A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #25620  by 275751198
 Sun Apr 12, 2015 2:12 am
A series of Trojan has recently been discovered which spreaded by QQ.
QQ is the most popular chat software in China.
Many hackers registered phishing account to comment the unencrypted qzone of the users
Cheat the user to click into the phishing account .
On PC you will find a phishing website,On Android you will get an APK Trojan
At first Kaspersky haven't scan this series until March 2015
Now Kaspersky HEUR:Trojan-Downloader.AndroidOS.Agent.y

sample link: http://yunpan.cn/cVYK2hJptFuVc
link password 0954
sample password infected

one of the phishing account (PS :He is a man)
无标题.png
无标题.png (144.36 KiB) Viewed 966 times
Attachments
infected
(2.09 MiB) Downloaded 72 times
 #25646  by EP_X0FF
 Wed Apr 15, 2015 11:41 am
275751198 wrote:update 4-15
:D :D :D

sample link http://yunpan.cn/cVkfCWJjkp5WK
link password f67f
sample password infected
You can attach your samples directly to your message, just put them inside archive (zip/7zip/rar) with standard password. Your filesharing service is very slow.
 #25656  by EP_X0FF
 Thu Apr 16, 2015 1:50 pm
Probably you need to split it on few archives by 5 Mb each.