A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #32585  by Fedor22
 Thu Feb 14, 2019 12:51 pm
ikolor wrote: Thu Feb 14, 2019 11:30 am Thanks .I can't find good malware sorry for it.

https://www.virustotal.com/en/file/2401 ... 550144002/


https://www.virustotal.com/en/file/2a51 ... 550143653/
The fisrt sample is Drupal JavaScript, not malicious.
The second sample is Emotet downloader.
Downloads exe from:
Code: Select all
hxxp://hifucancertreatment.com/wp-content/uploads/PKL8EApdvFOUn79
Connects to CnC server:
Code: Select all
hxxp://67.254.13.154/
 #32589  by Antelox
 Fri Feb 15, 2019 10:11 am
ikolor wrote: Thu Feb 14, 2019 7:12 pm Thanks you .Next file who knows

https://www.virustotal.com/en/file/d1e2 ... 550171450/
PDF phishing.

Links involved:
Code: Select all
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/ODL.html
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/MYM.html
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/OLK.html
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/HML.html
hxxps://www.djfernandodg.com.ve/OndrvE/drive/syn/AII.html
BR,

Antelox
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7