<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Citadel &#8211; ViriBack Blog</title>
	<atom:link href="https://viriback.com/tag/citadel/feed/" rel="self" type="application/rss+xml" />
	<link>https://viriback.com</link>
	<description>Malware Tracker, IOCs &#38; more ...</description>
	<lastBuildDate>Sun, 13 May 2018 20:00:11 +0000</lastBuildDate>
	<language>en-CA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://viriback.com/wp-content/uploads/2019/01/cropped-android-chrome-512x512-32x32.png</url>
	<title>Citadel &#8211; ViriBack Blog</title>
	<link>https://viriback.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>30 days later &#8211; 97 Panels</title>
		<link>https://viriback.com/30-days-later-97-panels/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sun, 13 May 2018 19:55:19 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Citadel]]></category>
		<category><![CDATA[ISRStealer]]></category>
		<category><![CDATA[LiteHTTP]]></category>
		<category><![CDATA[Lokibot]]></category>
		<category><![CDATA[Pony]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=42</guid>

					<description><![CDATA[It's been one month since I noticed an increase in number of malware communication to a certain IP: 185.6.242[.]251 and the trend has not slowed down in the last 30 days. The total of web panel malware seen the last 30 days is totalling 97 as of this morning, as shown in this bar graph.  [...]]]></description>
										<content:encoded><![CDATA[<p>It&#8217;s been one month since I noticed an increase in number of malware communication to a certain IP: 185.6.242[.]251 and the trend has not slowed down in the last 30 days.</p>
<p>The total of web panel malware seen the last 30 days is totalling 97 as of this morning, as shown in this bar graph.</p>
<p><img fetchpriority="high" decoding="async" class=" wp-image-43 aligncenter" src="https://viriback.com/wp-content/uploads/2018/05/timegraph-300x155.png" alt="" width="451" height="233" srcset="https://viriback.com/wp-content/uploads/2018/05/timegraph-300x155.png 300w, https://viriback.com/wp-content/uploads/2018/05/timegraph-768x397.png 768w, https://viriback.com/wp-content/uploads/2018/05/timegraph-1024x530.png 1024w, https://viriback.com/wp-content/uploads/2018/05/timegraph.png 1373w" sizes="(max-width: 451px) 100vw, 451px" /></p>
<p>The distribution of malware C2 seen on this ip is uneven. Most are Lokibot and Pony instances, a few ISRStealer, LiteHTTP and Citadel have also been noticed.</p>
<p><img decoding="async" class="alignnone  wp-image-44 aligncenter" src="https://viriback.com/wp-content/uploads/2018/05/donut-300x292.png" alt="" width="510" height="496" srcset="https://viriback.com/wp-content/uploads/2018/05/donut-300x292.png 300w, https://viriback.com/wp-content/uploads/2018/05/donut.png 606w" sizes="(max-width: 510px) 100vw, 510px" /></p>
<p>A few stats:</p>
<ul>
<li>1 IP</li>
<li>5 malware families</li>
<li>30 Days</li>
<li>47 Domains</li>
<li>97 C2 Web panel instances</li>
<li>222 MD5 hashes</li>
</ul>
<table class="table table-bordered table-hover table-condensed">
<tbody>
<tr>
<td>malware</td>
<td>panel_url</td>
<td>date</td>
</tr>
<tr>
<td>Citadel</td>
<td>www.dtron.gdn/testimony/cp.php?m=login</td>
<td>20180420</td>
</tr>
<tr>
<td>Citadel</td>
<td>nsdic.pp.ru/pilot/cp.php?m=login</td>
<td>20180421</td>
</tr>
<tr>
<td>ISRStealer</td>
<td>sellychukwu.ru/PHP/</td>
<td>20180412</td>
</tr>
<tr>
<td>LiteHTTP</td>
<td>posalive.su/login/</td>
<td>20180413</td>
</tr>
<tr>
<td>Loki</td>
<td>bellegin.ru/don-cha11/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>bellegin.ru/doncha10/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>bellegin.ru/oshok/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>gokuu.club/ckan/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/buch-k/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/buch-m/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>papgon10.ru/davidm/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>papgon10.ru/don-12/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>papgon10.ru/kennyB-1/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>papgon10.ru/oshok-two/pen.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Loki</td>
