vk_intel

10-12-2018: GOZI ISFB Botnet/Group '3083'

Oct 12th, 2018
550
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.50 KB | None | 0 0
  1. Unpacked Loader MD5: 7a1210d5e2d3737aeee5ecec8b15940d
  2.  
  3. Bot ['2.18']
  4. Build ['01']
  5. Botnet/Group ID ['3083’]
  6. DGA TLDs ['com', 'ru', 'org']
  7. Server [’12’]
  8. Encryption key ['10291029JSJUYNHG']
  9. DGA CRC ['0x4eb7d2ca']
  10. DGA Base URL ['constitution.org/usdeclar.txt']
  11. Domains ['k37aos82skd9nal92kamcdla.com', 'dhsiwyqdlskwsqo.com', 'hq92lmdlcdnandwuq.com']
  12. Path: ['/images/']
Add Comment
Please, Sign In to add comment