markusg wrote:today night, we get some requests from infected peoples, they get in a message, this files, via sendspacee urlsThis is Ngrbot aka Dorkbot. So many strings inside, so just I post a little piece.
https://www.virustotal.com/file/2b5ef3b ... /analysis/
normaly it comes as zip archiv
Main reasons:Two other files are Win32 PE executables. Will look later.
- you stupid cracker
- you stupid cracker...
- you stupid cracker?!
ngrBot Error shell32.dll " % s " % S msg http int %d httpi usbi dnsapi.dll DnsFlushResolverCache P O S T = http://%s/%s http://%s/ HTTP Host:
Ring0 - the source of inspiration