A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #18341  by Squirl
 Tue Feb 26, 2013 4:49 pm
nakedworldcelebrities\x2ecom

redir to *.ddns.name

All samples in archive
Attachments
password: infected
(188.24 KiB) Downloaded 64 times
 #18343  by EP_X0FF
 Tue Feb 26, 2013 5:04 pm
Squirl wrote:nakedworldcelebrities\x2ecom

redir to *.ddns.name

All samples in archive
And the payload exe is ZeroAccess CLSID autorunner version.
Attachments
pass: malware
(172.35 KiB) Downloaded 59 times