Ta!0n wrote:Attached sampleYour post is empty.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
Ta!0n wrote:Attached sampleYour post is empty.
DMEW wrote:I heard Poweliks has been dead since 2014, but I have what looks like a Poweliks sample from ~2015 and the C2 servers are still working. It does the same loader tactics, performs click fraud, and even visits Expendablesearch.com (just like the Symantec report on it). With that said..is this still a variant? I would like to know what to properly call this piece of malware.Attach your sample please.