markusg wrote:dll.exefile.exe
MD5 : 9ce020a0719921748b41fa76df876283
https://www.virustotal.com/file-scan/re ... 1317137762
file.exe
https://www.virustotal.com/file-scan/re ... 1317137394
MD5 : 909e35b8b43949dc008f6f88e93cbcf0
[main]dll.exe
version=0.03
aid=30227
sid=0
builddate=351
installdate=28.9.2011 8:39:38
rnd=2728766874
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://lo4undreyk.com/;hxxps://sh01cilewk.com/;hxxps://cap01tchaa.com/;hxxps://kur1k0nona.com/;hxxps://u101mnay2k.com/
wsrv=hxxp://gnarenyawr.com/;hxxp://rinderwayr.com/;hxxp://jukdoout0.com/;hxxp://swltcho0.com/;hxxp://ranmjyuke.com/
psrv=hxxp://crj71ki813ck.com/
version=0.31
[main]All extracted data from both in attach.
version=0.03
aid=30041
sid=0
builddate=351
installdate=28.9.2011 8:42:46
rnd=2326177136
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://lo4undreyk.com/;hxxps://sh01cilewk.com/;hxxps://cap01tchaa.com/;hxxps://kur1k0nona.com/;hxxps://u101mnay2k.com/
wsrv=hxxp://gnarenyawr.com/;hxxp://rinderwayr.com/;hxxp://jukdoout0.com/;hxxp://swltcho0.com/;hxxp://ranmjyuke.com/
psrv=hxxp://crj71ki813ck.com/
version=0.31
Attachments
pass: malware
(192.91 KiB) Downloaded 129 times
(192.91 KiB) Downloaded 129 times
Ring0 - the source of inspiration