Advertisement
ring0x0

2018-05-02-Hancitor

May 2nd, 2018
755
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.10 KB | None | 0 0
  1. Subjects: Your Verizon Wireless invoice, Here is your Verizon Wireless bill, Your mobile bill, Here is your mobile invoice, Here is your Verizon Wireless invoice, Here is your Verizon cellular bill, Your Verizon cellular invoice, Here is your Verizon cellular invoice, Your Verizon cellular bill
  2.  
  3. #Doc Download Domains:
  4. countywidememorials.com
  5. ryanandrie.me
  6. kwrn1550am.com
  7. countywidemonuments.com
  8. youngsvillehousevalues.com
  9. sleeplavish.com
  10. prescriptionerrorlawyer.com
  11. solutionsforsanjose.info
  12. solutionsforsanjose.net
  13. sawgrasspark.com
  14. youngsvilleproperties.com
  15.  
  16. #Hancitor C2
  17. hxxp://hemfeketro.com/4/forum.php
  18. hxxp://gejohntorsar.ru/4/forum.php
  19. hxxp://tonstinnotna.ru/4/forum.php
  20.  
  21. #Hancitor Payload Links
  22. hxxp://fatcowcoupon.us/wp-content/plugins/nofollow-for-external-link/1
  23. hxxp://alphafinancialservices.net/wp-content/themes/twentyeleven/inc/1
  24. hxxp://buckscountybass.com/wp-content/themes/canvas-bcac/1
  25. hxxp://mattbennett.ca/wp-content/themes/spark/inc/1
  26. hxxp://hugefrigginarms.com/wp-content/themes/twentyfifteen/1
  27.  
  28. hxxp://fatcowcoupon.us/wp-content/plugins/nofollow-for-external-link/2
  29. hxxp://alphafinancialservices.net/wp-content/themes/twentyeleven/inc/2
  30. hxxp://buckscountybass.com/wp-content/themes/canvas-bcac/2
  31. hxxp://mattbennett.ca/wp-content/themes/spark/inc/2
  32. hxxp://hugefrigginarms.com/wp-content/themes/twentyfifteen/2
  33.  
  34. hxxp://fatcowcoupon.us/wp-content/plugins/nofollow-for-external-link/3
  35. hxxp://alphafinancialservices.net/wp-content/themes/twentyeleven/inc/3
  36. hxxp://buckscountybass.com/wp-content/themes/canvas-bcac/3
  37. hxxp://mattbennett.ca/wp-content/themes/spark/inc/3
  38. hxxp://hugefrigginarms.com/wp-content/themes/twentyfifteen/3
  39.  
  40. #Pony C2
  41. hxxp://hemfeketro.com/mlu/forum.php
  42. hxxp://gejohntorsar.ru/mlu/forum.php
  43. hxxp://tonstinnotna.ru/mlu/forum.php
  44.  
  45. #Panda Config
  46. t": "2.6.8",
  47. "check_config": 327685,
  48. "send_report": 655370,
  49. "check_update": 1966110,
  50. "url_config": "https://robwassotdint.ru/1kewoimzatybewoliowof.dat",
  51. "url_webinjects": "https://robwassotdint.ru/68webinjects.dat",
  52. "url_update": "https://robwassotdint.ru/1kewoimzatybewoliowof.exe",
  53. "url_plugin_webinject32": "https://robwassotdint.ru/68webinject32.bin",
  54. "url_plugin_webinject64": "https://robwassotdint.ru/68webinject64.bin",
  55. "remove_csp": 0,
  56. "inject_vnc": 0,
  57. "url_plugin_vnc32": "https://robwassotdint.ru/68vnc32.bin",
  58. "url_plugin_vnc64": "https://robwassotdint.ru/68vnc64.bin",
  59. "url_plugin_vnc_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  60. "url_plugin_backsocks": "https://robwassotdint.ru/68backsocks.bin",
  61. "url_plugin_backsocks_backserver": "Z2KvEWWIVjHCjeytKlg4Ls8=",
  62. "url_plugin_grabber": "https://robwassotdint.ru/68grabber.bin",
  63. "grabber_pause": 2,
  64. "grab_softlist": 1,
  65. "grab_pass": 1,
  66. "grab_form": 1,
  67. "grab_cert": 1,
  68. "grab_cookie": 1,
  69. "grab_del_cookie": 0,
  70. "grab_del_cache": 0,
  71. "url_plugin_keylogger": "https://robwassotdint.ru/68keylogger.bin",
  72. "keylog_process": "cHV0dHkuZXhlAAA=",
  73. "screen_process": "cHV0dHkuZXhlAAA=",
  74. "reserved": "EHWYzK2iP0NudL9QxrsRIfKqEAkvVm8bPoNaVoe6sIaDCm5FCsU7HMa/0JKyA+OKKL0gGIXEqmWsckB+8m+LUK6ohAJv2qQOTBRVPiJ9P7sN8BMNbfRQFgMayV1dpjMm9C8V7gI="
  75. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement