weird zeus
Code: Select all
https://bilance.humanwebcentr.net:63992/prefer/moualu.exe
https://bilance.humanwebcentr.net:63992/prefer/stars/rihannew.jpg
https://bilance.humanwebcentr.net:63992/prefer/counters.php
http://localhost/captchaupload.php
http://localhost/notifygate.php
Code: Select all
https://microsads.net/sampler/admin/gate.php?mode=CHECK_LOGIN&type=COMMERZBANKING&bot_id=XYLITOL-F12F085_7875768FBC303C10

Found here http://www.malekal.com/2014/01/15/direc ... d-to-zbot/
base64+RC4+VisualDecrypt
RC4:
Code: Select all
30 65 73 8D 11 5D CB 1A E3 7C 7E 6B 0F 6D D6 3C 39 94 32 B4 61 52 93 DD C5 2F D8 1F 74 54 6A B9 C8 22 C4 07 EA 5A 1D 7A DA 34 25 DB 0C EC A4 5C BE AF 5E D2 3A BF 7F 00 2A EE 3F 3E 72 92 48 35 03 E9 63 D7 53 33 67 0E 1B AB 38 50 40 28 CD 23 A1 2C 47 AE C3 29 91 2B B6 62 19 0A 1E 36 57 FE DF 82 42 4D F8 89 98 4C DE EF 24 95 4A AA CA 06 56 58 46 A0 87 D4 16 A6 2E 14 E0 9C 85 8B 84 BD E7 31 F7 F2 9B 2D 96 B7 AD 01 8F A9 8A 20 FA 79 04 A8 6F 51 26 BB 8E 9D DC 43 A2 09 1C 9E F1 0B FC 68 E6 02 E1 CC F5 99 B0 81 90 D0 44 80 FF D3 77 66 C7 BA ED E2 6C C1 E5 69 71 55 4E 10 4B 27 60 CF 88 FB B2 83 75 F0 A5 5F 41 21 E4 B8 05 C6 F9 EB F6 B1 A3 9F 37 B5 49 CE FD E8 4F F4 C9 C0 BC 7B 6E D1 D5 3B 45 A7 F3 13 3D B3 AC 76 D9 78 18 86 0D 12 59 64 8C C2 17 9A 97 15 7D 70 08 5B
fine.landingplans.net/browser/images/logo.png

