Advertisement
vk_intel

2018-12-06: ISFB Gozi v215

Dec 6th, 2018
527
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.17 KB | None | 0 0
  1. MD5 (2018-12-06.isfbv215.loader.decoded.vk.exe) = d0fb46b6f85c148d16c8b0b1014dfd9d
  2. MD5 (2018-12-06.isfbv215.loader.decoded.vk.exe) = 63bf415bf29da3a80cf944bd734ef196
  3.  
  4. Bot ['2.15']
  5. Build ['165']
  6. Botnet/Group ID ['3142', '3143']
  7. DGA TLDs ['com', 'ru', 'org']
  8. Server [’12’]
  9. Encryption key ['10291029JSJUYNHG']
  10. DGA CRC ['0x4eb7d2ca']
  11. DGA Base URL ['constitution.org/usdeclar.txt']
  12. Domains ['hazzanaphi.com', 'coelloemai.com', 'outtersoco.com']
  13. Path: ['/images/']
  14.  
  15. Bot ['2.15']
  16. Build ['165']
  17. Botnet/Group ID ['3144', '3144']
  18. DGA TLDs ['com', 'ru', 'org']
  19. Server [’12’]
  20. Encryption key ['10291029JSJUYNHG']
  21. DGA CRC ['0x4eb7d2ca']
  22. DGA Base URL ['constitution.org/usdeclar.txt']
  23. Domains ['foxerwoman.com', 'ralmonresc.com', 'bartatoisc.com']
  24. Path: ['/images/']
  25.  
  26.  
  27. Payload Domains
  28.  
  29. tolinatogr.com/KHZ/diuyz.php?l=aque[1-14].tkn
  30. killoberil.com/KHZ/diuyz.php?l=tysk[1-14].tkn
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement