Skip to content

Instantly share code, notes, and snippets.

@0xToxin
Last active November 18, 2023 18:21
Show Gist options
  • Save 0xToxin/34978dab36d55285d163456fef8e593b to your computer and use it in GitHub Desktop.
Save 0xToxin/34978dab36d55285d163456fef8e593b to your computer and use it in GitHub Desktop.
JanelaRat fetches from remote DGA C2's keywords list and the port for the real C2
Related campaign - https://twitter.com/1ZRR4H/status/1725609793216291100
***************************************
* no keywords path this time :( *
* /postal.php - for C2 port *
***************************************
orionprimexgold1.ddns.net
orionprimexgold2.ddnsking.com
orionprimexgold3.3utilities.com
orionprimexgold4.bounceme.net
orionprimexgold5.freedynamicdns.net
orionprimexgold6.freedynamicdns.org
orionprimexgold7.gotdns.ch
orionprimexgold8.hopto.org
orionprimexgold9.myddns.me
orionprimexgold10.myftp.biz
orionprimexgold11.myftp.org
orionprimexgold12.myvnc.com
orionprimexgold13.onthewifi.com
axeroldcapitalx9x.onthewifi.com
orionprimexgold15.servebeer.com
orionprimexgold16.serveblog.net
openxmegaeur97.serveblog.net
orionprimexgold18.serveftp.com
orionprimexgold19.servegame.com
privgold20x10.servegame.com
hx9bemmexgold21.serveblog.net
orogold22cstrike.myddns.me
orionprimexgold23.serveminecraft.net
pkdelasexgold24.servepics.com
orionprimexgold25.servepics.com
orionprimexgold26.servequake.com
vemmoneyxgold27.viewdns.net
orionprimexgold28.viewdns.net
orionprimexgold29.webhop.me
plataplatamygold9x9.bounceme.net
orionprimexgold31.serveblog.net
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment