A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12489  by rough_spear
 Mon Apr 02, 2012 10:37 am
Hi All, :D
Here is one more Windows First-Class Protector

File name - Setup.exe -----> Dropper.
MD5 - 9e9898b0ca37f87db4d1a69a821268ed
VT link - https://www.virustotal.com/file/65a061e ... /analysis/

File name - Protector-mtqt.exe ---Dropped file.
MD5 - 856328e8d300aa30bab2a9dd00982456
VT link - https://www.virustotal.com/file/5c4cbb8 ... /analysis/

Regards,


rough_spear. ;)
Attachments
password - malware.
(2.03 MiB) Downloaded 66 times
password - malware.
(1.91 MiB) Downloaded 59 times
 #12510  by Evilcry
 Wed Apr 04, 2012 6:19 am
Delivered by Twitter spam message
jose a. espaillat p. ‏ @jespaillatp
- Shider http://tinyurl.com/7rhqdfy
Location:
http://optimizervulnerabilityprotect.in ... 375cbc551/
https://www.virustotal.com/file/2e36746 ... 333519722/

Pretty similar to Windows Shielding Utility mentioned in the previous post.

Addition:

From the same IP:
pcantivirustest.info/bb61f9bcec711d56/23/
pcantivirustest.info/bb61f9bcec711d56/21
computerantivirusmonitor.info/0520091375cbc551/
keeperdataperfomance.info/39f678a0d39279b6/4/
keeperdataperfomance.info/39f678a0d39279b6/4/
Attachments
pwd: infected
(2.04 MiB) Downloaded 69 times
  • 1
  • 10
  • 11
  • 12
  • 13
  • 14
  • 46