mercredi 16 août 2017

Quick look at another Alina fork: XBOT-POS

Edit: In fact after looking at the sample it's a pure copy pasta of Tiny Nuke :) - cd025523e3aec57f809552b9d1adc4b89526cc632f6d4c481aa2c8c3501dda6b

Hi, it's time for a new post. Today I'll try to have a look at the "Team NZMR"
I've found this funny team by hazard on Twitter via the bot @ScumBots I would like to write this little blog post because I think that this is interesting to see an Alina panel behind a .onion domain and as you can see later, I like look at some weird panels :D.
Let's have a look on this server.
As we know, we have an Alina (Well known POS malware) panel at
Samples: 26aa9709d0402157d9d36e4849b1f9bacecd8875169c7f26d7d40c5c0c3de298 (

In the same boring way, we can found:
  • a Fareit/Pony panel at (I don't have sample)
  • an Atmos at :
    Sample e34720cc8ab3718413064f19af5cc704e95661e743293a19f218d3b675147525 (

    Thanks to CCAM we can get 2 new servers used by this team:
Those guys really want your creds and your credit card numbers :D

They also try to deal with ransomware (NZMR Ransomware) at without success...

But I've write this quick blog post for the last panel,
Let me introduce you XBOT panel \o/:
(click to enlarge)

The bot ad:
Selling xbot ,new bank trojan -- Modules -- Webinject -- Formgrabber -- Socket4/5 -- Hidden VNC
New bot bank xbot is available for rent (800$/monthly) -- server on tornetwork/clearnet
Customized programming service and web developer/c/c++/Python/NET/others
Team Coder/NZMR
xbot costs 3k $ modules available >webinject -- formgrabber -- Socket4/5 -- Hidden VNC
When buying xbot what do you get?
You will get the builder,bin/exe+socket.exe/server.exe hvnc
[+] - Free installation on your server in tornetwork or clearnet, you choose
[+] - monthly support paid 100 $ (you choose,with or without support)
[+] - Update bot for new version 400 $
[+] Rent xbot
Panel access (Clearnet/Tornetwork)
Bin (exe)
800 $ monthly (First 6 customers, others 1k $)
Support monthly 100 $ (btc)
I don't have any sample yet but if you have one, i'm REALLY interrested :D.
Thanks to Xylitol this panel looks like a mix between Alina and Dexter. For example the URI scheme "/front/stats.php", the successstatuscode 666 or this page "Version Control":

This panel looks designed for Banking stuff (webinjects) and POS malware.
From XBOT panel you can DL/Exec, Start VNC sessions, socks sessions and update bots:

We can also found some strange "webinjects" stuff:

where "view content" leads to these kinds of data:

Some settings (look at the Alinas 666 status code):

You can also add some bins in the panel database. Currently, they have 8472 Bins in the database.
And finally the bot lists (~600 bots if I trust the bots list).

I've uploaded the whole list of bots on this album. Ping me if you're on the list :D I'm really curious to see the binary part
And finally the database structure reminds again Alina: By this way we will find soon more Alina forks than Zeus forks \o/

So, NOPE! it's not a super new next gen POS malware, it's just another Alina Fork :D but this webinjects part looks curious :) and the team seems very active.
But come one, 3k$ for open sourced malware haha...

Thanks for your time, thanks to Xylitol and happy hunting :)

IOCs: (Alina) (Neutrino) (Atmos) (Alina) (Neutrino (Atmos) (Gorynch) e34720cc8ab3718413064f19af5cc704e95661e743293a19f218d3b675147525 (atmos) 26aa9709d0402157d9d36e4849b1f9bacecd8875169c7f26d7d40c5c0c3de298 (Alina) 8a62f61c4d11d83550ab4baceb9b18d980a4c590723f549f97661a32c1731aff (neutrino)

56 commentaires:

  1. Ce commentaire a été supprimé par un administrateur du blog.

  2. Ce commentaire a été supprimé par l'auteur.

  3. Programming help provided by takes care of these fundamentals and most of our tutors are efficient with every programming assignment.

  4. So far, I found this website very professional for assignment writing. I took Assignment Help from them for my Science homework. I am really happy with the experience and I will recommend this website to you guys if you need quality writing services for your project.
    I had to complete my English assignment and I was worried because my assignment was not ready. I took the help from google but still fail to write. Then, I took Assignment Help Online from greatassignmenthelp and I was amazed by the work I received. Their expert provided me the instant support and helped me in my assignment. Thank you guys for your assignment help and support.

