Sample courtesy of Kafeine.
loader.bin + dump. Detected by MS as TrojanDownloader:Win32/Awavs.gen!A
cfg :
Code: Select all<config
botnet="120"
servers="202.124.205.84:8080;212.59.117.207:8080"
/>
https://feodotracker.abuse.ch/host/202.124.205.84/
Downloads 238.tmp, unpacked joined.
cfg :
Code: Select all<config
botnet="120"
servers="149.154.67.144:8080,150.214.24.132:8080,188.165.200.162:8080,62.76.187.78:8080,85.214.26.248:8080,95.140.34.140:8080,188.40.181.203:8080,90.156.238.76:8080,83.17.220.66:8080"
timeout="20"
delay="30:60"
interval="1020:1260"
/>
Public PGP Key :
Code: Select all-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9pYTezdSjwI7J9bZDFGeljChb
LB8VxQNmiIKU/VMY5TS0oYjzdY9zB6QVJC779Iwi+TQqX2Bf0rGAHCXm/3ehoe+t
Bfw8XpLt6wnK/olx3g7eY41jO4rMORPCRCmqGfhJSs07IDGwOJFn2URfTcIabowB
fAJgVhchGFQVhchGFQV91eLCQIDAQAB
-----END PUBLIC KEY-----
+ anti_rapport.dll packed in the 238.tmp as well.