https://www.virustotal.com/en/file/b046 ... 389817586/
weird zeus
Found here http://www.malekal.com/2014/01/15/direc ... d-to-zbot/
base64+RC4+VisualDecrypt
RC4:
fine.landingplans.net/browser/images/logo.png
fine.landingplans.net/browser/theme/style.css:
--
others cnc:, panel of 'second' zeusVM generation:
weird zeus
Code: Select all
Webinject:
https://bilance.humanwebcentr.net:63992/prefer/moualu.exe
https://bilance.humanwebcentr.net:63992/prefer/stars/rihannew.jpg
https://bilance.humanwebcentr.net:63992/prefer/counters.php
http://localhost/captchaupload.php
http://localhost/notifygate.php
Code: Select all
https://microsads.net/sampler/admin/gate.php?mode=CHECK_LOGIN&type=COMMERZBANKING&bot_id=XYLITOL-F12F085_7875768FBC303C10
Found here http://www.malekal.com/2014/01/15/direc ... d-to-zbot/
base64+RC4+VisualDecrypt
RC4:
Code: Select all
Edit: there a cnc also on another location hosting old panel of zeusVM:30 65 73 8D 11 5D CB 1A E3 7C 7E 6B 0F 6D D6 3C 39 94 32 B4 61 52 93 DD C5 2F D8 1F 74 54 6A B9 C8 22 C4 07 EA 5A 1D 7A DA 34 25 DB 0C EC A4 5C BE AF 5E D2 3A BF 7F 00 2A EE 3F 3E 72 92 48 35 03 E9 63 D7 53 33 67 0E 1B AB 38 50 40 28 CD 23 A1 2C 47 AE C3 29 91 2B B6 62 19 0A 1E 36 57 FE DF 82 42 4D F8 89 98 4C DE EF 24 95 4A AA CA 06 56 58 46 A0 87 D4 16 A6 2E 14 E0 9C 85 8B 84 BD E7 31 F7 F2 9B 2D 96 B7 AD 01 8F A9 8A 20 FA 79 04 A8 6F 51 26 BB 8E 9D DC 43 A2 09 1C 9E F1 0B FC 68 E6 02 E1 CC F5 99 B0 81 90 D0 44 80 FF D3 77 66 C7 BA ED E2 6C C1 E5 69 71 55 4E 10 4B 27 60 CF 88 FB B2 83 75 F0 A5 5F 41 21 E4 B8 05 C6 F9 EB F6 B1 A3 9F 37 B5 49 CE FD E8 4F F4 C9 C0 BC 7B 6E D1 D5 3B 45 A7 F3 13 3D B3 AC 76 D9 78 18 86 0D 12 59 64 8C C2 17 9A 97 15 7D 70 08 5B
fine.landingplans.net/browser/images/logo.png
fine.landingplans.net/browser/theme/style.css:
Code: Select all
fine.landingplans.net/browser/theme/throbber.gif:html, body
{
background: url("../theme/fonbutton/background.png");
margin: 0 auto;
color: #000000;
font-family: Verdana, Helvetica, sans-serif;
font-size: 10px
}
input, select, textarea
{
background: #F5F5F5;
font-family: Verdana, Helvetica, sans-serif;
font-size: 10px;
font-weight: normal;
margin: 0
}
pre
{
font-size: 10pt
}
td
{
margin: 0;
padding: 1px
}
a:link, a:visited
{
color: #000000;
text-decoration: none;
font-weight: normal
}
a:hover, a:active
{
color: #000000;
text-decoration: underline;
font-weight: normal
}
.div_top
{
width: 100%;
height: 95px;
background: url(../images/logo.png);
font-size: 15px;
color: black;
font-weight: bold;
padding: 2px 0;
margin: 0
}
.context
{
background: #F5F5F5;
background: -webkit-gradient(linear, left top, left bottom, from(#48D1CC), to(#B0E0E6));
background: -moz-linear-gradient(top, #48D1CC, #B0E0E6);
width: 100%;
padding: 10px;
text-shadow: 0 1px 1px rgba(0,0,0,.3);
-webkit-border-radius: .5em;
-moz-border-radius: .5em;
border-radius: .5em;
-webkit-box-shadow: 0 10px 2px rgba(0,0,0,.2);
-moz-box-shadow: 0 10px 2px rgba(0,0,0,.2);
box-shadow: 0 10px 2px rgba(0,0,0,.2);
color: #000000;
border: solid 1px #000000;
}
.menu
{
padding: 5px 0;
border-right: 1px solid #999999;
border-bottom: 1px solid #999999;
text-shadow: 0 1px 1px rgba(0,0,0,.3);
-webkit-border-radius: .5em;
-moz-border-radius: .5em;
border-radius: .5em;
-webkit-box-shadow: 0 10px 2px rgba(0,0,0,.2);
-moz-box-shadow: 0 10px 2px rgba(0,0,0,.2);
box-shadow: 0 10px 2px rgba(0,0,0,.2);
color: #d9eef7;
border: solid 1px #000000;
background: #0095cd;
background: -webkit-gradient(linear, left top, left bottom, from(#48D1CC), to(#B0E0E6));
background: -moz-linear-gradient(top, #48D1CC, #B0E0E6);
