A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #21723  by Win32:Virut
 Tue Dec 17, 2013 6:23 pm
I have downloaded it from:
Code: Select all
hxxp://rghost.net/50995422
Payment page:
Code: Select all
hxxp://futsyscarepay.com/payment.php
"Futurro Antivirus Unlimited license" :lol: Futurro Antivirus seems to be another rogue, I found only one thread about it: http://www.malwareremoval.com/forum/vie ... 11&t=62376

https://www.virustotal.com/en/file/247b ... /analysis/ - Publisher name is Futurro Soft. I'll request it in the Malware requests.
 #21726  by Xylitol
 Tue Dec 17, 2013 7:41 pm
Code: Select all
http://futsyscarepay.com/payment_process.php
> https://migs.mastercard.com.au/vpcpay (vpc_Merchant=9800000100)
>> https://www.vbv.ktb.co.th/vbvads/paWarning.aspx
• dns: 1 ›› ip: 130.185.105.68 - adresse: FUTSYSCAREPAY.COM
• dns: 1 ›› ip: 203.42.65.51 - adresse: MIGS.MASTERCARD.COM.AU *legit*
• dns: 1 ›› ip: 202.12.117.153 - adresse: WWW.VBV.KTB.CO.TH *legit*
SCAREpay.com seriously ?
  • 1
  • 11
  • 12
  • 13
  • 14
  • 15