Version 1.3.5.1 targeting wellsfargo.com
https://www.virustotal.com/en/file/0f3c ... 373629965/
Solving the last interesting old sample in this thread, rest are .zip without config.
Code: Select all
C&C
Drop: hxtp://173.192.210.79/KEAGAN/BBA/gate.php
Update: hxtp://173.192.210.79/KEAGAN/BBA/file.php|file=soft.exe
Key: B5 45 6D 50 7D 87 0E 24 F7 55 60 7C 47 4C 15 E5
Login key: C1F20D2340B519056A7D89B7DF4B0FFF
Code: Select all
exe, plugin, config and decoded in attachhxtp://173.192.210.79/KEAGAN/BBA/install/
hxtp://173.192.210.79/KEAGAN/BBA/my.php?m=login
hxtp://173.192.210.79/KEAGAN/BBA/_lk3/files/CIT/
https://www.virustotal.com/en/file/0f3c ... 373629965/
Solving the last interesting old sample in this thread, rest are .zip without config.
Xylitol wrote:FunCitadel v1.3.4.0 targeting a lot of banks (chase, bank of america, capital one, pnc, american express...) and some germans banks.Code: Select alltwo more C&C00420CD8 |. 68 C0194000 PUSH 4019C0 ; |Text = "Coded by BRIAN KREBS for personal use only. I love my job & wife."
Code: Select allhttps://www.virustotal.com/file/6f6b5fe ... 338035569/hxxp://inbani.com/js/res/cp.php?m=login hxxp://inbani.com/js/res/theme/images/citadel.jpg -- hxxp://lotosmusicfm.net/jstat/cp.php hxxp://lotosmusicfm.net/jstat/theme/images/citadel.jpg
Code: Select all
Drop: hxtp://metaxserv93.in/webstat79/info.php
Update: hxtp://metaxserv15.in/webstat79/file.php|file=volumeup.exe
Key: 62 86 90 BE 08 CB B0 C4 B5 25 0B 39 4D 82 65 02
Login key: 79B194D261FBD4BE3591802621C7E08E
Attachments
infected
(339.13 KiB) Downloaded 75 times
(339.13 KiB) Downloaded 75 times
infected
(537.49 KiB) Downloaded 81 times
(537.49 KiB) Downloaded 81 times