Author Topic: ZeuS? - wertupwan.com avalanche-digital.com copiluminune.com gurguroblakc.com  (Read 4832 times)

0 Members and 1 Guest are viewing this topic.

March 24, 2010, 04:35:39 pm
Read 4832 times

eoin.miller

  • Sr. Member

  • Offline
  • ****

  • 179
Found a bunch of different domains of what appears to be an infected client checking in once a day.

wertupwan.com
avalanche-digital.com
copiluminune.com
gurguroblakc.com
zdrasticeluka.com

All of these domains are hit with the following url appended:

/sox/exe.php?v=sox2b&sox=<10 digits>



To pull down some chunk of binary data, do this:
http://wertupwan.com/sox/exe.php

To pull down the potential config file or some sort of check in? Do this:
http://wertupwan.com/sox/exe.php?v=sox2b&sox=1359868210

March 24, 2010, 07:41:33 pm
Reply #1

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Definitely not Zeus.

Any ideas what it is ?

xor doesn't give any useful result.
Ruining the bad guy's day