Researchers Center: Atmos Strategic Monitoring


SPYWARE.CITADEL.ATMOS

Sample: 8af844ea647979196c02178e019732202595872c
SHA256: 36238af0cd449a70ee35a687540d281fb64f9d0dbe640efe1a5f6ff1fab18f72
Request: Tayuya [2016/08/25 - 21:08:10]
Callback: emzmnQXLRM3tnwCF.ga
Gate: http://emzmnQXLRM3tnwCF.ga/temp/cGxXsMjG.php|file=GWKW5feP.xml
Decryptor logs:
DEBUG:root:[*] get base config & several params
DEBUG:root:[*] found base config at RVA:0x000059b0, RA:0x000059b0
DEBUG:root:[*] found login key: 3533334439323236453443314345304139383135444245423139323335414534
DEBUG:root:[*] use RC4 key at (base config + 0x00000157)
DEBUG:root:[*] found following xor key for AES plus:
DEBUG:root:[62, 74, 187, 1, 132, 27, 178, 152, 18, 43, 181, 239, 177, 190, 209, 113]
DEBUG:root:[*] found RC4 salt: 0xF2C9CDEF
DEBUG:root:[*] found xor key using after Visual Decrypt: 0xF2C9CDEF
DEBUG:root:C&C found:
DEBUG:root:['http://qDmvqh5Nh3C6szRH.cf/temp/cGxXsMjG.php|file=GWKW5feP.xml', 'http://emzmnQXLRM3tnwCF.ga/temp/cGxXsMjG.php|file=GWKW5feP.xml', 'http://Zvb3Q6zESntP7bjn.gq/temp/cGxXsMjG.php|file=GWKW5feP.xml']
DEBUG:root:[*] try to unpack
DEBUG:root:[*] decrypt data using following key:
DEBUG:root:[65, 139, 235, 146, 25, 134, 174, 29, 12, 9, 95, 125, 119, 98, 22, 124, 34, 81, 17, 224, 21, 99, 50, 118, 139, 211, 212, 165, 104, 198, 146, 149, 108, 66, 48, 9, 226, 231, 139, 24, 150, 83, 96, 98, 85, 40, 153, 94, 130, 234, 188, 19, 147, 19, 190, 67, 203, 151, 107, 216, 212, 254, 16, 80, 231, 213, 63, 249, 24, 38, 152, 228, 13, 184, 78, 74, 83, 33, 130, 13, 35, 32, 179, 193, 165, 246, 145, 47, 78, 165, 74, 251, 247, 201, 45, 84, 75, 126, 80, 134, 10, 21, 57, 48, 95, 43, 7, 148, 207, 59, 185, 236, 229, 143, 117, 173, 100, 182, 208, 136, 186, 27, 169, 89, 163, 217, 29, 188, 174, 20, 49, 128, 111, 48, 207, 202, 190, 67, 128, 226, 248, 181, 251, 182, 60, 116, 83, 152, 188, 125, 26, 61, 173, 124, 131, 87, 144, 78, 28, 53, 101, 84, 165, 254, 20, 14, 104, 203, 27, 144, 106, 172, 0, 233, 209, 27, 214, 63, 120, 59, 59, 195, 64, 239, 246, 105, 27, 112, 80, 54, 59, 155, 125, 203, 233, 214, 251, 96, 155, 110, 240, 179, 87, 133, 11, 109, 54, 28, 237, 149, 202, 115, 245, 200, 84, 211, 74, 112, 25, 163, 89, 214, 193, 222, 161, 159, 55, 83, 109, 186, 101, 99, 192, 12, 226, 242, 177, 142, 88, 225, 222, 39, 52, 5, 184, 45, 170, 186, 219, 222, 159, 11, 54, 87, 42, 252]
DEBUG:root:[*] try to AES+ decryption
DEBUG:root:[*] use following AES key:
DEBUG:root:[20, 50, 241, 93, 114, 101, 29, 72, 78, 209, 168, 140, 64, 11, 121, 123]
Report:
{'login_key_hexed': '3533334439323236453443314345304139383135444245423139323335414534', 'base_key': {'y': 104, 'x': 82, 'state': [65, 226, 208, 12, 146, 203, 246, 117, 66, 98, 207, 12, 75, 43, 188, 11, 198, 81, 17, 224, 21, 99, 50, 118, 139, 211, 212, 165, 104, 34, 146, 149, 108, 25, 48, 9, 226, 231, 139, 24, 150, 83, 96, 98, 85, 40, 153, 94, 130, 234, 188, 19, 147, 19, 190, 67, 203, 151, 107, 216, 212, 254, 16, 80, 231, 213, 63, 249, 24, 38, 152, 228, 13, 184, 78, 74, 83, 33, 130, 13, 35, 32, 179, 193, 165, 174, 145, 47, 78, 165, 74, 251, 247, 201, 45, 84, 119, 126, 80, 134, 10, 21, 57, 48, 95, 9, 7, 148, 95, 59, 185, 236, 229, 143, 29, 173, 100, 182, 235, 136, 186, 27, 169, 89, 163, 217, 29, 22, 174, 20, 49, 128, 111, 48, 207, 202, 190, 67, 128, 139, 248, 181, 251, 182, 60, 116, 83, 152, 188, 125, 26, 61, 173, 124, 131, 87, 144, 78, 28, 53, 101, 84, 165, 254, 