A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #22206  by granit12
 Thu Feb 13, 2014 3:34 pm
HI all memebers here.
Why not stoped this big bots?
https://www.google.com/#q=http:%2F%2Fd.lqw.me
Code: Select all
<script type="text/javascript" id="2f2a695a6afce2c2d833c706cd677a8e" src="htxp://d.lqw.me/xuiow/?g=750C2C5B-CF42-6996-0E5A-306165564128&s=F5D333A8-C748-4686-AE0A-9E008F670C22&z=1384886096"></script>
htXp://watch3dfilms.com/stats.php?hash=31dd7d01b0f5a9aeecaf921e05e367ce
 #22208  by patriq
 Thu Feb 13, 2014 8:29 pm
https://www.google.com/#q=http:%2F%2Fd.lqw.me
I believe this threat is called "AdPeak" or "ScorpianSaver"

more:

http://www.mcafee.com/threat-intelligen ... ?id=773786
http://www.threatexpert.com/report.aspx ... 903c5e5fa7
http://stackoverflow.com/questions/2053 ... -web-pages



Is it related to this panel?
htXp://watch3dfilms.com/stats.php?hash=31dd7d01b0f5a9aeecaf921e05e367ce
Code: Select all
Payload AV check

Date: 13.02.14 23:22:03
fsecure - Gen:Variant.Zusy.74138
drwebfile - Win32.HLLW.Autoruner1.61530
immunet - Gen:Variant.Zusy.74138
bitdef - Gen:Variant.Zusy.74138
avg - trj.Downloader.Generic13.BPEJ
panda - Generic Malware
gdata - Virus: Gen:Variant.Zusy.74138 (Engine A)
kis2013 - Network: Trojan.Win32.Fsysna.cwi
norman - winpe/MadnessPro.A
nod - @Trojan.Win32/TrojanDownloader.Agent.AAM
avast - Win32:Malware-gen
avira - TR/Downloader.Gen Trojan!
se - Trojan:Win32/Qidmorks.A
Variant.Zusy.74138
https://www.virustotal.com/en/file/cd59 ... /analysis/

Win32.HLLW.Autoruner1.61530
https://www.virustotal.com/en/file/7787 ... /analysis/


The 'gate' urls have similar structure.
Code: Select all
hxxp://fewr.biz/?uid=81984710&ver=1.14&mk=bb3b62&os=WinXP&rs=adm&c=1&rq=0
hxxp://d2ogssay9or4s.com/M83/?uid=81984710&ver=1.13&mk=0fe9bd&os=WinXP&rs=adm&c=2&rq=0
a plasma panel
hxxp://d2ogssay9or4s.com/login.php

sorry for a bit off topic
 #22209  by patriq
 Thu Feb 13, 2014 9:29 pm
that second panel you posted was Neutrino
Code: Select all
htXp://watch3dfilms.com/stats.php?hash=31dd7d01b0f5a9aeecaf921e05e367ce

http://malware.dontneedcoffee.com/2013/ ... t-kit.html

google caught a more active panel (attached)
googlecache.png
googlecache
googlecache.png (97.74 KiB) Viewed 513 times
pushing over browsers..
browsers.png
browsers
browsers.png (90.69 KiB) Viewed 513 times
also, dayum JP! what happened?
JPN.png
JAPAN !!!! NOOOO!!!
JPN.png (90.72 KiB) Viewed 513 times