A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #26745  by Xylitol
 Wed Sep 16, 2015 7:30 pm
From an existing campaign i believe, it got found by Kafeine with a pony and andromeda in parallel.
Variant of the dropper in attachement.

• dns: 1 ›› ip: 95.213.186.51 - adress: GETUPTATESRV.EU

MalScore fail
Image
VT: 26/57 (13 hours ago was 4/55)
Attachments
 #27226  by Xylitol
 Sat Nov 14, 2015 10:06 am
Not a fakeAV just a downloader but trick user with a splash screen and download/install a bunch of crap in background and drop shortcuts.
Image
VT: 3/55 - malwr
Attachments