20, 14, 104, 134, 27, 144, 106, 172, 0, 233, 209, 27, 214, 63, 120, 59, 59, 195, 64, 239, 246, 105, 27, 112, 80, 54, 59, 155, 125, 203, 233, 214, 251, 96, 155, 110, 240, 179, 87, 133, 11, 109, 54, 28, 237, 149, 202, 115, 245, 200, 84, 211, 74, 112, 25, 163, 89, 214, 193, 222, 161, 159, 55, 83, 109, 186, 101, 99, 192, 125, 226, 242, 177, 142, 88, 225, 222, 39, 52, 5, 184, 45, 170, 186, 219, 222, 159, 124, 54, 87, 42, 252], 'z': 116}, 'xor_key': '>J\xbb\x01\x84\x1b\xb2\x98\x12+\xb5\xef\xb1\xbe\xd1q', 'urls': ['http://qDmvqh5Nh3C6szRH.cf/temp/cGxXsMjG.php|file=GWKW5feP.xml', 'http://emzmnQXLRM3tnwCF.ga/temp/cGxXsMjG.php|file=GWKW5feP.xml', 'http://Zvb3Q6zESntP7bjn.gq/temp/cGxXsMjG.php|file=GWKW5feP.xml'], 'base_config_hexed': '1779e613a165c3d68a57206525ea7d55876e33a28be1a245191b8b04a748bb8eff9beac74341e2612f94e4ac9f9247af518d6277eb23acaf407122687474703a2f2f71446d767168354e68334336737a52482e63662f74656d702f63477858734d6a472e7068707c66696c653d47574b57356665502e786d6c0000000000000000000000000000000000000000000000000000000000000000000000000000005e728f5a04913d73939b38700e17421edc5e99d5cb971a0654e6ac1421e1dc6504000100eae533b948ea08d27439de457f30ed7802972f8f5fd2c340495b90e387702ac9f409f9cfcb0d983321c57ba6b391d5a2e2dab8fdfc477ebfbd346931166086363c000000a46eb0391ea46269ffe917fb7449fd78b4ada7368552b074017aa1a6090004005c731a8c72bcdbb7eca07c2cbfcc46270d6d0450a79facd7d12842c24566fa867a869dd525f72db8011eccddcb4cda418beb921986ae1d0c095f7d7762167c225111e0156332768bd3d4a568c692956c423009e2e78b18965360625528995e82eabc139313be43cb976bd8d4fe1050e7d53ff9182698e40db84e4a5321820d2320b3c1a5f6912f4ea54afbf7c92d544b7e50860a1539305f2b0794cf3bb9ece58f75ad64b6d088ba1ba959a3d91dbcae1431806f30cfcabe4380e2f8b5fbb63c745398bc7d1a3dad7c8357904e1c356554a5fe140e68cb1b906aac00e9d11bd63f783b3bc340eff6691b7050363b9b7dcbe9d6fb609b6ef0b357850b6d361ced95ca73f5c854d34a7019a359d6c1dea19f37536dba6563c00ce2f2b18e58e1de273405b82daabadbde9f0b36572afc52687474703a2f2f656d7a6d6e51584c524d33746e7743462e67612f74656d702f63477858734d6a472e7068707c66696c653d47574b57356665502e786d6c00e8b2c911bd9ffad8a189b865e159da891514e20ef85c7452773a0d35081af1353d1765d899791f4ba27cfb483754ef3c246d41aaf4f7f7ca07a29077e4a6f148cf07a2fc9f173a1bca3c18dac2f3543f8415f5876d5a65c5501b22cbc75cb54dc609e84476803491400800000040f2da5c94676d0c8ba4897d2c2bfa5942268f4aa69f79c64200460000002b1143af55d470fe2379949e5eb45e13cd43632a5581642f6339d4618fb895a379260374f7163321735b7c398e1d3742092dc4aae696ce01ca75cf65a60ad63d960e882a0a47643a235b4c5f60e2412079be6f8f8baf697b7622080004008bb94b72dab7d4928cb0fc200bf71b280416e49f6bbf8cf5bf062fe98fce6fa13d815efa02059e1d32000000c1e9081a078a1178c024318f570bbc726404b03773fc974d07faaf10de53499b771d6fddd2e5c9f077a5c2a5b9f0e6643c708e33b592c014f180519419504ca1347a989ced90d4af962986616e1f75671ffa53bd8bab9ff6c87ecad14b58040000eaca7de1f1fa5e289ac6e9fdfe3125168a45ff7eaffe9c95db63ee59a9f685e3554ea8347203a532dfca65eef7e1432808ae1e1506a3ad608164136ed52cb4e6a16d4606000300bee0dafeca704f6c5e5cd445d91956d22f57156a3236034010b76c7f1d70dc99d3853edb17d34146be687474703a2f2f5a76623351367a45536e745037626a6e2e67712f74656d702f63477858734d6a472e7068707c66696c653d47574b57356665502e786d6c0000000000000000000000000000000000000000000000000000000000000000000000000000005a4a42af56c8b0ee4638e214de8bd3c2917b25a1b21f6699dabd934489dfdaa210a9a40eae69d370f97048b57f21a97cae47', 'salt': '\xef\xcd\xc9\xf2'}
Tools: [Hybrid] [MDB]

Download File