View Full Version : if WinRAR is in NullsoftInstaller, then...
evaluator
June 7th, 2010, 08:46
if WinRAR is in NullsoftInstaller, then... should be malware

ehm, malware hunt is so easy..
torrent:
magnet:?xt=urn:btih:PA7GLNF6CKG2YK7RM6BB7GOENR2AWQOD
evaluator
June 7th, 2010, 09:02
extract from Resource.
passw:
malware
esther
June 7th, 2010, 10:58
Quote:
[Originally Posted by evaluator;86749]extract from Resource.
passw:
malware |
not detected on Avira,might be interesting

Woodmann
June 7th, 2010, 18:42
Howdy,
Comodo and Clamwin dont have a problem with it BUT,
Why is it trying to visit this IP 64.79.79.227 ?
Woodmann
Kayaker
June 8th, 2010, 00:25
Man, this thing's full of all kinds of shite. If you were to trace through it you'd see the strings decrypting and there's a reference to megabyet.net, which is a free web hosting site, IP 64.79.79.227. Looks for /patch2/update.php, 2NKstep1-auto and a bunch of other crap.
Not too interesting by itself I think, but might be if allowed to download the rest of its payload. There's a DeviceIoControl call that might expose an interesting driver somewhere in the mix...
evaluator
June 8th, 2010, 02:18
nah, it collects info about your PC.
DevicedIOControl used for get HD-serial.. NetCard...
Powered by vBulletin® Version 4.2.2 Copyright © 2018 vBulletin Solutions, Inc. All rights reserved.