A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20127  by dumb110
 Tue Jul 16, 2013 1:06 pm
Code: Select all
fbi.gov.id657546456-39994?56674.k8381.com/
fbi.gov.id657546456-39994?56674.k8381.com/?flow_id=2019&&453?640=45513/case_id=39994
europol.europe.eu.id65754?6456-3999456674.k8381.com/
europol.europe.eu.id65754?6456-3999456674.k8381.com/?flow_i?d=2019&&453640=45513/case_id=39994
Attachments
(153 Bytes) Downloaded 65 times
 #20129  by Xylitol
 Tue Jul 16, 2013 5:23 pm
Code: Select all
hxxp://fbi.gov.id657546456-3999456674.k8381.com/?result=success
hxxp://fbi.gov.id657546456-3999456674.k8381.com/checkout.php
hxxp://fbi.gov.id657546456-3999456674.k8381.com/admin.php
hxxp://fbi.gov.id657546456-3999456674.k8381.com/ok.php
hxxp://fbi.gov.id657546456-3999456674.k8381.com/gb/
hxxp://fbi.gov.id657546456-3999456674.k8381.com/us/
hxxp://fbi.gov.id657546456-3999456674.k8381.com/fr/
hxxp://fbi.gov.id657546456-3999456674.k8381.com/dating/
hxxp://fbi.gov.id657546456-3999456674.k8381.com/phpmyadmin/
leet verification:
Code: Select all
if(input[0].value != '' && input[0].value.length != 14 ){
alert('YOUR PAYMENT INFORMATION IS NOT CORRECT.\n\nALL PC DATA WILL BE DETAINED AND CRIMINAL PROCEDURES WILL BE INITIATED AGAINST YOU IF THE FINE WILL NOT BE PAID.');
what i've saw before the shutdown.
oh, also: http://blog.malwarebytes.org/intelligen ... s-x-users/