Bunch of POS Malwares in attach (JackPos/Soraya/rdasrv/mmon)...
for SetupX.exe the password of the installer is 'Rome0' and drop mmon and rdasrv into /system32/
http://vxvault.siri-urz.net/ViriList.ph ... .91.198.91
Code: Select all
Soraya:Uname: Linux rome0.com 2.6.32-29-pve #1 SMP Thu Apr 24 10:03:02 CEST 2014 i686
$ last -f /var/log/wtmp
reboot system boot 2.6.32-29-pve Fri May 16 14:28 - 05:57 (22+15:29)
reboot system boot 2.6.32-19-pve Fri May 16 10:26 - 05:57 (22+19:31)
accounts pts/0 37.48.81.44 Thu Apr 24 18:55 - 13:54 (18:59)
reboot system boot 2.6.32-19-pve Sat Mar 15 11:08 - 10:07 (61+22:59)
root pts/0 37.48.81.52 Sat Mar 15 10:56 - down (00:11)
reboot system boot 2.6.32-19-pve Sat Feb 22 09:00 - 11:07 (21+01:07)
root pts/0 37.48.81.48 Sat Feb 22 07:28 - down (01:32)
reboot system boot 2.6.32-19-pve Sat Feb 22 07:27 - 09:00 (01:32)
wtmp begins Sat Feb 22 07:27:23 2014
https://www.virustotal.com/en/file/a776 ... 402224931/
https://www.virustotal.com/en/file/04b5 ... 402224932/
https://www.virustotal.com/en/file/c1a2 ... 402224934/
https://www.virustotal.com/en/file/33f0 ... 402225093/
https://www.virustotal.com/en/file/0866 ... 402225092/
JackPos:
https://www.virustotal.com/en/file/6347 ... 402225135/
mmon:
https://www.virustotal.com/en/file/7b31 ... 402225162/
bundled installer:
https://www.virustotal.com/en/file/6050 ... 402225205/
Attachments
infected (some additional files)
(902.29 KiB) Downloaded 168 times
(902.29 KiB) Downloaded 168 times
infected
(159.13 KiB) Downloaded 174 times
(159.13 KiB) Downloaded 174 times
no password
(556 Bytes) Downloaded 135 times
(556 Bytes) Downloaded 135 times
infected
(1.37 MiB) Downloaded 210 times
(1.37 MiB) Downloaded 210 times