Interesting, just stumbled upon another TinyBanker sample, this one is from May 1, 2012. I have counted 4 TinyBanker botnets now in total. The data of the one I have found (the sample is attached):
Code: Select all
There is a ThreatExpert report about the sample at http://www.threatexpert.com/report.aspx ... 660371c267 . Most of the domains (not all) of the other 3 botnets were listed on http://contagiodump.blogspot.se/2012/06/amazon.html and are:monolitabuse.com registered 2012-04-27
mon1olitabuse1.com sinkholed 2012-05-02
mon2olit2abuse.com sinkholed 2012-05-02
mo3nolitabus33e.com sinkholed 2012-05-02
RC4 Key: wer8c7ygbw485ghw
Code: Select all
Botnet 1:
dakotavolandos.com
dak1otavola1ndos.com
dako22tavol2andos.com
d3akotav33olandos.com
d4ak4otavolandos.com
RC4 key: e5bb6u6wv6whvje6
Botnet 2:
monsboys.biz
ieubietubviurb.com
uwyhbgwiechgi.com
RC4 key: wer8c7ygbw485ghw
Botnet 3:
azonpowzanadinoar.com
basdinopowadoar.com
sbasdinopowadoar.com
basdinopowadoar.eu
basdinopowadoar.org
RC4 key: e5bb6u6wv6whvje6
Attachments
Pw: infected
(9.54 KiB) Downloaded 102 times
(9.54 KiB) Downloaded 102 times