Skip to content
Permalink
master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time
Reference: https://twitter.com/VK_Intel/status/1259905046134829056
BeaconType - Hybrid HTTP DNS
Port - 1
SleepTime - 50090
MaxGetSize - 1048576
Jitter - 0
MaxDNS - 195
PublicKey - b"0\xc2\x81\xc2\x9f0\r\x06\t*\xc2\x86H\xc2\x86\xc3\xb7\r\x01\x01\x01\x05\x00\x03\xc2\x81\xc2\x8d\x000\xc2\x81\xc2\x89\x02\xc2\x81\xc2\x81\x00\xc2\x9fdo\xc2\xb3S't\x1e\xc2\xa4\xc2\xa8\x16=\xc2\xa5CX\xc3\x8f\xc2\x86\xc3\x9d,0h\xc3\xbf`\xc2\x9b\xc2\xb7U\x0c\xc3\x97\xc3\xbc\x05@s\xc3\x8d)\xc3\x86\xc3\x95\xc2\x8a\xc3\xaf\xc2\x9b\xc2\xa4:\x19\x12\xc2\x9a\xc2\x98\xc2\xb0%\x16\xc2\x89Q\xc3\x8f\xc2\x9b@\xc2\xbb\xc3\xacq\xc3\xb8\xc3\x9b\xc2\xba:\xc3\x89\xc2\xb7\xc3\x81\x17\xc2\x9b\xc3\xa9c\xc2\xaa\xc3\x9f\xc2\xafj\r)\xc3\x9e\xc2\xba\xc3\x90J\xc3\xab\xc3\x85V\x02_\xc3\x91\xc3\x91\xc3\xa89\xc3\x96\xc3\x83\xc3\x8e\x0c\xc2\x977\x03\xc3\xb0\xc3\xa5\xc2\xb6\xc3\xb2\xc2\x8bl\xc2\xb9\xc3\xa1\xc2\x8a\xc2\xafWl\xc2\xb7=\xc2\xb8n\xc3\xb4\x1b9\xc3\xbe\x08\xc2\xbd-9W\xc3\x93\xc2\xb2\x00\xc2\xa8\xc2\xa9\xc3\xa9A\xc3\xab\xc3\x99\xc3\xbf\x02\x03\x01\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
C2Server - dns2.dnsskype.com,/cx,dns.dnsskype.com,/dot.gif,dns3.dnsskype.com,/j.ad
UserAgent - Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0; MAAU; NP08)
HttpPostUri - /submit.php
HttpGet_Metadata - Cookie
HttpPost_Metadata - Content-Type: application/octet-stream
id
SpawnTo - b'\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
PipeName -
DNS_Idle - 0.0.0.0
DNS_Sleep - 0
SSH_Host - Not Found
SSH_Port - Not Found
SSH_Username - Not Found
SSH_Password_Plaintext - Not Found
SSH_Password_Pubkey - Not Found
HttpGet_Verb - GET
HttpPost_Verb - POST
HttpPostChunk - 0
Spawnto_x86 - %windir%\syswow64\rundll32.exe
Spawnto_x64 - %windir%\sysnative\rundll32.exe
CryptoScheme - 0
Proxy_Config - Not Found
Proxy_User - Not Found
Proxy_Password - Not Found
bProxy_Behavior - Use IE settings
Watermark - 305419896
bStageCleanup - False
bCFGCaution - False
KillDate - 0
bProcInject_StartRWX - True
bProcInject_UseRWX - True
bProcInject_MinAllocSize - 0
ProcInject_PrependAppend_x86 - Empty
ProcInject_PrependAppend_x64 - Empty
ProcInject_Execute - CreateThread
SetThreadContext
CreateRemoteThread
RtlCreateUserThread
ProcInject_AllocationMethod - VirtualAllocEx
bUsesCookies - True
HostHeader -