filter: progid:DXImageTransform.Microsoft.gradient(startColorstr='#00adee', endColorstr='#0078a5');
}
.menu_header
{
margin: 0 0 10px 10px;
font-size: 10px;
font-weight: bold
}
.menu a:link, .menu a:visited
{
border: 1px #000000;
display: block;
color: #000000;
padding: 2px 2px 2px 15px;
margin: 0 2px 0px 2px;
font-weight: normal;
width: 150px;
text-decoration: none
}
.menu a:hover, .menu a:active
{
border: 1px solid #000000;
background-color: #FFFFFF;
text-decoration: none;
color: #000000
}
.bot_a:link, .bot_a:visited
{
color: #FF4500;
font-weight: bold;
text-decoration: none
}
.bot_a:hover, .bot_a:active
{
color: #FFFFFF;
font-weight: bold;
text-decoration: underline
}
.menu_separator
{
border-top: 1px solid #000000;
margin: 2px 0
}
.menu_info
{
color: #000000;
padding: 2px 2px 2px 15px;
margin: 0 2px;
font-weight: normal;
width: 150px
}
.table_frame
{
border: solid 1px #000000;
background: #FFFFFF;
margin: 0 auto;
padding: 1px
}
.table_frame td
{
white-space:nowrap
}
.td_header
{
background: #48D1CC;
color: #000000;
font-weight: bold;
padding: 1px;
margin: 0
}
.td_header a:link, .td_header a:visited
{
color: #000000;
text-decoration: none;
font-weight: bold
}
.td_header a:hover, .td_header a:active
{
color: #FFFFFF;
text-decoration: underline;
font-weight: bold
}
.td_c1
{
background: #AFEEEE;
padding: 1px;
margin: 0
}
.td_c2
{
background: #B0E0E6;
padding: 1px;
margin: 0
}
.error
{
color: #FF0000;
font-weight: bold
}
.success
{
color: #228B22;
font-weight: bold
}
.screenshot
{
border: solid 1px #FF0000
}
.popupmenu table
{
color: #3A5FCD;
border: solid 1px #000000;
background-color: #FFFFFF;
}
.popupmenu td
{
padding: 0
}
.popupmenu a:link, .popupmenu a:visited
{
border: 1px solid #FFFFFF;
display: block;
color: #404040;
padding: 2px 15px;
margin: 0;
font-weight: normal;
text-decoration: none;
background-color: #FFFFFF
}
.popupmenu a:hover, .popupmenu a:active
{
border: 1px solid #999999;
background-color: #AFEEEE;
text-decoration: none;
color:#000000
}
.popupmenu hr
{
border: 1px solid #000000;
background-color: #AFEEEE;
margin: 0;
padding: 0
}
.table_frame_backgrounds
{
border: solid 3px #ffffff;
background: #F5F5F5;
-moz-border-radius: 5px;
border-radius: 5px;
}
.sexy_list_infol1{
background: rgb(143, 126, 126);
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
font-size: 10px;
}
.sexy_list_infol2{
background: rgb(56, 50, 50);
padding: 1px;
margin: 0;
font-size: 10px;
border: solid 1px #cccccc;
}
.sexy_list_infor1{
background: rgb(143, 126, 126);
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
font-size: 10px;
}
.sexy_list_infor2{
background: rgb(56, 50, 50);
padding: 1px;
margin: 0;
font-size: 10px;
border: solid 1px #cccccc;
}
.sexy_list_infol3{
background: #efefef;
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
}
//////
.sexy_list_infl1{
background: #000000;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infl2{
background: #efefef;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infr1{
background: #FFFFFF;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infr2{
background: #efefef;
padding: 1px;
margin: 0;
font-size: 10px;
}
///////////////
--
others cnc:, panel of 'second' zeusVM generation:
Code: Select all
https://fine.landingplans.net/solution/theme/throbber.gif
https://fine.landingplans.net/enter/theme/throbber.gif
https://fine.landingplans.net/shop/theme/throbber.gif
https://fine.landingplans.net/central/theme/throbber.gif
Attachments
infected
(120.35 KiB) Downloaded 128 times
(120.35 KiB) Downloaded 128 times
infected
(416.96 KiB) Downloaded 238 times
(416.96 KiB) Downloaded 238 times