A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #19790  by r3shl4k1sh
 Tue Jun 25, 2013 5:03 am
Flamef wrote:Hi,
pretty much summing up what you guys posted in this vid,showing how to decrypt your files.
http://www.youtube.com/watch?v=CgC5uRT46oQ
Should help the infected users.

You probably mean Shouldn't help the infected users.

==========================================================

When we have analyzed this the "Identification number" the infected user would get was around 10000, now it is still live on the same server hxxp://infominfo.net/add/add.php and the ID is around 27000.

Well most of his customers with IDs between 13000-27000 i have created using the python (3) script in attach.
It is shame that this server is still up.
Attachments
(371 Bytes) Downloaded 49 times