<td>gokuu.club/M/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180414</td>
</tr>
<tr>
<td>Loki</td>
<td>braithwalte.co.uk/konvict/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180418</td>
</tr>
<tr>
<td>Loki</td>
<td>finelets.ru/fankzu/pen.php</td>
<td>20180418</td>
</tr>
<tr>
<td>Loki</td>
<td>finelets.ru/buch-x3/pen.php</td>
<td>20180420</td>
</tr>
<tr>
<td>Loki</td>
<td>finelets.ru/buch-x4/pen.php</td>
<td>20180420</td>
</tr>
<tr>
<td>Loki</td>
<td>topreadz.ru/willy-1/pen.php</td>
<td>20180420</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/buch-x2/pen.php</td>
<td>20180421</td>
</tr>
<tr>
<td>Loki</td>
<td>domainsender.info/moon/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180422</td>
</tr>
<tr>
<td>Loki</td>
<td>dunysaki.ru/buch-x5/pen.php</td>
<td>20180423</td>
</tr>
<tr>
<td>Loki</td>
<td>joanread.ru/work-1/pen.php</td>
<td>20180423</td>
</tr>
<tr>
<td>Loki</td>
<td>dunysaki.ru/stephen/pen.php</td>
<td>20180424</td>
</tr>
<tr>
<td>Loki</td>
<td>topreadz.ru/alexbe/pen.php</td>
<td>20180424</td>
</tr>
<tr>
<td>Loki</td>
<td>unifarmex.net/Dstan/Panel/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180424</td>
</tr>
<tr>
<td>Loki</td>
<td>braithwalte.co.uk/smith/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Loki</td>
<td>dunysaki.ru/doncha-2/pen.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/buch-l/pen.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Loki</td>
<td>vopspyder.website/log/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Loki</td>
<td>annamadums.ml/jazzy/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180426</td>
</tr>
<tr>
<td>Loki</td>
<td>domainsender.info/sun/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180426</td>
</tr>
<tr>
<td>Loki</td>
<td>papgon10.ru/don-one/pen.php</td>
<td>20180426</td>
</tr>
<tr>
<td>Loki</td>
<td>vopspyder.website/home/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180427</td>
</tr>
<tr>
<td>Loki</td>
<td>joanread.ru/decap/pen.php</td>
<td>20180429</td>
</tr>
<tr>
<td>Loki</td>
<td>vailablity.ml/vaila/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180430</td>
</tr>
<tr>
<td>Loki</td>
<td>braithwalte.co.uk/blam/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180502</td>
</tr>
<tr>
<td>Loki</td>
<td>unifarmex.net/hsp1/Panel/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180502</td>
</tr>
<tr>
<td>Loki</td>
<td>unifarmex.net/nesto/Panel/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180502</td>
</tr>
<tr>
<td>Loki</td>
<td>viettrust-vn.net/samii/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180502</td>
</tr>
<tr>
<td>Loki</td>
<td>braithwalte.co.uk/block/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180503</td>
</tr>
<tr>
<td>Loki</td>
<td>ultrainstinct.ru/file/exe/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180504</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/buchX-1/pen.php</td>
<td>20180505</td>
</tr>
<tr>
<td>Loki</td>
<td>topreadz.ru/doncha-3/pen.php</td>
<td>20180507</td>
</tr>
<tr>
<td>Loki</td>
<td>bollingoes.ml/ngoes/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>cadjetbums.ml/tbums/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>erintoba.info/bbbb/Panel/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>eriousimen.ml/eriou/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>lidgeys.ru/eddy/pen.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>thousandan.ml/andan/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180508</td>
</tr>
<tr>
<td>Loki</td>
<td>uy-akwaibom.ru/vinho/Panel/five/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Loki</td>
