A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30560  by Cody Johnston
 Mon Jul 10, 2017 12:09 am
https://www.virustotal.com/en/file/f559 ... 499619085/
This one is MacKeeper. It is a PUP for mac OS, it's not necessarily malware but it is also not very useful.
https://www.virustotal.com/en/file/a920 ... 499617744/
This is a chinese malicous browser extension. It changes the HOSTS file, overwrites all browser desktop icons with new shortcut (to change homepage), mostly standard stuff for malicious browser extensions.

Installs kangle web server:

https://sourceforge.net/projects/kangle/

Attached config file for it.

Contacts a lot of hosts. Attached contacted hosts full list in csv format.

Something else interesting, it seems to do something with ChromeCast:

Image

More info here: https://www.reverse.it/sample/a92058800 ... mentId=100
Attachments
(22.81 KiB) Downloaded 12 times