A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7272  by EP_X0FF
 Thu Jul 14, 2011 12:55 pm
bitx wrote:System Repair
Looks like reincarnation of Windows XP Repair.
Posts moved.
 #7483  by EP_X0FF
 Thu Jul 21, 2011 2:57 pm
SMS Hoax Skype

This is SMS hoax which copies Skype setup interface. It comes from hxxp://skype-downloads.ru (hxxp://77.221.149.219/get/311/23639)
Crapware written in C#

Hello! I'm Skype!

Image

Installation complete, would you like to start Skype?

Image


Give me money, send SMS dialog

Image

Real Skype can be downloaded from http://www.skype.com/ and it's FREE. Don't be fooled by such primitive crapware.
Attachments
pass: malware
(885.21 KiB) Downloaded 61 times
 #7629  by Xylitol
 Mon Jul 25, 2011 9:40 am
Zip-Archive
Leaked stuff.

Tracking Cyber Crime: Zip Archive Affiliate (Hoax SMS/Fake Installer)
http://xylibox.blogspot.com/2011/07/tra ... chive.html

html template in attach and zipArchive hoax builder on multiupload due to heavy size of package (19Mb)
http://www.multiupload.com/Z15J2EADZV
Attachments
pwd: xylibox
(1.57 MiB) Downloaded 65 times
 #7635  by bitx
 Mon Jul 25, 2011 12:40 pm
EP_X0FF wrote:SMS Hoax Skype

This is SMS hoax which copies Skype setup interface. It comes from hxxp://skype-downloads.ru (hxxp://77.221.149.219/get/311/23639)
Another URL hxxp://d2xx.ru/SkypeSetup.exe
 #7859  by Xylitol
 Fri Aug 05, 2011 2:55 pm
Hoax SMS Skype who come from the cashmagnat.com russian affiliate.

2/43 >> 4.7%
http://www.virustotal.com/file-scan/rep ... 1312490095
Code: Select all
GET /client_api/payform.php?step&aid=3747463 HTTP/1.1
Accept: */*
Accept-Language: fr
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1;
.NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR
3.5.21022)
Host: cashmagnat.com
Connection: Keep-Alive

HTTP/1.1 200 OK
Attachments
pwd: xylibox
(2.28 MiB) Downloaded 53 times
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 12