A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #19422  by 360Tencent
 Sun May 26, 2013 5:37 am
PWS


https://www.virustotal.com/en/file/d75b ... 369546079/

SHA256: d75b07eced87360e8753c4f312f59075a0bb6a42c5075a57b53b92355727d16b
SHA1: 43dd86e050d7d287ce4990e74582b3344bfdcc6c
MD5: 35f63590d1dd5bf6423f527b22584bc4
pass;infected
(3.1 MiB) Downloaded 90 times
hxxp://jjso.net:88/
hxxp://jjso.net:88/1
hxxp://jjso.net:88/2
hxxp://jjso.net:88/3
hxxp://jjso.net:88/4
hxxp://jjso.net:88/ceshi
hxxp://jjso.net:88/D_mt
hxxp://jjso.net:88/D_xp
hxxp://jjso.net:88/jjso
hxxp://jjso.net:88/jp
hxxp://jjso.net:88/l0
hxxp://jjso.net:88/l0_1
hxxp://jjso.net:88/l1
hxxp://jjso.net:88/l1_1
hxxp://jjso.net:88/l1_T.jpg
hxxp://jjso.net:88/l2
hxxp://jjso.net:88/l2_T.doc
hxxp://jjso.net:88/l3
hxxp://jjso.net:88/l4
hxxp://jjso.net:88/l4_T.jpg
hxxp://jjso.net:88/liwei.jpg
hxxp://jjso.net:88/mt
hxxp://jjso.net:88/mt1
hxxp://jjso.net:88/mt2
hxxp://jjso.net:88/mt3
hxxp://jjso.net:88/mt3_T.jpg
hxxp://jjso.net:88/px.jpg
hxxp://jjso.net:88/xp.jpg
...
Capture.PNG
Capture.PNG (52.76 KiB) Viewed 1193 times
 #19929  by hx1997
 Wed Jul 03, 2013 2:55 am
Sendspace is sending (targeted?) malware
http://www.reddit.com/r/netsec/comments ... d_malware/

It's adware. VT 8/47
https://www.virustotal.com/en/file/7565 ... 372819428/

Malware download page
捕获3.png
捕获3.png (15.04 KiB) Viewed 1072 times
Note that you need to check the "sendspace accelerator" checkbox to download this adware.
Attachments
infected
(274.79 KiB) Downloaded 65 times