A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15891  by Xylitol
 Fri Oct 05, 2012 7:37 am
landing and panel cash
Attachments
infected
(2 MiB) Downloaded 87 times
infected
(2 MiB) Downloaded 79 times
infected
(797 Bytes) Downloaded 67 times
 #15928  by rough_spear
 Tue Oct 09, 2012 6:57 am
Hi, :D

Here is one more Fake AV.

Urls -

hxxp://178.77.103.54:8080//get/faa91cf5e79a76602f094ed38fad5872.exe
hxxp://188.212.156.180:8080//get/faa91cf5e79a76602f094ed38fad5872.exe
hxxp://202.169.224.202:8080//get/faa91cf5e79a76602f094ed38fad5872.exe
hxxp://50.22.136.150:8080/get/faa91cf5e79a76602f094ed38fad5872.exe

Regards,


rough_spear. ;)
Attachments
password - infected.
(381.15 KiB) Downloaded 98 times
 #15984  by EP_X0FF
 Sun Oct 14, 2012 10:05 am
Buster_BSA wrote:
TeamRocketOps wrote:System Progressive Protection

Fresh Sample

Low detection

VT 3/43

https://www.virustotal.com/file/59394be ... 350178423/
This sample calls DSEditSecurity function. What is the purpose of that?
There is no purpose like any other. This is a part of fake import table.
  • 1
  • 40
  • 41
  • 42
  • 43
  • 44
  • 46