A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #27852  by FafZee
 Thu Feb 11, 2016 8:35 am
ikolor wrote:next

https://www.virustotal.com/en/file/4766 ... 455127576/
Download in .NET:
Contacts : hxxp://185.50.71.150/browser.txt
extract url from this and download (at the date of post): hxxp://185.50.71.150/newbrowser.zip
extract it, and run it under smss.exe (looks to be a bruteforcer) https://www.virustotal.com/en/file/84ec ... 455180133/
extracted archive upload: https://www.virustotal.com/en/file/4276 ... 455180963/

//edit:
Password for newbrowser.zip : ejder*