new version from
http://blog.dynamoo.com/2014/06/inovice ... -spam.html
Code: Select all{
'version': '02.00.00.00',
'botnet': 'C1',
'cfg': 'https://62.76.185.30/c.jpg',
'fakeurl': 'http://ilfahcn.com/cfg.bin',
'rc4sbox': '56689c78c6122baaa6a52c6dfc75636ab873363de718fb8a77097c2622b5ccd4dc8e8f4a9f059447bd298c7b9e8d412855524921ac79b2873a92938bd1f7e2d82fa21fc74bb05af9ec74f5cb1746e4195d2db11d57d5f0cf9a15ff0e433c3f5b07d25432700b7f01c042e0973ea1041c000883dd445c8866d0aff159bf91c8fd24ce02a97a309953f30313c40c1b722e617e0da44e1a7d6e62eb9667a7ba38c5853348ad5fd67176a3a8eaede35169abdfc13580d390b7deae4d9be60a11d7b36c60e8a095814558f4149def20bbf64cee06cddaca644f1ed93110e1392ae5db820fb9fe6525f85ec2bebc8637b66b3b34506f98c923e984fac3b416f28940270000',
'rc6sbox':'8a8d6d1aecc63fd1767bff112688165e67aaed426146d46f2ce3ef389a41ac48a397aefedee1c80215c857c1b31aba5035a20c088a2c5cbaf85400c5024427a75fd3d795f8fa4a3fa3535505e5b765fe02f6e591a73eb18991c2c37d9084a24808d150e67bfe7586e79160d098bda87df92e50f524d57ba6643f1f150a790049c682d2ea188548da8d5bbb3d10735c8142ff8e089d31d43d53e9d3e3b6c19f3a428e036835d2d74034ece6c5a6eb1103'
'urls': "['https://62.76.185.30/c.jpg']"
}
many changes in binstorage... :(
attached binary raw cfg and decoded