A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #11329  by rkhunter
 Sat Jan 28, 2012 6:42 pm
markusg wrote:FakeSysdef (systemcheck):
mCl7w2YFKX8LGN.exe
MD5: f1ab6c2ab5fd 6d229e43f2f22911aa9f
McAfee -> Artemis!F1AB6C2AB5FD

BitDefender, F-Secure, GData -> Kazy.53751

Image
 #11431  by Xylitol
 Sat Feb 04, 2012 6:19 pm
FakeAV Landing package

Landing package, included some specials, like the SWF landing page.

Image
Attachments
pw: infected
(2.55 MiB) Downloaded 129 times
pw: infected
(5 MiB) Downloaded 127 times
 #11445  by Xylitol
 Sun Feb 05, 2012 6:21 pm
Smart Protection 2012 + Payment processing

Image

Image

Original: 2/42
https://www.virustotal.com/file/f515548 ... /analysis/

Unpack: 4/43
https://www.virustotal.com/file/37a0cea ... /analysis/
Attachments
pw: infected
(612.97 KiB) Downloaded 64 times
pw: infected
(114.2 KiB) Downloaded 74 times
 #11463  by rkhunter
 Mon Feb 06, 2012 8:54 am
4 Winwebsec - Security Shield

30931c85b1c86e2a3a62f05fecd0d88a
575E3F69C90C3AAC80B7105FBA5EE6B3
BB44C55F3F209FE249AA39A09F79755D
C8208F6C05D4276CA52AD3EFAD1366B1

FakeRean - SecurityMonitor

aaa6ce5c677b3c38cfb9f6d4e2d9f878
Attachments
pass:infected
(3.85 MiB) Downloaded 75 times
pass:infected
(1.09 MiB) Downloaded 65 times
 #11466  by Xylitol
 Mon Feb 06, 2012 4:01 pm
Attachments
infected
(2.51 MiB) Downloaded 84 times
infected
(2.51 MiB) Downloaded 69 times
infected
(2.65 MiB) Downloaded 82 times
 #11481  by rkhunter
 Tue Feb 07, 2012 12:23 pm
FakeSysdef

MD5: d1d0dc875b81bd1eb5404286104c00e6
13/43

FakeRean - Security Monitor

MD5: 7daa49fa0642ad007413cff953c1a8e0
16/41

Winwebsec - Security Shield

MD5: 3e9a80bc1b6ac9896767fe8840a8cbb1
MD5: 72672ecc501cfa83f2c662d12020b41c
Attachments
pass:infected
(569.7 KiB) Downloaded 54 times
pass:infected
(402.9 KiB) Downloaded 54 times
pass:infected
(3.85 MiB) Downloaded 60 times
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 46