Source: 00000001.00000000.230933027.00000000003C1000.00000040.00000400.00020000.00000000.sdmp |
Malware Configuration Extractor: FormBook {"C2 list": ["www.lafuriaroja.team/jn86/"], "decoy": ["yzeym.top", "bettymassage.co.uk", "zvzac.com", "eventscomparison.xyz", "ybzgh.com", "3618shop.com", "sosoicey.com", "sundancerenewable.com", "whorephotos.com", "zamawiamy.online", "idmtoucan.site", "home-visites.com", "maxtesler.website", "terilio.net", "aaemp.com", "linksy.site", "hairurge.com", "lizzo.ltd", "ukmcqc.co.uk", "coolerzap.net", "minifini.com", "rainjewel.com", "picassoai.art", "qwry.store", "gstwarehousesolutions.com", "fexlueg.xyz", "residentiallaw.uk", "corelinks.app", "suaratkbm.com", "juliettjaya.xyz", "suggestiontherapy.com", "chocolatemacaroon.com", "axionmotion.net", "gurpreet.world", "watersportsale.space", "babyinbalance.com", "alcacersurveyors.com", "jerseycity.construction", "jav-stars.com", "xn--micrsoft-q4a.com", "9966181.xyz", "batesmotel.xyz", "liquidationsteals.com", "guveniliradresim5.site", "onlycars.app", "156293.sbs", "fithealthcode.net", "bin-pro.com", "vacation2me.net", "ofertalbox.com", "tesla3.website", "saradaram.com", "forttownfinancial.net", "aguide2floridakeys.com", "asd461.xyz", "nihan.world", "vife.solutions", "aspotfy.com", "muttleycrue.net", "qvai-p8.xyz", "bestastroraghuram.com", "thefsdcollective.xyz", "flowerstudio.info", "clearwaterbeachdiet.store"]} |