This is PowerLoader Alureon cross-platform dropper.
https://www.virustotal.com/en/file/843f ... 369101506/
https://www.virustotal.com/en/file/6a9c ... 369101315/
Posts moved.
[main]here deobfuscated
srvurls=hxxp://r.gigaionjumbie.biz/images/gx.php;hxxp://x.dailyradio.su/images/gx.php;hxxp://w.kei.su/images/gx.php
srvdelay=15
srvretry=2
buildid=REE
https://www.virustotal.com/en/file/843f ... 369101506/
https://www.virustotal.com/en/file/6a9c ... 369101315/
Posts moved.
Attachments
pass: infected
(31.3 KiB) Downloaded 83 times
(31.3 KiB) Downloaded 83 times
Ring0 - the source of inspiration