<td>wheelonexs.ml/wheel/PvqDq929BSx_A_D_M1n_a.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Pony</td>
<td>hypercosine.ml/cosi/hyper/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>preutainer.ml/aine/preut/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>rolexkings.ml/king/rolex/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/dort/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/sekiz/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/yedi/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>vinglosine.ml/osin/vingl/admin.php</td>
<td>20180412</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/bes/admin.php</td>
<td>20180413</td>
</tr>
<tr>
<td>Pony</td>
<td>erintoba.info/user/admin.php</td>
<td>20180414</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/alti/admin.php</td>
<td>20180414</td>
</tr>
<tr>
<td>Pony</td>
<td>cuogargaming.com/sop/admin.php</td>
<td>20180416</td>
</tr>
<tr>
<td>Pony</td>
<td>irishgrind.ml/irish/grind/admin.php</td>
<td>20180417</td>
</tr>
<tr>
<td>Pony</td>
<td>hostelunke.ml/lunke/hoste/admin.php</td>
<td>20180418</td>
</tr>
<tr>
<td>Pony</td>
<td>efficienci.ml/ienci/effic/admin.php</td>
<td>20180419</td>
</tr>
<tr>
<td>Pony</td>
<td>grandmoney.ml/money/grand/admin.php</td>
<td>20180419</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/on/admin.php</td>
<td>20180419</td>
</tr>
<tr>
<td>Pony</td>
<td>centranets.ml/anets/centr/admin.php</td>
<td>20180420</td>
</tr>
<tr>
<td>Pony</td>
<td>dazzlelogs.ml/elogs/dazzl/admin.php</td>
<td>20180422</td>
</tr>
<tr>
<td>Pony</td>
<td>gokubid.review/chife/panelnew/admin.php</td>
<td>20180423</td>
</tr>
<tr>
<td>Pony</td>
<td>gokubid.review/indo/panelnew/admin.php</td>
<td>20180423</td>
</tr>
<tr>
<td>Pony</td>
<td>carikapapa.ml/apapa/carik/admin.php</td>
<td>20180424</td>
</tr>
<tr>
<td>Pony</td>
<td>cuogargaming.com/klinsnip/admin.php</td>
<td>20180424</td>
</tr>
<tr>
<td>Pony</td>
<td>braithwalte.co.uk/bass/admin.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Pony</td>
<td>pharma&#8211;partners.com/bfayz/admin.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/dokuz/admin.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Pony</td>
<td>uy-akwaibom.ru/wise/Panel/admin.php</td>
<td>20180425</td>
</tr>
<tr>
<td>Pony</td>
<td>pharma&#8211;partners.com/nonib/admin.php</td>
<td>20180426</td>
</tr>
<tr>
<td>Pony</td>
<td>taineruder.ml/ruder/carik/admin.php</td>
<td>20180427</td>
</tr>
<tr>
<td>Pony</td>
<td>totalguage.ml/guage/total/admin.php</td>
<td>20180427</td>
</tr>
<tr>
<td>Pony</td>
<td>pharma&#8211;partners.com/twst/admin.php</td>
<td>20180428</td>
</tr>
<tr>
<td>Pony</td>
<td>viettrust-vn.net/juzz/admin.php</td>
<td>20180502</td>
</tr>
<tr>
<td>Pony</td>
<td>braithwalte.co.uk/ajjuu/admin.php</td>
<td>20180503</td>
</tr>
<tr>
<td>Pony</td>
<td>carikapapa.ml/carik/admin.php</td>
<td>20180503</td>
</tr>
<tr>
<td>Pony</td>
<td>irishgrind.ml/grind/admin.php</td>
<td>20180503</td>
</tr>
<tr>
<td>Pony</td>
<td>stauniverseqp.com/roks2/admin.php</td>
<td>20180503</td>
</tr>
<tr>
<td>Pony</td>
<td>bundletops.ml/bundl/etops/admin.php</td>
<td>20180504</td>
</tr>
<tr>
<td>Pony</td>
<td>stauniverseqp.com/office1/admin.php</td>
<td>20180504</td>
</tr>
<tr>
<td>Pony</td>
<td>viettrust-vn.net/adin/admin.php</td>
<td>20180507</td>
</tr>
<tr>
<td>Pony</td>
<td>hostelunke.ml/lunke/admin.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Pony</td>
<td>suruperet.ml/eret/surup/admin.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Pony</td>
<td>taineruder.ml/ruder/admin.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Pony</td>
<td>theonlygoodman.com/aman/admin.php</td>
<td>20180510</td>
</tr>
<tr>
<td>Pony</td>
<td>dunysaki.ru/buch-A3/admin.php</td>
<td>20180512</td>
</tr>
<tr>
<td>Pony</td>
<td>thousandan.ml/lumin/sop/admin.php</td>
<td>20180513</td>
</tr>
</tbody>
</table>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
