Advertisement
vk_intel

2018-11-13: ISFB Gozi v217 & v3.00

Nov 13th, 2018
533
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.19 KB | None | 0 0
  1. MD5 (2018-11-12.isfbv217.client.decoded.vk.dll) = 9af8d35fcd286d8c06d06873480617b7
  2. MD5 (2018-11-12.isfbv217.loader.decoded.vk.exe) = 2660b1834829ef54cacdd7ad5d538c8d
  3. MD5 (2018-11-13.isfbv3.injected.loader.decoded.vk.exe.dll) = 5a444188b4789fb1538a2f6202ca9a13
  4. MD5 (2018-11-13.isfbv3.loader.decoded.vk.exe) = abd56532b599fecd70cd3b8fde9e6a76
  5.  
  6. Bot ['2.17']
  7. Build ['39']
  8. Botnet/Group ID ['3108’, '3109']
  9. DGA TLDs ['com', 'ru', 'org']
  10. Server [’12’]
  11. Encryption key ['10291029JSJUYNHG']
  12. DGA CRC ['0x4eb7d2ca']
  13. DGA Base URL ['constitution.org/usdeclar.txt']
  14. Domains ['cythromatt.com', 'ticraphiff.com', 'dubbumnabb.com']
  15. Path: ['/images/']
  16.  
  17.  
  18. Bot ['3.00']
  19. Build ['665']
  20. Botnet/Group ID ['40001']
  21. DGA TLDs ['com', 'ru', 'org']
  22. Server [’12’]
  23. Encryption key ['KcJ2rbtrqmuHaj9W']
  24. DGA CRC ['0x4eb7d2ca']
  25. DGA Base URL ['constitution.org/usdeclar.txt']
  26. Domains ['https://chicmall.com]
  27. Path: ['/images/']
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement