Source: 10.2.explorer.exe.30b0000.0.unpack |
Malware Configuration Extractor: Qbot {"Bot id": "obama53", "Campaign": "1622633996", "Version": "402.68", "C2 list": ["96.61.23.88:995", "86.220.62.251:2222", "71.74.12.34:443", "75.67.192.125:443", "24.152.219.253:995", "105.198.236.101:443", "24.179.77.236:443", "47.22.148.6:443", "92.59.35.196:2222", "81.97.154.100:443", "207.246.116.237:443", "207.246.77.75:995", "45.32.211.207:2222", "45.77.115.208:443", "149.28.98.196:443", "45.77.115.208:2222", "144.202.38.185:995", "45.77.115.208:8443", "207.246.77.75:8443", "207.246.77.75:443", "144.202.38.185:2222", "45.77.117.108:995", "149.28.98.196:995", "149.28.101.90:443", "149.28.98.196:2222", "45.32.211.207:995", "144.202.38.185:443", "207.246.77.75:2222", "45.77.115.208:995", "45.77.117.108:443", "149.28.101.90:8443", "149.28.101.90:2222", "216.201.162.158:443", "73.151.236.31:443", "71.41.184.10:3389", "149.28.99.97:443", "149.28.99.97:995", "45.63.107.192:995", "149.28.99.97:2222", "72.240.200.181:2222", "97.69.160.4:2222", "136.232.34.70:443", "83.196.56.65:2222", "188.26.91.212:443", "140.82.49.12:443", "68.186.192.69:443", "95.77.223.148:443", "122.58.117.81:995", "197.45.110.165:995", "184.185.103.157:443", "71.187.170.235:443", "50.29.166.232:995", "92.96.3.180:2078", "27.223.92.142:995", "144.139.47.206:443", "50.244.112.106:443", "76.25.142.196:443", "75.118.1.141:443", "173.21.10.71:2222", "98.252.118.134:443", "98.192.185.86:443", "72.252.201.69:443", "67.165.206.193:993", "75.137.47.174:443", "109.12.111.14:443", "24.55.112.61:443", "190.85.91.154:443", "24.229.150.54:995", "189.210.115.207:443", "175.136.38.142:443", "83.110.108.161:2222", "100.2.123.234:443", "105.198.236.99:443", "81.214.126.173:2222", "68.204.7.158:443", "151.205.102.42:443", "149.28.101.90:995", "207.246.116.237:8443", "207.246.116.237:995", "45.77.117.108:2222", "45.32.211.207:443", "45.32.211.207:8443", "45.77.117.108:8443", "207.246.116.237:2222", "45.63.107.192:2222", "45.63.107.192:443", "172.78.18.142:443", "96.37.113.36:993", "24.122.166.173:443", "73.25.124.140:2222", "71.163.222.223:443", "24.139.72.117:443", "86.173.143.211:443", "47.196.213.73:443", "86.248.16.253:2222", "45.46.53.140:2222", "186.154.175.13:443", "70.163.161.79:443", "24.95.61.62:443", "78.63.226.32:443", "195.6.1.154:2222", "76.168.147.166:993", "64.121.114.87:443", "77.27.207.217:995", "31.4.242.233:995", "125.62.192.220:443", "195.12.154.8:443", "71.117.132.169:443", "96.21.251.127:2222", "71.199.192.62:443", "70.168.130.172:995", "8 |