Jump to content

Malwarebytes

setup.exe


1 reply to this topic

#1
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
http://95.53.187.96/d=tohva.org/0x3E8/view/
VT 15/41
File size: 61440 bytes
http://rapidshare.de/files/48395399/setup.rar.html


#2
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,152 posts
  • Gender:Male
  • Location:127.0.0.1
Thanks Jax,

Have now added the URL for harvesting :)

Ps now i know why i dont take time off :) ...was my first day(s) off since end of May and boy has it stacked up :)

Hey this is turning out to be a fun rabbit hole,the first file you linked up is a configuration file and is none PE..but it had a URL in the HEX

http://61.235.117.83/popup.php

Went there and get hit with fake scanner redirect

http://securitytestnetonline.com/download.php?affid=12410

Can see how these nets work by spreading packaged droppers...Malware affialites :)

Woot i is back and on fire :lol:
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us