ring0x0

2018-07-31 Hancitor/Panda

Jul 31st, 2018
489
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.20 KB | None | 0 0
  1. Subjects: IRS Notification, Internal Revenue Service, IRS Notice to the Taxpayer, IRS Taxpayer Notice, IRS Taxpayer Notification, Internal Revenue Service Taxpayer Notice, IRS Notice of intent to levy, IRS Final Notice, Internal Revenue Service Important Notification
  2.  
  3. #Word doc loader domains
  4. cliptrips.org
  5. greatharvestfranchising.com
  6. destinationvasectomy.net
  7. greatharvestbreadco.info
  8. greatharvestbread.info
  9. destinationvasectomy.info
  10. greatharvestbirmingham.com
  11. greatharvest.info
  12. govdelivery.co
  13. marychurchphotography.net
  14. racheldessinphotography.net
  15. racheldessinphotography.com
  16. richlandbrewingco.com
  17. marychurchphotography.co
  18. great-harvest.us
  19. great-harvest.biz
  20.  
  21. #Hancitor C2s
  22. fortryhowpar.com/4/forum.php
  23. terabsedsand.ru/4/forum.php
  24. widingwild.ru/4/forum.php
  25.  
  26. #Hancitor payload URLs
  27. {l:
  28. hxxp://uptowndermatologyandaesthetics.com/wp-content/plugins/header-footer/lib/easytabs/1
  29. hxxp://powerplaygenerators.com/wp-content/plugins/et-shortcodes/1
  30. hxxp://newswriting.com/wp-content/plugins/disable-comments/includes/1
  31. hxxp://www.geriatricdementiaconsulting.com/wp-content/plugins/gravityforms/includes/1
  32. hxxp://vermontlinestriping.com/wp-content/plugins/wp-super-cache/1
  33. }
  34.  
  35. {b:
  36. hxxp://uptowndermatologyandaesthetics.com/wp-content/plugins/header-footer/lib/easytabs/2
  37. hxxp://powerplaygenerators.com/wp-content/plugins/et-shortcodes/2
  38. hxxp://newswriting.com/wp-content/plugins/disable-comments/includes/2
  39. hxxp://www.geriatricdementiaconsulting.com/wp-content/plugins/gravityforms/includes/2
  40. hxxp://vermontlinestriping.com/wp-content/plugins/wp-super-cache/2
  41. }
  42.  
  43. {r:
  44. hxxp://uptowndermatologyandaesthetics.com/wp-content/plugins/header-footer/lib/easytabs/3
  45. hxxp://powerplaygenerators.com/wp-content/plugins/et-shortcodes/3
  46. hxxp://newswriting.com/wp-content/plugins/disable-comments/includes/3
  47. hxxp://www.geriatricdementiaconsulting.com/wp-content/plugins/gravityforms/includes/3
  48. hxxp://vermontlinestriping.com/wp-content/plugins/wp-super-cache/3
  49. }
  50.  
  51. #Panda C2
  52. nauseorofte.ru
  53.  
  54. #Panda Config
  55. t": "2.6.10",
  56. "check_config": 327685,
  57. "send_report": 655370,
  58. "check_update": 1966110,
  59. "url_config": "https://nauseorofte.ru/1ifmuybbolakuotegepma.dat",
  60. "url_webinjects": "https://nauseorofte.ru/610webinjects.dat",
  61. "url_update": "https://nauseorofte.ru/1ifmuybbolakuotegepma.exe",
  62. "url_plugin_webinject32": "https://nauseorofte.ru/610webinject32.bin",
  63. "url_plugin_webinject64": "https://nauseorofte.ru/610webinject64.bin",
  64. "remove_csp": 0,
  65. "inject_vnc": 0,
  66. "url_plugin_vnc32": "https://nauseorofte.ru/610vnc32.bin",
  67. "url_plugin_vnc64": "https://nauseorofte.ru/610vnc64.bin",
  68. "url_plugin_vnc_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  69. "url_plugin_backsocks": "https://nauseorofte.ru/610backsocks.bin",
  70. "url_plugin_backsocks_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  71. "url_plugin_grabber": "https://nauseorofte.ru/610grabber.bin",
  72. "grabber_pause": 2,
  73. "grab_softlist": 1,
  74. "grab_pass": 1,
  75. "grab_form": 1,
  76. "grab_cert": 1,
  77. "grab_cookie": 1,
  78. "grab_del_cookie": 0,
  79. "grab_del_cache": 0,
  80. "url_plugin_keylogger": "https://nauseorofte.ru/610keylogger.bin",
  81. "keylog_process": "cHV0dHkuZXhlAAA=",
  82. "screen_process": "cHV0dHkuZXhlAAA=",
  83. "reserved": "EHWYzK2iP0NmeKxDwa0DPfOuV0QjVC0GY4BCSoGmr5mPGXJMBt07AMq1yJ7+Sea
Add Comment
Please, Sign In to add comment