Jump to content

Malwarebytes

coupons.exe


14 replies to this topic

#1
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
hxxp://132.238.55.114/
Result: 6/38 (15.79%)
http://www.virustotal.com/analisis/e31a921...d355bdbb97eec76
CIMA: http://camas.comodo.com/cgi-bin/submit?fil...8ebce56effc6678
Trojan.Salmon moving to fish tank on reboot.

#2
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
Morph List.exe
hxxp://88.161.229.82/
hxxp://81.9.198.159
Result: 4/38 (10.53%)
http://www.virustotal.com/analisis/8f67a91...827845fe2fe863a
Trojan.Salmon moving to fish tank on reboot.

#3
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
Sale.exe
hxxp://85.231.18.13/
Result: 6/38 (15.79%)
http://www.virustotal.com/analisis/87aa37a...c1be874cf89f766
Trojan.Salmon moving to fish tank on reboot.

#4
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
Sales.exe
hxxp://200.206.142.116/
Result: 7/39 (17.95%)
http://www.virustotal.com/analisis/ba61712...b8f37e222a94092
CIMA: http://camas.comodo.com/cgi-bin/submit?fil...9e6b01517b81ae0
Trojan.Salmon moving to fish tank on reboot.

#5
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.

View Postsalmon, on Feb 27 2009, 12:01 AM, said:

Went to that site and picked up a nocrisis.exe?

Quote

File nocrisis.exe received on 02.27.2009 00:55:34 (CET)
Current status: finished
Result: 5/38 (13.16%)
Virus Total
File size: 411136 bytes

#6
funkydude

    New Member

  • Members
  • Pip
  • 3 posts

View PostJaxryley, on Feb 26 2009, 11:58 PM, said:

Went to that site and picked up a nocrisis.exe?

Virus Total
File size: 411136 bytes

Hello, the waledac serving sites are automated. They serve different malware every 10 minutes or so, posting them is useless as they are gone as soon as they came.

#7
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
I would hazard a guess and say these are from the same family of trojans along the lines of those postcard.exes and valentine's.exes we had a while back.

The sites can spit out a morphed and or renamed exe at any time and real hard to keep up with the variants. B)

Bit of fun for some though! :rolleyes:

#8
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.

View Postfunkydude, on Feb 27 2009, 08:03 AM, said:

Hello, the waledac serving sites are automated. They serve different malware every 10 minutes or so, posting them is useless as they are gone as soon as they came.
Posted as I was posting. :rolleyes:

#9
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
Anyone know what these are?
A popup comes up with some strange thing O.o
hxxp://69.242.178.19
hxxp://69.242.178.19
hxxp://68.91.215.17

Source: http://www.threatexpert.com/report.aspx?md...61b0ffed62f5dee
Trojan.Salmon moving to fish tank on reboot.

#10
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,162 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
Very bad....

Quote

File run_2_.exe received on 03.01.2009 17:15:36 (CET)
Current status: finished
Result: 2/39 (5.13%)

Virustotal
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#11
sho-dan

    कैंसर योद्धा

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,023 posts
  • Gender:Not Telling
  • Location:Jah Jersey Shore
re-morphed
hxxp://69.242.178.19

Quote

File salelist.exe received on 03.01.2009 17:28:22 (CET)
Current status: finished
Result: 9/39 (23.08%) File size:400 KB (409,600 bytes)
virustotal
"Don't worry about a thing,
'Cause every little thing gonna be all right!"

#12
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States

View PostJaxryley, on Feb 26 2009, 07:05 PM, said:

I would hazard a guess and say these are from the same family of trojans along the lines of those postcard.exes and valentine's.exes we had a while back.

The sites can spit out a morphed and or renamed exe at any time and real hard to keep up with the variants. ;)

That is an understatement if I ever read one. ;)

#13
sho-dan

    कैंसर योद्धा

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,023 posts
  • Gender:Not Telling
  • Location:Jah Jersey Shore
Morphing us to death softly. ;)
"Don't worry about a thing,
'Cause every little thing gonna be all right!"

#14
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
hxxp://www.chatloveonline.com/
Getting discounts.exe at the moment
Result: 4/39 (10.26%)
http://www.virustotal.com/analisis/af8be2d...09b0f6e37aeb31e
CIMA: http://camas.comodo.com/cgi-bin/submit?fil...72861ea60b4f673
Trojan.Salmon moving to fish tank on reboot.

#15
salmon

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 179 posts
  • Gender:Male
  • Interests:Mainly salmon
coponlist.exe
hxxp://84.29.203.15/
Result: 3/38 (7.9%)
http://www.virustotal.com/analisis/b41ed6c...131a5e7bad5d38a
http://88.114.207.199 <- Not online yet
Trojan.Salmon moving to fish tank on reboot.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us