A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28835  by ikolor
 Thu Jul 07, 2016 6:10 pm
next...

Thanks for analysis

https://www.virustotal.com/en/file/ccd3 ... 467914818/
########################################
This type of file from my browser is classified as malware .?
########################################

https://www.virustotal.com/en/file/36ef ... 467915557/

https://www.virustotal.com/en/file/b550 ... 467915450/
Attachments
(327.69 KiB) Downloaded 63 times
(506.31 KiB) Downloaded 64 times
 #29453  by EP_X0FF
 Tue Oct 18, 2016 8:33 am
ikolor wrote:next..

https://www.virustotal.com/en/file/1c8b ... 467956059/


collection

https://www.virustotal.com/en/file/9b43 ... 467969043/
a1634.exe software bundler, trash, removed.
janavb.exe - MSIL/Noancooe (NanoCore)
janawin.exe - MSIL/Noancooe (NanoCore)
kazycrp.exe - MSIL/Noancooe (NanoCore)
cs.exe - MSIL/Silog (PWS)
NEI 13 10 Cyber__6629_i1929647758_il289940_26.exe - software bundler Mizenota

Posts moved.
 #29454  by EP_X0FF
 Tue Oct 18, 2016 8:52 am
ikolor wrote:next...

Thanks for analysis

https://www.virustotal.com/en/file/ccd3 ... 467914818/
########################################
This type of file from my browser is classified as malware .?
########################################

https://www.virustotal.com/en/file/36ef ... 467915557/

https://www.virustotal.com/en/file/b550 ... 467915450/
310F23E7D850B1891FCE1B8A0DDDF1E63216EE50 - Ransomware
email.exe - MSIL/Silog (PWS)
updater.exe - MSIL/Noancooe

Posts moved.
 #32655  by hackr8
 Thu Mar 07, 2019 2:49 pm
I found this on dropbox. It's made with VB6 [signature:Microsoft Visual Basic v5.0]
Please note that I was the first person to upload the file to Virustotal so the report might change soon.
Virustotal: https://www.virustotal.com/#/file/dab62 ... /detection
Attachments
password: infected
(534.43 KiB) Downloaded 20 times
Last edited by hackr8 on Thu Mar 07, 2019 5:51 pm, edited 1 time in total.