A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #31209  by Fedor22
 Tue Jan 16, 2018 7:35 pm
4 samples of "NIX Video Player" (Win32/InstallCore)
This samples taken from 4 russian scum websites:
xxxx://wq.underfongaafui.download/161114/1736/zt6pptz/s37qjl/3799#
xxxx://ydlqn.soogiedsoafm.download/161112/1738/s84y9/dy5js#
xxxx://f.underfongaafui.download/16119/1736/jsqbmbe/794vw4d#
xxxx://pks03.buncezmnwyxadv.download/16114/1738/pkoy61r# (all websites worked)
When you visit one of these sites, a warning is displayed:
"Please install NIX Video Player to continue".
VT: https://www.virustotal.com/en/file/4e19 ... 516130791/ (Nix_Player_3435892897, 5/66)
https://www.virustotal.com/en/file/d117 ... /analysis/ (Nix Player, 17/67)
Nix_Player_0729469623 (5/66)
Nix_Player_1655606335 (5/66)
Attachments
(6.74 MiB) Downloaded 36 times