\\
  380. pwd
  381. http://Paltalk.com
  382. Paltalk
  383. \\.purple\\accounts.xml
  384. <account>
  385. <protocol>
  386. </protocol>
  387. <name>
  388. </name>
  389. <password>
  390. </password>
  391. Pidgin
  392. \\SmartFTP\\Client 2.0\\Favorites\\Quick Connect\\
  393. SmartFTPClient 2.0FavoritesQuick Connect*.xml
  394. <password>
  395. </password>
  396. <name>
  397. </name>
  398. SmartFTP
  399. APPDATA
  400. \\Ipswitch\\WS_FTP\\Sites\\ws_ftp.ini
  401. Host
  402. UID
  403. pwd
  404. WS_FTP
  405. PWD=
  406. Substring
  407. Password decryption failed!
  408. Key
  409. Mode
  410. IV
  411. Padding
  412. CreateDecryptor
  413. HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\FTP Commander\\UninstallString
  414. uninstall.exe
  415. Ftplist.txt
  416. ;Server=
  417. ;Port=
  418. ;Password=
  419. ;User=
  420. ;Anonymous=
  421. Name=
  422. FTPCommander
  423. HKEY_LOCAL_MACHINE\\SOFTWARE\\Vitalwerks\\DUC
  424. HKEY_CURRENT_USER\\SOFTWARE\\Vitalwerks\\DUC
  425. UserName
  426. http://no-ip.com
  427. NO-IP
  428. Input text must be a multiple of 4 characters!
  429. +-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
  430. Input contains illegal character '
  431. '!
  432. \\The Bat!
  433. \\Account.CFN
  434. TheBat
  435. Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676
  436. Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging
  437. Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676
  438. Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676
  439. Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676
  440. Email
  441. IMAP Password
  442. POP3 Password
  443. HTTP Password
  444. SMTP Password
  445. GetBytes
  446. SMTP Server
  447. Not found!
  448. Outlook
  449. HKEY_CURRENT_USER\\Software\\Aerofox\\FoxmailPreview
  450. Executable
  451. HKEY_CURRENT_USER\\Software\\Aerofox\\Foxmail\\V3.1
  452. FoxmailPath
  453. \\Storage\\
  454. \\mail\\
  455. \\VirtualStore\\Program Files\\Foxmail\\mail\\
  456. \\VirtualStore\\Program Files (x86)\\Foxmail\\mail\\
  457. \\Accounts\\Account.rec0
  458. \\Account.stg
  459. \\fox.temp
  460. Read
  461. Dispose
  462. POP3Host
  463. SMTPHost
  464. IncomingServer
  465. Account
  466. MailAddress
  467. POP3Password
  468. !empty!
  469. Foxmail
  470. 5A
  471. 71
  472. No Data!
  473. \\Opera Mail\\Opera Mail\\wand.dat
  474. opera:
  475. Opera Mail
  476. abcdefghijklmnopqrstuvwxyz1234567890_-.~!@#$%^&*()[{]}\\|';:,<>/?+=
  477. \\Pocomail\\accounts.ini
  478. POPPass
  479. SMTPPass
  480. SMTP
  481. PocoMail
  482. No Data!
  483. [
  484. ]
  485. ;
  486. <array>
  487. <dict>
  488. <string>
  489. </string>
  490. <data>
  491. </data>
  492. Safari Browser
  493. -convert xml1 -s -o "
  494. \\fixed_keychain.xml"
  495. A
  496. 10
  497. B
  498. 11
  499. C
  500. 12
  501. D
  502. 13
  503. E
  504. 14
  505. F
  506. 15
  507. ABCDEF
  508. PK11_GetInternalKeySlot
  509. PK11_FreeSlot
  510. ATOB_ConvertAsciiToItem_Util
  511. ATOB_ConvertAsciiToItem
  512. PK11SDR_Decrypt
  513. NSS_Shutdown
  514. PK11_Authenticate
  515. Programfiles(x86)
  516. \\Mozilla Firefox\\nss3.dll
  517. \\Mozilla Firefox\\
  518. programfiles
  519. \\Postbox\\nss3.dll
  520. \\Postbox\\
  521. \\Mozilla Thunderbird\\nss3.dll
  522. \\Mozilla Thunderbird\\
  523. \\SeaMonkey\\nss3.dll
  524. \\SeaMonkey\\
  525. \\Flock\\nss3.dll
  526. \\Flock\\
  527. \\vcruntime140.dll
  528. mozglue.dll
  529. nss3.dll
  530. NSS_Init
  531. Password could not decrypted.
  532. Copy
  533. \\Mozilla\\Firefox\\
  534. Path=([A-z0-9\\/\\.]+)
  535. profiles.ini
  536. \\Mozilla\\SeaMonkey\\
  537. \\Flock\\Browser\\
  538. \\Thunderbird\\
  539. (
  540. IndexOf
  541. UNIQUE
  542. table
  543. No Data
  544. RegRead
  545. Software\\DownloadManager\\Passwords\\
  546. EncPassword
  547. Internet Download Manager
Add Comment
Please, Sign In to add comment