360Tencent wrote:http://www.securelist.com/en/blog/20819 ... ssing_linkStuxnet dropper [that contains Flamer component in resource]
Orig [crypted/packed]:
MD5: 2fb979eb3e8d8b1571cdd0df33427969
SHA1: 46104bf26300a5fb7a4f799d80e141b95465d0cc
File size: 611840 bytes
Decrypted/unpacked [with resource section]:
MD5: 2f4e30a497ae6183aabfe8ba23068c1b
SHA1: 1df6ae2a5594ab29a6e60b6d9296128b1f9fd980
File size: 1603072 bytes
Both in attach.
Attachments
pass:infected
(590.02 KiB) Downloaded 123 times
(590.02 KiB) Downloaded 123 times
pass:infected
(780.77 KiB) Downloaded 118 times
(780.77 KiB) Downloaded 118 times