Reverse Engineering [Tool] AllCome Clipbanker configuration extractor

struppigel

Super Moderator
Thread author
Verified
Staff Member
Well-known
Forum Veteran
Apr 9, 2020
666
5,865
1,280
Germany
I made configuration extractor for AllCome Clipbanker. The config saves all the cryptocurrency addresses, Paypal emails, Steam trade offer links, C2 server addresses that the clipbanker uses to replace in the clipboard.

Download the tool here:

allcome.png


You can download samples for testing here (I guess I should upload some more): MalwareBazaar | Browse malware samples

List of several extracted configs is here: Extracted Allcome Clipper Configs - Pastebin.com