Attachments
(127.35 KiB) Downloaded 61 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:https://www.virustotal.com/file-scan/re ... 1317397490This is ngrBot aka Win32/Dorkbot.A
rough_spear wrote:Hi All, :DAttempt to read hxxp://www.hastyrefills.com/url.txt which is C&C data. Not available, only in search cache.
W32.Jorik/ngrbot sample. 8-)
YwKCxcStcfSFAHXHVqVQdownloads hxxp://cudear.com/view.php?=Facebook-pic####-JPEG which is trojan downloader which downloads ngrBot from hxxp://solarpanelscleveland.com/bbb.exe
12| Combien de bonnes photos!!#! :O hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
20|hoh. interessante bilder?!!:) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
6|om det var dig??#= hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
29| Vad ar det foto?#??# ? :) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
19| of je het leuk??!= :D hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
21|Smieszne zdjecia?#?!:P hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
16|hhhh,Dato di riconoscere una fotografia??!= hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
5|Wow,To je neverjetno,,= photos - hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
7| Sie in das Bild??#. _ hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
39|L0l!!**, kuris t??? nuotrauk?#?!!* hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
9| Who the F.#K is that?!#- hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
10|,jaja mira esta foto?!!#_ es tu cabron?!#! hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
24| haha, care este c?#! fotografie!# = hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
22|si usted estaba en la imagen??!# :) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
26|hihihe ,to si ti na fotki?_ :) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
25|???!!!! :) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
0|Wow,! is this is you fotoo??#!= ;) hxxp://cudear.com/view.php?=Facebook-pic####-JPEG
rkhunter wrote:Worm:Win32/Dorkbot.INice description
32d929a7b9cf0c8a2c8d516720d95fe4
VT
rkhunter wrote:Worm:Win32/Dorkbot.Ifrom infected machine
32d929a7b9cf0c8a2c8d516720d95fe4
VT