i believe you are right ;]
Code: Select all{
"binary": "54f5ffd397b156782a177dfe85c3c8ea",
"family": "vmzeus2",
"rc4sbox": "561f0493246b664cc022f9ed609fe5f673ce447800135215bade1435bc746340aef15db7691a09e4d50fc14e8562c34d8c8a024f7145bdfafba7b6e9965ee35541c73ee65cd16e7261d237e15319c4862d3f58a0c2b56a31c53df0bef2ad9805b4ea834ab920aa1bac81f7df8e9e958470876c9a0bab775f3aff8d497d82cd8bb38f512e7f54b2345a292ac632909d887ae265e039ee89a37ca8bb7567d9c81c9b382c26082106fd174b07c930f5e8d3ddcadbf3d71642a6a27b47d40ca194d810f443eb9112b8fe33cb80250123361e48d0e73b5b99921d9c3c0df8dcdaccbf79a56db1270eec686f597e46cf1864fc2f280a11af502bd6a9977603a4ef57b00000",
"cfg-key": "rc6sbox",
"cfg": "https://vanilladed.com/server1/jf75qw.jpg",
"botname": "botnet2",
"version": "02.00.00.00",
"cnc": "vanilladed.com",
"urls": [
"https://golfedxx.com/ktest/mod_vnc.bin",
"https://vanilladed.com/server1/jf75qw.jpg"
],
"fakeurl": "http://olpfo.com/xapwj/cfg.bin",
"rc6sbox": "64be7c34431523a8665bd22839c72014c8bc17e6749898e2b744be04cb73dab87c8d2806b397647e057b3c3781857553bc604bc9651dbc10f0be2a3c1d33a99a5408c01e4a79b175f165ca640b14627ea1776681b3ed1fd938ac7c5befc3e1d367080476a8399c6095605577997c6b5c4d4d0f2c8991f38df2645d500026068604d45137e0451e8b9436f08416eadf717e19912906239a8cd88f9c5ca89b2f3cd30f767098698e82191e60bac20018d4",
"strings": [
"lhttp://olpfo.com/xapwj/cfg.bin"
]
}
domain seems to be dead?