Hi guys.
I'm analyzing Downloader.Dromedian - https://www.symantec.com/security_respo ... 99&tabid=2
So far i don't have sample yet, but symantec reports several infections in last 24 hours.
Most of the files is in format dx*.exe. Symantec lists several C&C domains and it looks like only these three are still active:
Link to VirusTotal analysis: https://www.virustotal.com/en/file/e771 ... /analysis/
I'm analyzing Downloader.Dromedian - https://www.symantec.com/security_respo ... 99&tabid=2
So far i don't have sample yet, but symantec reports several infections in last 24 hours.
Most of the files is in format dx*.exe. Symantec lists several C&C domains and it looks like only these three are still active:
- infoodstuffshop.com, 69.43.161.176
flyshopear.ru, 95.211.172.143
Maidarm.ru, 46.19.137.14
Link to VirusTotal analysis: https://www.virustotal.com/en/file/e771 ... /analysis/