Recycle.Bin.exe
http://www.virustotal.com/file-scan/rep ... 1307438580
http://www.virustotal.com/file-scan/rep ... 1307438580
Attachments
(445.18 KiB) Downloaded 42 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:Recycle.Bin.exev1.3
http://www.virustotal.com/file-scan/report.html?id=94457981a2d3969426d2c67b190bc93291d8ee46e36551fc3d93732f0ddebe76-1307438580
hxxp://95.168.178.220/index.php;80
hxxp://188.72.201.213/index.php;80
hxxp://google-1aa.com/index.php;80
hxxp://avira-data.com/index.php;80
hxxp://212.95.58.129/index.php;80
hxxp://212.95.63.35/index.php;80
hxxp://212.95.63.36/index.php;80
hxxp://www.borsgandkotletsplatinum.com/suit/gate.php;90http://www.virustotal.com/file-scan/rep ... 1307433646
hxxp://www.uploadefreewarenow.co.cc/mail/gate.php;90
hxxp://www.muchachasgraciass.co.cc/freeware/gate.php;90
hxxp://www.muchafdfererss.co.cc/driver/gate.php;90
hxxp://www.erfotofreefactory.co.cc/freeware/gate.php;90
hxxp://visitorcounter.net.in/images/gate.phphttp://www.virustotal.com/file-scan/rep ... 1307654559
hxxp://visitorcounterbck.net.in/images/gate.php
Washer2.rar.exeSpyEye v1.3
http://www.virustotal.com/file-scan/report.html?id=c15125dc7ad2954330538a4aa1cb22c438251896fdf3521df6718c9065c5af8d-1307698951
hxxp://host-checkker.net/ASdhgas6d/sdhgas/yrgdate13.php;350
hxxp://befirstchild.net/bFeIN_L/50x.html.php;350
hxxp://nofrostengland.com/hYtgfE/dgTrfdbbbf.php;350
Washer1.rar.exeSpyEye v1.3
http://www.virustotal.com/file-scan/report.html?id=10b758a75f5662fec1d08be607e7f8c2f241333267f185cf3bd697a983dc4892-1307698615
hxxp://host-checkker.net/ASdhgas6d/sdhgas/yrgdate13.php;350
hxxp://keepyoursecurity.net/lTq_YTrqw3/hhgdftco9.php;350
hxxp://befirstchild.net/qDewtdd/bfdhtt33.php;350
hxxp://nslookupxo.com/dns/home.php;1500I see random name for config.bin :)
hxxp://91.223.82.127/dns/home.php;1500
hxxp://91.223.82.128/dns/home.php;1500
hxxp://91.223.82.125/dns/home.php;1500
hxxp://91.223.82.126/dns/home.php;1500