fine.landingplans.net/browser/theme/style.css:
Code: Select all
html, body
{
background: url("../theme/fonbutton/background.png");
margin: 0 auto;
color: #000000;
font-family: Verdana, Helvetica, sans-serif;
font-size: 10px
}
input, select, textarea
{
background: #F5F5F5;
font-family: Verdana, Helvetica, sans-serif;
font-size: 10px;
font-weight: normal;
margin: 0
}
pre
{
font-size: 10pt
}
td
{
margin: 0;
padding: 1px
}
a:link, a:visited
{
color: #000000;
text-decoration: none;
font-weight: normal
}
a:hover, a:active
{
color: #000000;
text-decoration: underline;
font-weight: normal
}
.div_top
{
width: 100%;
height: 95px;
background: url(../images/logo.png);
font-size: 15px;
color: black;
font-weight: bold;
padding: 2px 0;
margin: 0
}
.context
{
background: #F5F5F5;
background: -webkit-gradient(linear, left top, left bottom, from(#48D1CC), to(#B0E0E6));
background: -moz-linear-gradient(top, #48D1CC, #B0E0E6);
width: 100%;
padding: 10px;
text-shadow: 0 1px 1px rgba(0,0,0,.3);
-webkit-border-radius: .5em;
-moz-border-radius: .5em;
border-radius: .5em;
-webkit-box-shadow: 0 10px 2px rgba(0,0,0,.2);
-moz-box-shadow: 0 10px 2px rgba(0,0,0,.2);
box-shadow: 0 10px 2px rgba(0,0,0,.2);
color: #000000;
border: solid 1px #000000;
}
.menu
{
padding: 5px 0;
border-right: 1px solid #999999;
border-bottom: 1px solid #999999;
text-shadow: 0 1px 1px rgba(0,0,0,.3);
-webkit-border-radius: .5em;
-moz-border-radius: .5em;
border-radius: .5em;
-webkit-box-shadow: 0 10px 2px rgba(0,0,0,.2);
-moz-box-shadow: 0 10px 2px rgba(0,0,0,.2);
box-shadow: 0 10px 2px rgba(0,0,0,.2);
color: #d9eef7;
border: solid 1px #000000;
background: #0095cd;
background: -webkit-gradient(linear, left top, left bottom, from(#48D1CC), to(#B0E0E6));
background: -moz-linear-gradient(top, #48D1CC, #B0E0E6);
filter: progid:DXImageTransform.Microsoft.gradient(startColorstr='#00adee', endColorstr='#0078a5');
}
.menu_header
{
margin: 0 0 10px 10px;
font-size: 10px;
font-weight: bold
}
.menu a:link, .menu a:visited
{
border: 1px #000000;
display: block;
color: #000000;
padding: 2px 2px 2px 15px;
margin: 0 2px 0px 2px;
font-weight: normal;
width: 150px;
text-decoration: none
}
.menu a:hover, .menu a:active
{
border: 1px solid #000000;
background-color: #FFFFFF;
text-decoration: none;
color: #000000
}
.bot_a:link, .bot_a:visited
{
color: #FF4500;
font-weight: bold;
text-decoration: none
}
.bot_a:hover, .bot_a:active
{
color: #FFFFFF;
font-weight: bold;
text-decoration: underline
}
.menu_separator
{
border-top: 1px solid #000000;
margin: 2px 0
}
.menu_info
{
color: #000000;
padding: 2px 2px 2px 15px;
margin: 0 2px;
font-weight: normal;
width: 150px
}
.table_frame
{
border: solid 1px #000000;
background: #FFFFFF;
margin: 0 auto;
padding: 1px
}
.table_frame td
{
white-space:nowrap
}
.td_header
{
background: #48D1CC;
color: #000000;
font-weight: bold;
padding: 1px;
margin: 0
}
.td_header a:link, .td_header a:visited
{
color: #000000;
text-decoration: none;
font-weight: bold
}
.td_header a:hover, .td_header a:active
{
color: #FFFFFF;
text-decoration: underline;
font-weight: bold
}
.td_c1
{
background: #AFEEEE;
padding: 1px;
margin: 0
}
.td_c2
{
background: #B0E0E6;
padding: 1px;
margin: 0
}
.error
{
color: #FF0000;
font-weight: bold
}
.success
{
color: #228B22;
font-weight: bold
}
.screenshot
{
border: solid 1px #FF0000
}
.popupmenu table
{
color: #3A5FCD;
border: solid 1px #000000;
background-color: #FFFFFF;
}
.popupmenu td
{
padding: 0
}
.popupmenu a:link, .popupmenu a:visited
{
border: 1px solid #FFFFFF;
display: block;
color: #404040;
padding: 2px 15px;
margin: 0;
font-weight: normal;
text-decoration: none;
background-color: #FFFFFF
}
.popupmenu a:hover, .popupmenu a:active
{
border: 1px solid #999999;
background-color: #AFEEEE;
text-decoration: none;
color:#000000
}
.popupmenu hr
{
border: 1px solid #000000;
background-color: #AFEEEE;
margin: 0;
padding: 0
}
.table_frame_backgrounds
{
border: solid 3px #ffffff;
background: #F5F5F5;
-moz-border-radius: 5px;
border-radius: 5px;
}
.sexy_list_infol1{
background: rgb(143, 126, 126);
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
font-size: 10px;
}
.sexy_list_infol2{
background: rgb(56, 50, 50);
padding: 1px;
margin: 0;
font-size: 10px;
border: solid 1px #cccccc;
}
.sexy_list_infor1{
background: rgb(143, 126, 126);
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
font-size: 10px;
}
.sexy_list_infor2{
background: rgb(56, 50, 50);
padding: 1px;
margin: 0;
font-size: 10px;
border: solid 1px #cccccc;
}
.sexy_list_infol3{
background: #efefef;
padding: 1px;
margin: 0;
border: solid 1px #cccccc;
}
//////
.sexy_list_infl1{
background: #000000;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infl2{
background: #efefef;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infr1{
background: #FFFFFF;
padding: 1px;
margin: 0;
font-size: 10px;
}
.sexy_list_infr2{
background: #efefef;
padding: 1px;
margin: 0;
font-size: 10px;
}
///////////////

--
others cnc:, panel of 'second' zeusVM generation:
Code: Select all
https://fine.landingplans.net/solution/theme/throbber.gif
https://fine.landingplans.net/enter/theme/throbber.gif
https://fine.landingplans.net/shop/theme/throbber.gif
https://fine.landingplans.net/central/theme/throbber.gif