Author Topic: zeus/prg/zbot/ntos/wnspoem config file decryptor  (Read 13204 times)

0 Members and 1 Guest are viewing this topic.

January 01, 2009, 12:25:07 pm
Read 13204 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

January 18, 2009, 05:54:49 pm
Reply #1

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
This decryptor tool doesn't work for the latest version of zeus.
The config file of new zeus versions is encrypted by a key which
is compiled into the binary.

That means you need an unpacked copy of the corresponding
binary in order to decrypt the config.

example :
Code: [Select]
hxxp://58.65.236.41/cfg.bin
hxxp://58.65.236.41/z.exe

/EDIT

See also the translation of a Spanish article
http://translate.google.com/translate?prev=hp&hl=en&u=http%3A%2F%2Fblog.s21sec.com%2F2009%2F01%2Fnuevas-muestras-de-zeus.html&sl=auto&tl=en
Ruining the bad guy's day

January 03, 2010, 06:35:24 pm
Reply #2

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

May 03, 2010, 07:30:00 am
Reply #3

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day