  5. Nice Post!!....
    Do you ever think about the dreadful situation of HP Printer? It may be occurred in your genuine computer peripheral without giving any intimation message to you. Appearance of minute quotient of failure in HP printer does not let you to achieve the prospective result. A number of professionals think about to fetch the most perfect scanning outcome even though they have stand on verge of million HP printer disorder. How to get recovery from the negative functionality of HP printer is a trick question. Instead of applying different method and technology, it is nice to ask the full help and guidance through HP Printer Support executive. There is no further need to stay connected with this problem as the troops of our third party professional teams help you to recover from this issue. Our team is offering the soon solution of problem as you send the quote on its toll free number. In order to know more information, you can browse our web portal.
    View More Information:-
    HP Printers Support !! HP Printer Support Phone Number !! HP Support !! HP Printer Support Number
    !! HP Phone Number !! HP Support Number

  6. Great post! I appreciate you for the effort you take to share your knowledge with people. Thanks for you time and knowledge. Great!!! Get support click here Office 365 Help
    Office 365 Support
    Microsoft 365 Support
    Microsoft Office 365 Support
    Outlook Support
    Microsoft Outlook Support
    Outlook Support Number
    Outlook Support Phone Number

  7. Very nice!!! This is really good blog information thanks for sharing. We are a reliable third party QuickBooks support phone number company, offering technical support for various types of technical errors.

    Quickbooks online backup

    QuickBooks online customer service


  8. I, Josh George is anxious about to get some desirable change to enjoy the proficient features and functions in the aspect of data protection software assets. That’s why I turn my passion into profession and offering the valuable support for removing the technical issue in the different suites and packages of avast antivirus. I hold the great experience in this business field. In case you are facing various antivirus turbulence, then you knock the door of Avast Customer Support Phone Number center. For saturating the whole demand of customers, we are offering the instant support all the time. No specific time has been defined for this.

  9. having a great reputation among students, we deliver knowledge with full information.

  10. From last couple of months, I am working with Apple Support team and eliminating customer’s problems at ease. If you want to know about my service, then you see the happy faces of customers who take services at their door steps. At this support, not only me but my whole team is available all the time and working efficiently to provide best-in-class service. Thus, if you need guidance in getting rid of your Apple device’s issues, then you can call at Apple Support number which is also reachable throughout the day and night.

  11. In this modern world, HP printers have quickly become a must-have office or home device to print optimum quality images. Also, the installation of these printers has been considerably streamlined over the years. While we can install the majority of the printers automatically, but adding the HP printer with a network or sharing your printer with other users can still be a difficult part. But, once you become familiar with the complete steps to install printer software then you can use your printer very with no trouble. To know more about this, you can dialHP Tech Support Phone Number to know the appropriate steps to install printer driver and software.

  12. Nice blog for getting office 365 support. I got the solution for my issue related to office 365 here. This blog is very important for Microsoft 365 support. Thanks for sharing this blog!
    Visit here:-
    office 365 Support
    office 365 help
    Microsoft office 365 support
    Microsoft 365 support

  13. Hii i am donaldgeorge and i am a senior technician in Quickbooks .If you face any technical issues in quickbooks then must dial Quickbooks Support Phone Number
    to get an instant solutions.

  14. Overall, I really enjoyed the aid provided from Microsoft Outlook Support. I personally thought their guidance and instructions are trouble-free for me to follow. Thus, I will recommend this support to everyone if they face any kind of issue related to outlook. Get support click here Outlook Support
    Outlook Support Number
    Outlook Tech Support
    Outlook Technical Support
    Outlook Support Phone Number
    Outlook Customer Support Phone Number
    Outlook Customer Service Phone Number
    Office 365 Help
    Office 365 Support
    Microsoft 365 Support
    Microsoft Office 365 Support

  15. Thank you so much for sharing such an amazing blog with us. Visit lifestyle magazine for creative events.
    Lifestyle Magazine

  16. Always we are working to offer best and updated assignment service always. Don't search more for the research paper topic you can get it's best service at World's best experts are giving amazing service and can complete all your demands. Our experts are online to offer you amazing services and they are offering 24x7 online facility.

  17. Excellent post.I like your concept very much. Especially the way you explain it, it’s impressive.Though I am very new to your post but really want to know more in future.Great work Keep it up...Get outlook support in USA.

  18. Thanks for sharing this unique article. The creative juices are flowing so fast I can’t even hold them back! I just want to share this with the world! office 365 support is a customer care helpline that is offered by one of the world's best Technical service provider. For more info Contact Microsoft supports.

  19. Oh cool. Looking forward to having a play with your updates. Keep us posted. As a side note, can you develop it to “Microsoft 365 Support”? That will be great.
    If you wanna read more for Microsoft office 365 Support then visit the office 365 Support website.

  20. Our website is affiliated with the site of various nations. We give our administration everywhere around the world. Our assignment assistance is given to students all through.
    Assignment Help Online
    Assignment Expert Canada

  21. Just dial 1-877-916-7666, the tech support number of Assistance for All. We are the most popular tech support agency operating around the country. Get More Information Visit My Website:-

  22. With time and technology, the importance of computer has augmented immeasurably. Microsoft offers several windows versions as per the people need and also keeps updating them for excellent functionality.
    office 365 customer service phone number
    outlook tech support phone number
    Microsoft Support Phone Number
    Office 365 tech support phone number
    Office 365 technical support phone number

  23. Thank you so much for sharing this post, I appreciate your work.It was a great informative post.Go so many useful and informative links. Loved your writings also. Concept of the topic was well discussed. Love to come here again. We also provide affordable Law Assignment help in uk.

