A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15815  by markusg
 Sun Sep 30, 2012 12:33 am
it connect to:
promos.fling.com
and other ips, i seen in zero access samples, so perhaps z-access.
it loads other files from hotfile, i will attach
Attachments
(271.84 KiB) Downloaded 61 times
 #15816  by markusg
 Sun Sep 30, 2012 12:38 am
ok
the produkt name
ProductName..............: ;%`TODO;%`:;%`Product;%`;%`Name;%`
of
File name:
weifgwf.ong 
shows me also, its z-access, i see this in the uploaded samples of main in the last days
but this one drops z-access into recycler
Last edited by markusg on Sun Sep 30, 2012 3:43 am, edited 1 time in total.
 #15817  by markusg
 Sun Sep 30, 2012 3:05 am
a ok, so
ogxEz57 
is the file sending the infekted links to kontakts:
url chema:
sendspace.com/pro/dl/8a963g?image =kontaktname
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8