|
||
Researchers Center: Atmos Strategic Monitoring |
SPYWARE.CITADEL.ATMOSSample: e95209d1967c59f5765d728b979533f374d33f26SHA256: b1dfe945d6adf89e9bf06879c35c7e81fe0fd28243a206165160631163e57143 Request: Tayuya [2016/11/12 - 22:11:53] Callback: webspace.ph Gate: http://webspace.ph/ftp1/file.php|file=webs.xml Decryptor logs: DEBUG:root:[*] get base config & several params DEBUG:root:[*] found base config at RVA:0x000059b0, RA:0x000059b0 DEBUG:root:[*] found login key: 3533334439323236453443314345304139383135444245423139323335414534 DEBUG:root:[*] use RC4 key at (base config + 0x00000157) DEBUG:root:[*] found following xor key for AES plus: DEBUG:root:[62, 74, 187, 1, 132, 27, 178, 152, 18, 43, 181, 239, 177, 190, 209, 113] DEBUG:root:[*] found RC4 salt: 0xF2C9CDEF DEBUG:root:[*] found xor key using after Visual Decrypt: 0xF2C9CDEF DEBUG:root:C&C found: DEBUG:root:['http://webspace.ph/ftp1/file.php|file=webs.xml'] DEBUG:root:[*] try to unpack DEBUG:root:[*] decrypt data using following key: DEBUG:root:[19, 83, 109, 25, 144, 17, 254, 23, 172, 169, 42, 204, 171, 158, 49, 64, 129, 26, 162, 20, 91, 115, 159, 157, 216, 118, 75, 250, 92, 129, 79, 154, 217, 10, 161, 78, 62, 201, 62, 193, 13, 130, 137, 60, 131, 215, 141, 45, 114, 217, 31, 233, 71, 192, 96, 91, 251, 182, 202, 156, 198, 220, 133, 110, 206, 178, 30, 139, 242, 44, 185, 216, 176, 250, 5, 85, 237, 226, 60, 103, 228, 69, 95, 56, 165, 233, 43, 16, 134, 55, 170, 159, 48, 75, 54, 169, 174, 124, 206, 197, 158, 4, 17, 90, 194, 236, 138, 4, 113, 34, 99, 153, 84, 50, 44, 130, 220, 147, 173, 114, 98, 190, 179, 31, 150, 112, 89, 59, 255, 210, 236, 13, 167, 19, 194, 76, 111, 1, 193, 243, 34, 204, 174, 97, 233, 150, 248, 212, 142, 137, 131, 234, 41, 238, 139, 218, 204, 36, 126, 147, 40, 18, 143, 179, 89, 116, 203, 206, 10, 216, 216, 46, 31, 7, 149, 99, 246, 42, 167, 182, 207, 127, 251, 111, 86, 214, 71, 150, 208, 90, 198, 227, 223, 107, 84, 236, 197, 199, 225, 208, 3, 132, 147, 27, 9, 142, 123, 14, 156, 29, 128, 232, 30, 212, 56, 163, 26, 222, 227, 11, 254, 253, 26, 219, 73, 176, 240, 194, 42, 133, 241, 74, 170, 166, 85, 87, 23, 72, 124, 108, 103, 189, 21, 68, 199, 104, 93, 15, 53, 27, 207, 49, 160, 61, 120, 53] DEBUG:root:[*] try to AES+ decryption DEBUG:root:[*] use following AES key: DEBUG:root:[220, 175, 226, 48, 151, 223, 176, 13, 50, 215, 136, 163, 196, 210, 160, 126]Report: {'login_key_hexed': '3533334439323236453443314345304139383135444245423139323335414534', 'base_key': {'y': 104, 'x': 82, 'state': [19, 56, 223, 222, 236, 179, 98, 97, 156, 42, 49, 227, 19, 78, 129, 204, 226, 26, 162, 20, 91, 115, 159, 157, 216, 118, 75, 250, 92, 129, 79, 154, 217, 10, 161, 158, 62, 201, 62, 193, 13, 130, 137, 60, 131, 215, 141, 45, 114, 217, 31, 233, 71, 192, 96, 91, 251, 182, 202, 172, 198, 220, 133, 110, 206, 178, 30, 139, 242, 44, 185, 216, 176, 250, 5, 85, 237, 42, 60, 103, 228, 69, 95, 83, 165, 233, 43, 16, 134, 55, 170, 159, 48, 75, 54, 169, 174, 124, 206, 197, 158, 4, 17, 90, 194, 144, 138, 4, 113, 34, 99, 153, 84, 50, 44, 130, 220, 147, 173, 114, 254, 190, 17, 31, 150, 112, 89, 59, 255, 210, 236, 13, 167, 171, 194, 76, 111, 1, 193, 243, 34, 64, 174, 23, 233, 150, 248, 212, 142, 137, 131, 234, 41, 238, 