A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7329  by kmd
 Sat Jul 16, 2011 5:10 pm
nickvth2009 wrote:
EP_X0FF wrote:9652265929 -> BELGIUM
9099417118 -> BELGIUM
9099417146 -> BELGIUM
inb4 new unblock code is THEFORMERYUGOSLAVREPUBLICOFMACEDONIA.
where?

Image

are you kidding? not joking really. btw mad skillz.
codes posted here after this reposts in many forums out there - your jokes are not funny
 #7330  by EP_X0FF
 Sat Jul 16, 2011 5:13 pm
Post removed.

There is no need to post randomized pictures and self proclaimed unblock codes.
This is not a game and peoples outside who will try to enter fake codes will be unhappy at least.
 #7332  by EP_X0FF
 Sat Jul 16, 2011 5:27 pm
Another few killed.
Host name: xxxfilmaviforyou.info

Registrant Email: frolova.olga@gmail.com

Name Server:NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Name Server:NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM

Host name: filmforyouxxx.info

Name Server:NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Name Server:NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
 #7334  by mc0blck
 Sat Jul 16, 2011 6:57 pm
FilmForYouXxx.info has been blocked.
I have sent the request to block the redirectors:
hxxp://girid12va.info/gizfcciin.cgi?11
hxxp://bloti89da.info/gizaasciin.cgi?11
hxxp://dodol14da.info/gizffdiin.cgi?11
 #7343  by EP_X0FF
 Sun Jul 17, 2011 2:40 am
mc0blck wrote:FilmForYouXxx.info has been blocked.
I have sent the request to block the redirectors:
hxxp://girid12va.info/gizfcciin.cgi?11
hxxp://bloti89da.info/gizaasciin.cgi?11
hxxp://dodol14da.info/gizffdiin.cgi?11
All three killed.

kliop59ta.info - redirector -> dead
Hostname: kliop59ta.info
Registrant Email: antonanton1980@yahoo.com
Name Server: NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Name Server: NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
 #7356  by EP_X0FF
 Sun Jul 17, 2011 4:44 pm
Codes seems the same. Additionally submitted through MDL. Goodbye GoDaddy, hello REGRU.
domain: GIGPORNOFORFREE.RU
nserver: ns1.reg.ru.
nserver: ns2.reg.ru.
state: REGISTERED, DELEGATED, UNVERIFIED
person: Private Person
e-mail: abatinsan@gmail.com
registrar: REGRU-REG-RIPN
created: 2011.07.17
paid-till: 2012.07.17
source: TCI
http://www.reg.ru/whois/index?dname=GIGPORNOFORFREE.RU

http://www.reg.ru/support/abuse
 #7357  by nickvth2009
 Sun Jul 17, 2011 7:36 pm
Code: Select all
hxxp://gigpornoforfree.ru/1/video/porno-rolik1.avi.exe
hxxp://gigpornoforfree.ru/2/video/porno-rolik2.avi.exe
hxxp://gigpornoforfree.ru/3/video/porno-rolik3.avi.exe
hxxp://gigpornoforfree.ru/4/video/porno-rolik4.avi.exe
hxxp://gigpornoforfree.ru/6/video/porno-rolik6.avi.exe
hxxp://gigpornoforfree.ru/7/video/porno-rolik7.avi.exe
hxxp://gigpornoforfree.ru/8/video/porno-rolik8.avi.exe
hxxp://gigpornoforfree.ru/9/video/porno-rolik9.avi.exe
hxxp://gigpornoforfree.ru/10/video/porno-rolik10.avi.exe
Working as of 17/07/2011. Attached are the latest samples of this ransomware in a RAR-archive available for further analysis.

I am still wondering why there never is a porno-rolik5.avi.exe.
Attachments
pass: malware
(529.44 KiB) Downloaded 43 times
Last edited by EP_X0FF on Mon Jul 18, 2011 1:25 am, edited 1 time in total. Reason: archive reaupload with password
 #7358  by EP_X0FF
 Mon Jul 18, 2011 1:52 am
dokoler-w.info redirector has been killed.
Host name: dokoler-w.info
Registrant Email: hirmo09@ymail.com
Name Server:NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Name Server:NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
nickvth2009 wrote:I am still wondering why there never is a porno-rolik5.avi.exe.
Likely this was made specially to fool some crawlers with autodownloader feature.
nickvth2009 wrote:Working as of 17/07/2011
Please send abuse to REG.RU - as many peoples will start abusing - then better chances to get this sh*t down.
  • 1
  • 10
  • 11
  • 12
  • 13
  • 14
  • 17