kendra.fr got take down but is back, config in attachement.
[syntax="php"]
$config['botnet_cryptkey'] = 'Hello';
$config['botnet_cryptkey_bin'] = array(72, 174, 59, 139, 180, 33, 182, 231, 179, 244, 136, 58, 86, 56, 69, 218, 108, 141, 106, 16, 126, 109, 217, 92, 227, 68, 77, 74, 184, 135, 170, 165, 186, 71, 94, 67, 202, 93, 73, 133, 61, 101, 166, 142, 64, 137, 216, 189, 36, 63, 107, 18, 171, 76, 241, 95, 192, 212, 88, 28, 134, 167, 210, 125, 10, 194, 23, 105, 116, 54, 127, 236, 223, 239, 176, 47, 151, 83, 60, 24, 70, 190, 43, 2, 119, 121, 104, 102, 129, 219, 82, 232, 4, 29, 144, 112, 252, 111, 55, 35, 187, 160, 221, 3, 11, 169, 215, 172, 130, 90, 118, 45, 14, 206, 175, 44, 52, 140, 80, 17, 233, 242, 34, 7, 30, 220, 120, 198, 91, 162, 193, 51, 62, 100, 207, 25, 85, 255, 40, 234, 204, 96, 196, 173, 48, 251, 150, 65, 147, 185, 152, 6, 53, 155, 164, 163, 5, 81, 197, 228, 237, 20, 131, 50, 66, 0, 229, 98, 208, 235, 158, 114, 199, 188, 37, 225, 9, 250, 230, 209, 254, 32, 123, 226, 211, 89, 19, 128, 78, 253, 168, 79, 13, 145, 181, 248, 8, 38, 195, 161, 200, 22, 117, 177, 201, 97, 46, 224, 214, 27, 42, 110, 1, 178, 87, 146, 75, 238, 99, 138, 159, 157, 148, 113, 103, 26, 132, 39, 249, 243, 153, 41, 203, 240, 205, 246, 122, 12, 149, 191, 222, 245, 143, 247, 21, 31, 156, 49, 213, 57, 183, 84, 15, 154, 115, 124);[/syntax]
And another one in attach calling 193.169.189.45.
https://www.virustotal.com/en/file/1bd1 ... 434376067/ detected as PWS:Win32/Zbot.gen!VM by Microsoft.