A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4521  by GMax
 Mon Jan 17, 2011 6:43 pm
FileName: pornoplayer.exe
Size: 45 Kb (46592 byte)
Data/Time compile: 17.01.2011 / 15:04:39 UTC
MD5: 166C436DCA37956D0677D61500EC1C4C
Code: Select all
http://chmok.info/player/pornoplayer.exe
Call num: 9629456950
Unlock key: VALDEZ
 #4616  by Xylitol
 Fri Jan 21, 2011 3:17 pm
homoblocker:
Code: Select all
Number to Call: 9055228378
Number to Call: 9671979556
Number to Call: 9647263435
Number to Call: 9647263634
Number to Call: 9653919160
Number to Call: 9647235212
Number to Call: 9653919221
Code to unlock Windows: NOGLUES
homoblocker:
Code: Select all
Number to Call: 9629464449
Number to Call: 9629456950
Number to Call: 9652107336
Number to Call: 9647262090
Number to Call: 9629454365
Number to Call: 9653919228
Number to Call: 9629457136
Number to Call: 9671979553
Number to Call: 9671979590
Number to Call: 9671979557
Number to Call: 9671979556
Number to Call: 9055228378
Code to unlock Windows: VALDEZ
bluetrash:
Code: Select all
Number to Call: 9055230856
Number to Call: 9653919220
Code to unlock Windows: TNMTTF
 #4630  by GMax
 Sat Jan 22, 2011 9:08 am
homoblocker

Number to Call: 9652857791
Number to Call: 9671979717

unlock key: NOGLUES

Source
hxxp://pezdos.info/player/pornoplayer.exe
 #4641  by EP_X0FF
 Sat Jan 22, 2011 5:09 pm
More links to Winlock locations.

All links payload already reviewed by this forum members :)

hxxp://huevka.info/player/pornoplayer.exe
hxxp://hueriga.info/player/pornoplayer.exe

these two are the same like Xylitol reviewed here

hxxp://ztubexxx.info/5hlb8v883s5b4n1qm9t4nrh5qwvg2hp1/pornoplayer.exe

this one from SpermTV pattern.
 #4645  by Xylitol
 Sat Jan 22, 2011 7:38 pm
i just use my ransomware bots for see if samples was updated

https://www.virustotal.com/file-scan/re ... 1295724664
https://www.virustotal.com/file-scan/re ... 1295724667
Code: Select all
Number to Call: 9636256561
Number to Call: 9652750771
Code to unlock Windows: NOGLUES
  • 1
  • 2
  • 3
  • 4
  • 5
  • 17