A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #31214  by Fedor22
 Sat Jan 20, 2018 4:04 pm
08-07-Homer (I think it's banker or spyware, but I do not know exactly what it is).
Installed: HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run <- <appdata>\\Local\\<08-07-homer.exe>
Sample taken from this website:
xxxx://eiainteriors.com/wp-content/plugins/jetpack/08-07-homer.exe
VT: https://www.virustotal.com/en/file/e36a ... /analysis/
HA: https://www.hybrid-analysis.com/sample/ ... mentId=100
Attachments
(2.88 MiB) Downloaded 28 times