139, 218, 204, 36, 126, 147, 40, 18, 143, 179, 89, 116, 203, 206, 10, 216, 216, 46, 31, 7, 149, 99, 246, 42, 167, 182, 207, 127, 251, 111, 86, 214, 71, 150, 208, 90, 198, 227, 109, 107, 84, 236, 197, 199, 225, 208, 3, 132, 147, 27, 9, 142, 123, 14, 156, 29, 128, 232, 30, 212, 56, 163, 26, 25, 204, 11, 254, 253, 26, 219, 73, 176, 240, 194, 169, 133, 241, 74, 170, 166, 85, 87, 23, 72, 124, 108, 103, 189, 21, 68, 199, 104, 93, 15, 53, 27, 207, 49, 160, 61, 120, 53], 'z': 116}, 'xor_key': '>Jxbbx01x84x1bxb2x98x12+xb5xefxb1xbexd1q', 'urls': ['http://webspace.ph/ftp1/file.php|file=webs.xml'], 'base_config_hexed': '1779e613a165c3d68a57206525ea7d55876e33a28be1a245191b8b04a748bb8eff9beac74341e2612f94e4ac9f9247af518d6277eb23acaf407122687474703a2f2f77656273706163652e70682f667470312f66696c652e7068707c66696c653d776562732e786d6c000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005e728f5a04913d73939b38700e17421edc5e99d5cb971a0654e6ac1421e1dc6504000100eae533b948ea08d27439de457f30ed7802972f8f5fd2c340495b90e387702ac9f409f9cfcb0d983321c57ba6b391d5a2e2dab8fdfc477ebfbd346931166086363c000000a46eb0391ea46269ffe917fb7449fd78b4ada7368552b074017aa1a6090004005c731a8c72bcdbb7eca07c2cbfcc46270d6d0450a79facd7d12842c24566fa867a869dd525f72db8011eccddcb4cda13536d199011fe17aca92accab9e3140811aa2145b739f9dd8764bfa5c814f9ad90aa14e3ec93ec10d82893c83d78d2d72d91fe947c0605bfbb6ca9cc6dc856eceb21e8bf22cb9d8b0fa0555ede23c67e4455f38a5e92b108637aa9f304b36a9ae7ccec59e04115ac2ec8a047122639954322c82dc93ad7262beb31f9670593bffd2ec0da713c24c6f01c1f322ccae61e996f8d48e8983ea29ee8bdacc247e9328128fb35974cbce0ad8d82e1f079563f62aa7b6cf7ffb6f56d64796d05ac6e3df6b54ecc5c7e1d00384931b098e7b0e9c1d80e81ed438a31adee30bfefd1adb49b0f0c22a85f14aaaa6555717487c6c67bd1544c7685d0f351bcf31a03d783552687474703a2f2f77656273706163652e70682f667470312f66696c652e7068707c66696c653d776562732e786d6c002f806fead280f3137a59313e8cafcdcfe8b2c911bd9ffad8a189b865e159da891514e20ef85c7452773a0d35081af1353d1765d899791f4ba27cfb483754ef3c246d41aaf4f7f7ca07a29077e4a6f148cf07a2fc9f173a1bca3c18dac2f3543f8415f5876d5a65c5501b22cbc75cb54dc609e84476803491400800000040f2da5c94676d0c8ba4897d2c2bfa5942268f4aa69f79c67500730063006100000055d470fe2379949e5eb45e13cd43632a5581642f6339d4618fb895a379260374f7163321735b7c398e1d3742092dc4aae696ce01ca75cf65a60ad63d960e882a0a47643a235b4c5f60e2412079be6f8f8baf697b7622080004008bb94b72dab7d4928cb0fc200bf71b280416e49f6bbf8cf5bf062fe98fce6fa13d815efa02059e1d32000000c1e9081a078a1178c024318f570bbc726404b03773fc974d07faaf10de53499b771d6fddd2e5c9f077a5c2a5b9f0e6643c708e33b592c014f180519419504ca1347a989ced90d4af962986616e1f75671ffa53bd8bab9ff6c87ecad14b18040400eaca7de1f1fa5e289ac6e9fdfe3125168a45ff7eaffe9c95db63ee59a9f685e3554ea8347203a532dfca65eef7e1432808ae1e1506a3ad608164136ed52cb4e6a16d4606000300bee0dafeca704f6c5e5cd445d91956d22f57156a3236034010b76c7f1d70dc99d3853edb17d34146be687474703a2f2f77656273706163652e70682f667470312f66696c652e7068707c66696c653d776562732e786d6c000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005a4a42af56c8b0ee4638e214de8bd3c2917b25a1b21f6699dabd934489dfdaa210a9a40eae69d370f97048b57f21a97cae47', 'salt': 'xefxcdxc9xf2', 'remote_config': {}}Tools: [Hybrid] [MDB] Download File |