A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12225  by Neurofunk
 Mon Mar 19, 2012 9:05 pm
Must be relatively fresh low detection on this, only reason I found this on a users machine was because of this:
C:\Documents and Settings\<removed>\Local Settings\Temporary Internet Files\Content.IE5\U6VNK9EL\Ticket_American_Airlines_pdf[1]\Ticket_American_Airlines_pdf.exe

Executable and Conf found in C:\Windows7 hidden from view I have attached them below, the downloader in the fake American Airlines ticket was this: TrojanDownloader:Win32/Dofoil.O

File name: 4D525EC11CC.exe
https://www.virustotal.com/file/4652cc4 ... 332190253/
MD5: f1dbc166edca50739836562ab54a1aeb
0/43
Attachments
Password: infected
(569.96 KiB) Downloaded 72 times
 #12237  by EP_X0FF
 Tue Mar 20, 2012 10:38 am
rough_spear wrote:Hi EP_X0FF,
What is the password for decrypted13x_78B99546421ABAB330B17D278262EABB.zip file.
78B99546421ABAB330B17D278262EABB
  • 1
  • 35
  • 36
  • 37
  • 38
  • 39
  • 42