Skip to content

Instantly share code, notes, and snippets.

@herbiezimmerman
Created November 15, 2017 17:30
Show Gist options
  • Save herbiezimmerman/1180f45066dc1d2f82c5cb95a8c67d87 to your computer and use it in GitHub Desktop.
Save herbiezimmerman/1180f45066dc1d2f82c5cb95a8c67d87 to your computer and use it in GitHub Desktop.
2017-11-15 Dridex Malspam
Snippet from script for the binary:
===============================
//|:ptth|exe.oRYtXTJY\|elifotevas|ydoBesnopser|etirw|nepo|epyT|PmeT|TeG|ssecorP|llehs.tpircsW|noitacilppA.llehs|Maerts.bdodA|PTTHLMX.tfosorciM
----
Microsoft.XMLHTTP|Adodb.streaM|shell.Application|Wscript.shell|Process|GeT|TemP|Type|open|write|responseBody|savetofile|\XdzEBhuN.exe|http:|//
//|:ptth|exe.bYONuOReq\|elifotevas|ydoBesnopser|etirw|nepo|epyT|PmeT|TeG|ssecorP|llehs.tpircsW|noitacilppA.llehs|Maerts.bdodA|PTTHLMX.tfosorciM
----
Microsoft.XMLHTTP|Adodb.streaM|shell.Application|Wscript.shell|Process|GeT|TemP|Type|open|write|responseBody|savetofile|\qeROuNOYb.exe|http:|//
//|:ptth|exe.NuhBEzdX\|elifotevas|ydoBesnopser|etirw|nepo|epyT|PmeT|TeG|ssecorP|llehs.tpircsW|noitacilppA.llehs|Maerts.bdodA|PTTHLMX.tfosorciM
----
Microsoft.XMLHTTP|Adodb.streaM|shell.Application|Wscript.shell|Process|GeT|TemP|Type|open|write|responseBody|savetofile|\YJTXtYRo.exe|http:|//
URLs from script:
=================
palimpsesto-technologies.es/jhvgRg5?
axtes.com/jhvgRg5?
vonmammen.org/jhvgRg5?
ticketstekoop.nl/jhvgRg5?
test136.siteholder.ru/jhvgRg5?
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment