markusg wrote:Dismb.exe
http://www.virustotal.com/file-scan/report.html?id=61222b2d4c677d6a7f3a266bec358280bee3ed22cd037db20edebdd285830293-1299757652
Target hxxp://westray.info/docs/batserv2.exe
TrojanDownloader:Win32/Renos.MJ
findstrb.exe
http://www.virustotal.com/file-scan/report.html?id=e45ca78099b2e89689140a5c85ba490481707eb2d995dafcd32aa9e01422d5d0-1299757755
Target hxxp://vidmage.info/stssd/sptnd.exe
TDL4
makecaba.exe
http://www.virustotal.com/file-scan/report.html?id=2187676ac078207d49fbbc1f1acd7b33f9633f697ac54c337259d92fb89006bf-1299757890
Target hxxp://westray.info/docs/checkp3.exe (previously it was Bamital drop)
mtstocomb.exe
http://www.virustotal.com/file-scan/report.html?id=f7bb85774275ffbe52a902a75dffb99126dbe5d08c42bfacb87fff10284efe92-1299757975
Target hxxp://vidmage.info/stssd/tcs20.exe
TrojanDownloader:Win32/Harnig.S
netiougca.exe
http://www.virustotal.com/file-scan/report.html?id=7ec43633379c67bb5c163a8d12948918bff95f3f441e56c0c51067ac3919cf72-1299758063
Target hxxp://westray.info/docs/cfwan.exe
Backdoor:Win32/Cycbot.B
DisplaySwitcha.exe
http://www.virustotal.com/file-scan/report.html?id=244e54b112ee4de99e5423323139da723941c7537b03f9ded4ae1b85c38607e1-1299760539
Target hxxp://westray.info/docs/cfwan.exe
Backdoor:Win32/Cycbot.B
gpscriptb.exe
http://www.virustotal.com/file-scan/report.html?id=8a7da39a3cf4a1a6ec18b30ef487d93824a3f678e883986829155130487190d8-1299760648
Target hxxp://westray.info/docs/batserv2.exe
TrojanDownloader:Win32/Renos.MJ
nslookupa.exe
http://www.virustotal.com/file-scan/report.html?id=997354f9a31aac7fa9e0d0053f1ad85c1d951ea257b36e36a21b252e37214b1e-1299760553
Target hxxp://vidmage.info/stssd/tcs20.exe
TrojanDownloader:Win32/Harnig.S
openfilesb.exe
http://www.virustotal.com/file-scan/report.html?id=f2d798cea2ceced5103c1c864ba426392845c9f4316cf8aaa30b58544b6112c8-1299760769
Target hxxp://vidmage.info/stssd/sptnd.exe
TDL4
psrb.exe
https://www.virustotal.com/file-scan/report.html?id=15b48247d989604f2fc83a06bdc2b739b82890639b0e412ad535b15c109dbdf3-1299764517
Target hxxp://westray.info/docs/checkp3.exe (previously it was Bamital drop)
Nothing new, even payload it not re-crypted. All these trash were reviewed many times.