Jump to content

Malwarebytes

TubeViewer.ver.6.48268.exe


2 replies to this topic

#1
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
http://softportal-extrafiles.com/TubeViewer.ver.6.48268.exe
Result: 2/41 (4.88%)
VT
File size: 78489 bytes
http://rapidshare.de/files/47679110/TubeViewer.ver.6.48268.rar.html


#2
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
http://files-softportal.com/TubeViewer.ver.6.48268.exe
Result: 2/40 (5.00%)
VT
File size: 74852 bytes
http://rapidshare.de/files/47679327/TubeViewer.ver.6.48268.rar.html
Morph.
http://rapidshare.de/files/47679530/TubeViewer.ver.6.48268.rar.html


#3
S!Ri

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 7,111 posts
  • Gender:Male
Take care with those files. They are the same
Today the DNS is: extrafiles-softportal.com

Filename is not important, exemple:
hxxp://extrafiles-softportal.com/Jaxryley.123.exe

Coders are using a stub to have different MD5 (different size, different key). The stub is changed every 24h/48h.
When running the exe, the stub decrypt an UPX file, then it is unpacked, and finally we get the original executable that downloads 3 other malwares.

Don't look after MD5 or VT detection. Classic AV are far behind...
Posted ImageS!Ri
Research Engineer

Posted Image Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us