  24. Love your blogger theme and graphics. You've done a good job with this blog. login

  25. Really Appreciate, This impressive post certainly encourages to choose Assignment Help Services. Get Assignment help services by the best

    qualified and experienced assignment experts of Complete My Assignment.
    Mathematics Assignment Help

  26. Find the best assignment help in Australia at reasonable prices. We provide quality assignments by our top writers for your help.
    Assignment Help

  27. Download latest audio and video file fromvidmate

  28. I loved the article, keep updating interesting articles. I will be a regular reader…know about anveshi jain

  29. Assignment help also provides the assignment writing for the students of college assignments, dissertation help, essay writing and thesis writing services as per the university guidelines.
    Assignment Help UK
    law dissertation help

  30. Intelepos offering business solution.
    EPOS system for your shop
    EPOS system for your Restaurants
    EPOS system for your Bakery
    EPOS system for your Takeaway
    EPOS system for your retail store
    Contact No: 0330 1134 157

  31. Superb! I love the way of your writing and what a subject you choose, It’s amazing. Please keep posting because we always wait for your next post. You should also visit our Microsoft support web page and guide us, we are good to provide information or not.
    Our other web pages
    Outlook phone number
    Outlook customer service

  32. give Thesis Writing Help for students.they give 100% plagiarism free and quality content.

  33. Assignment Help likewise gives the assignment keeping in touch with the understudies of school assignments, paper help, article composing, and postulation composing administrations according to the college rules.
    Assignment Help UK
    law assignment help
    my assignment help

  34. I have just one word – Superb blog! Love the way you think, strategize and execute. Look forward to your next post. Excited to check out the free and updated future blogs. Microsoft 365 Support
    If you wanna read more for Office 365 Support then visit the Microsoft office 365 Support website.

  35. You can take Epson Support and get the appropriate guidance from the experts who are available all day long just to help you out. For joining hands with them, you just need to make a phone call at help line number. It would be great that you should have to approach on our third party professional team to obtain the suitable solution. Dial our to remove this failure. To know more information, you can surf our web portal. However, the failure existence does not let to move in forward.

  36. Such a great article!! Looking for an assignment help? we provide you the best assignment help at very low prices.All the assignment experts provide their services at affordable prices so that most of the students can seek help from them. Their assignment help is free of plagiarism and all the citation rules are followed thoroughly.

  37. Having troubles with your math’s assignment?? Well look no further we all got you here. We all got you. And your assignment will be done in just a minute.
    pay someone to do my online math class

  38. Are you giving nmrc exam this year? If yes then we will suggest you to download your nmrc admit card today.
    Keeping your admit card with you is a very necessary step as without it you won't be able to appear for the exam.

  39. The technology of producing similar copies of the new text to facilitate a wide readership is referred to as printing. Earlier it was done manually, today with innovative technology it can be done in a few seconds. If your HP Printer not printing then visit our website and know how you can fix the issue.

  40. It is nice to read such high-quality content. We are offering best Assignment Help in Australia for students studying Australia. We guarantee good grades and promise to complete the task on the promised time. If you need to contact our team and also visit our website and get your Assignment help.

  41. I found this is an interesting website and this is very useful and knowledgeable.

    marketing dissertation writing -
    dissertation statistics help

  42. Get the best Assignment help online in Singapore by PhD experts at affordable prices. Our assignment services are 100% risk free and are assured by 100%.
    java assignment help

  43. Looking to install generic ink cartridges in your HP Printer? Read the Article and find simple steps or instructions, then your printer will be able to recognize the cartridges. If you are still finding any issues then visit HP Number.

  44. Thanks for this informative blog, visit Kalakutir Pvt Ltd for School Bus Painting and Warehouse Zebra Painting.
    School Bus Painting

  45. There are all sorts of programming languages in existence, and new ones keep getting released. So, why learn Python? Python counts among the most popular programming languages.Look up on Python Homework Help

  46. Thank you for sharing this informative is giving assignment help to students.we are already trusted by thousands of students who struggle to write their academic papers and also by those students who simply want assignment writer
    to save their time and make life easy.

  47. Thank you for sharing such an informative information. I like it and recommend to others. In case you are searching for charbroiler equipment’s search no more for commercial charbroiler delivers quality and easy to use equipment’s at a pocket friendly cost.

  48. We can solve all the problems related to Yahoo just by dialling the number of experts. The service is available 24x7. You can also use Yahoo live chat to continuously chat with our yahoo experts and resolve the issues without any chaos.
    Yahoo Live Chat

  49. Thanks for the points shared using your blog. Something else I would like to talk about is that cox email sign in support phone number information. .Here you will learn what is important, it gives you a link to an interesting fact about cox email sign in support. you'll find exciting and interesting things on cox email support. Have a look here:

  50. thanks for the sharing the article. i have also written few blogs related to topic. please do have a look and can encourage me
    cox email setting support phone number

  51. Thanks for the points shared using your blog. Something else I would like to talk about is that cox email sign in support phone number information. .Here you will learn what is important, it gives you a link to an interesting fact about cox email sign in support. you'll find exciting and interesting things on cox email support. Have a look here: AOL Mail Problem Help Phone Number

  52. Students who have an assignment of essay writing can take essay writing help from because we have expert essay writers USA that provides you with high-quality essay writing help services.