Found this running with one of the new ZeroAccess variants today (one is FUD other is very low 1/46):
The dll was loaded inside the exe process:
This was also running on the PC (FUD again):
Attachment quota has been reached. You can find it temporarily here:
https://dl.dropboxusercontent.com/u/176 ... eokyur.zip
Password: infected
The dll was loaded inside the exe process:
- MD5: a83816056b0ab0d1d4e6898812288bfa
File name: peokyur.dll
Detection ratio: 1 / 46
- MD5: e02dd60332cc3d8dd19795e1d9887b8b
File name: ehojilcn.exe
Detection ratio: 0 / 46
This was also running on the PC (FUD again):
- MD5: 598107403d9fb8871d00470f8ff716d1
File name:83A.exe
Detection ratio: 0 / 46
Attachment quota has been reached. You can find it temporarily here:
https://dl.dropboxusercontent.com/u/176 ... eokyur.zip
Password: infected