A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20364  by unixfreaxjp
 Sat Aug 03, 2013 4:27 pm
Thank's to *stupid* REGGI.RU to let Kelihos marked-dead 100 domains came up to enter internet.. now 85/100 are ups.
RedKit guys is up into something. Check your perimeter friends. PoC: http://pastebin.com/aLDGJNxJ < marked these IPs,
it rolls & is not a bphosts/etc proxy, pure stolen ftp accounts!

To RedKit Moronz, you haven't learned your lesson, we won't play easy on you now.
We'll come straight into your panels, your hashes database , your stats, your shell,
before you're going to weep and down. Expect this, moronz!

Malware MUST f*ckin DIe!!!

Image
 #21829  by unixfreaxjp
 Wed Jan 01, 2014 5:03 am
@Xylit0l this threat's closed.
Redkit was bought by Kelihos botherder, he is busy with the iframe toys (CookieBomb) & affiliating malware distribution now.
Maps are changing CookieBomb is affiliating to etc EK too, and to my disappointment is not RK.
So we can close this OP. OP Kelihos is on same stuff.