From VT: A new seed of Dircrypt?
suqitian opened this issue · comments
suqitian commented
- MD5
8dce388365ba4ddd516a744c677d41e9 - Domains
aecsztodxcauezvwv.com
agqkgrttm.com
dkpcztxjhlmgppzrd.com
erajimtnghuqfdgnhj.com
ftxtknedryvgywsmchm.com
gcaocxscewiemvhggl.com
gxcmyvpmuuxoluzdenhr.com
hbyxpqjkm.com
hrbkzpoytss.com
injhsmedkkvjktwgmz.com
iufmmhtfuglkewvyrira.com
jzyskusvwwpnykoi.com
khtpzsuzpbaforbsqoqt.com
lvbikxjfrzrofxzn.com
ngntxyqih.com
ntaeqknhxehkadis.com
pbxfdvizihgcv.com
qmeuxytpxbf.com
xbrsttwgaomaxapjpa.com
zwmobkxpbcwddexzh.com - Details in VT
File has been identified by at least ten Antiviruses on VirusTotal as malicious, and one of the keywords is "Dircrypt".
Johannes Bader commented
This is indeed DirCrypt with Seed 0xF6A84A56 and 50 generated domains . Here is the full list
roxgaffvgdoussasodp.com
fmmpcvptedjj.com
kcioltyxt.com
uoneiidbgd.com
cgisutadrreeofer.com
cdvdzllc.com
qmiovfqxfottkhvxnbh.com
cosehduitwhveyawpvb.com
rstjohxvafpdil.com
ktnpeigebccttk.com
owhcvpphjlhmmhsu.com
hsysmmsyrqigvk.com
xiwizgqqxsxiufcqog.com
bbtflrghufwutxujka.com
srivztiulphfxd.com
poinakvh.com
yjghnpukyqy.com
zjnzfctktonlspuanzlr.com
qszjxjem.com
iedzvuyxzihzdwccayx.com
gznvxlfppo.com
adhwcthf.com
halmafqsuibsddqls.com
ppwktofoh.com
evbjhfhddsqejovzfjx.com
eugrbfjvkzx.com
pmuyficrjmtartnzeouj.com
vfcnugadnuhaoebzwaq.com
khcagvgdllhfjqn.com
siamgggtevghgi.com
erajimtnghuqfdgnhj.com
iufmmhtfuglkewvyrira.com
injhsmedkkvjktwgmz.com
ntaeqknhxehkadis.com
ngntxyqih.com
jzyskusvwwpnykoi.com
khtpzsuzpbaforbsqoqt.com
dkpcztxjhlmgppzrd.com
xbrsttwgaomaxapjpa.com
lvbikxjfrzrofxzn.com
hbyxpqjkm.com
ftxtknedryvgywsmchm.com
pbxfdvizihgcv.com
hrbkzpoytss.com
gcaocxscewiemvhggl.com
aecsztodxcauezvwv.com
agqkgrttm.com
qmeuxytpxbf.com
gxcmyvpmuuxoluzdenhr.com
zwmobkxpbcwddexzh.com