In lieu of a proper write up, the following hashes should help replicate the work by any interested researchers. All samples discussed are available on VirusTotal :)
0xFancyFilter or Regin 1.5 (‘htmlfiltxx64.dll’ or ‘Microsoft\Internet Explorer\iesrch32.dat’)
Older 0xFF samples (‘httpfilt.dll’, ‘htmlfilt.dll’)
369145c6f366f25a4e8878ad1ffec73d680cdc2da4380b221d1d7cdf3a90c930
ef35705696d78cc9f4de6adad2cbe5ed22fd50da0ce4180c1d47cf0536aebc87
df4bc387181ffaabe0be39e66ef5eb838ed638e0ae2b82e9a7daa83647e38bb1
Old EQGRP ‘nethdlr’ (MISTYVEAL) for comparison
Regin’s Hopscotch with shared RC4 implementation
YARA