script for unpack old versions
https://damagelab.org/index.php?showtopic=21391
https://damagelab.org/index.php?showtopic=21391
A forum for reverse engineering, OS internals and malware analysis
hxxp://globallaty.ru/bambo/gzm.php;90dropper and decrypted config attached.
[settings]comes from hxxp://kerneldz.dyndns.org/main/bin/
Plugin3Config=
Plugin3=
Plugin2Config=
Plugin2=
Plugin1Config=
Plugin1=
WebInjectsPath=
ClearCookies=1
KillZeus=1
UpxCompress=1
ConnectorInterval=300
EncKey=azerty321
SpyEyeCollectorPath=78.47.59.236:53
MainCpPathBack=hxxp://kerneldz.dyndns.org/main/gate.php
MainCpPath=hxxp://kerneldz.dyndns.org/main/gate.php
They event don't know how to configure properly the webshit, patheticIt's common plague for SpyEye skiddie users :D
hxxp://raz7pi7zop.com/gate.php;1800bot and decrypted config in attach
hxxp://da3bom7ano.com/gate.php;1800
hxxp://tan6vop3ar.com/gate.php;1800
hxxp://to3rta7nol.com/gate.php;1800
hxxp://dan6tos7pt.com/gate.php;1800
hxxp://baxo6pa7bo.com/gate.php;1800
hxxp://to6mn3aslo.com/gate.php;1800
hxxp://pas6te7rtp.com/gate.php;1800
hxxp://pot6sa5noa.com/gate.php;1800
hxxp://san4di4pot.com/gate.php;1800
hxxp://n3ot6a4rl4op.com/gate.php;1800
hxxp://t3atu47g4ano.com/gate.php;1800
hxxp://so4p3sa47nop.com/gate.php;1800
hxxp://4t3an6bo4kit.com/gate.php;1800
hxxp://sos343na4gol.com/gate.php;1800
hxxp://po43n6c4hita.com/gate.php;1800
hxxp://l43ot4ra7nef.com/gate.php;1800
hxxp://bu43b3nut7ar.com/gate.php;1800
hxxp://sop35m5a3not.com/gate.php;1800
hxxp://raz47pi7z3op.com/gate.php;1800
hxxp://da3bom37a4no.com/gate.php;1800
hxxp://ta4n64o3p3ar.com/gate.php;1800
hxxp://to3rt3a57nol.com/gate.php;1800
hxxp://dan65t3os7pt.com/gate.php;1800
hxxp://to6n4m3a3dor.com/gate.php;1800
hxxp://ba3xo56pa7bo.com/gate.php;1800
hxxp://to365mn3aslo.com/gate.php;1800
hxxp://pa3s6t7e7rtp.com/gate.php;1800
hxxp://po3t6s6a5noa.com/gate.php;1800
hxxp://san34di74pot.com/gate.php;1800
hxxp://addleslawcenter.com/9999/gate.php;60Plugins:
C:\Data\Documents\My Projects\CC\CardNet\Progs\Client\SpyEye\plugins\BC\Client\Release\ftpbc.pdb