A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20635  by Win32:Virut
 Thu Aug 29, 2013 10:42 am
Antivirus Security Pro

SHA256: dc715a8e61985f04ec06d7289527bbfd00a4af9ffd2745482f3da071a8b65c93
SHA1: 47d0d0260dd036d4b9526ea6cced28f90b44f784
MD5: 3e7dfe660e773106620ee7f000ed6a1e
File size: 646.5 KB ( 662016 bytes )
File name: XlX3nUa3.exe
Detection ratio: 0 / 46
Analysis date: 2013-08-29 10:35:25 UTC ( 0 minutes ago )
https://www.virustotal.com/en/file/dc71 ... 377772525/

dropped file:

SHA256: 982f9a3ec39cbbb3f415c0e6c686deca6c6e5dd14a4b26e454af93f3cc6858ca
SHA1: 83e61d3a9f6f17304c209abc14f5ccb5e5bcf2d1
MD5: 37ae22ba2799ed146c47085268dd481b
File size: 112.5 KB ( 115200 bytes )
File name: 1898282641481779720.exe
Detection ratio: 23 / 46
Analysis date: 2013-08-29 10:36:46 UTC ( 1 minute ago )
https://www.virustotal.com/en/file/982f ... /analysis/
Attachments
(558.55 KiB) Downloaded 63 times
 #20637  by Win32:Virut
 Thu Aug 29, 2013 3:56 pm
133 samples of Antivirus Security Pro

Payment page:

hxxps://swaretraders.com/p/fp/asp/?lid=0073&ver=0073&reject_url=http%3A%2F%2Frxprogress.com%2Fp%2Fdecline%2F%3Flid%3D0073%26ver%3D0073%26nid%3DD5B2E7CD%26r%3D77%26affid%3D78701%26group%3Dasp&nid=D5B2E7CD&r=77&affid=78701&group=asp
Attachments
(49 Bytes) Downloaded 67 times
 #20665  by secObs
 Sat Aug 31, 2013 8:05 pm
Internet Security 2013

MD5: fdb5450c46d2bc7f9b7acb986f1211e6
SHA-1: 5273ca2f83b29cf6b98c5ef2afd5cd67785dceea

Payment page: [url]hxxp://regdexsecurity.com/buynow.php?bid=95[/url]

Virustotal: https://www.virustotal.com/en/file/ac.. ... 377979367/
Attachments
pwd: infected
(796.65 KiB) Downloaded 76 times
  • 1
  • 9
  • 10
  • 11
  • 12
  • 13
  • 15