0 Members and 2 Guests are viewing this topic.
zeus trojans (and other related malmare):Code: [Select]hxxp://bhostonline.com/loaderadv562.exemd5sum ===> afe0c42bd76163762ac798938046743afor:Code: [Select]hxxp://96.9.183.149/app21.binhxxp://174.36.237.84/app21s.bin incoming? Code: [Select]hxxp://bhostonline.com/loaderadv563.exemd5sum ===> 5b12cf0e2439517af6af8c8ba6b0f7b4forCode: [Select]hxxp://174.36.237.84/app21s.bin
hxxp://bhostonline.com/loaderadv562.exe
hxxp://96.9.183.149/app21.binhxxp://174.36.237.84/app21s.bin incoming?
hxxp://bhostonline.com/loaderadv563.exe
hxxp://174.36.237.84/app21s.bin
hxxp://camerinorestaurant.com/data_bak/booking.gif
hxxp://camerinorestaurant.com/data_bak/dinner.gif
hxxp://camerinorestaurant.com/data_bak/feedback.gif
hxxp://camerinorestaurant.com/data_bak/lunch.gif
hxxp://camerinorestaurant.com/data_bak/party.gif
hxxp://camerinorestaurant.com/data_bak/wine.gif
hxxp://kalowweb.de/1/images/css.png
hxxp://195.78.108.22/brgr/config.bin
hxxp://apsight.ru/123/valid.exe
http://yrots.ru/56/antirap.exe
IP:91.201.28.43
Code: [Select]http://yrots.ru/56/antirap.exemd5sum ===> 4e3e8d63bb90e09a34478e201202b255IP:91.201.28.43
Quote from: jackberri on February 23, 2010, 02:45:03 pmIP:91.201.28.43IP is :92.241.176.18
I don't know what it is, but it isn't Zeus.
Quote from: jackberri on February 23, 2010, 02:52:48 pmQuote from: jackberri on February 23, 2010, 02:45:03 pmIP:91.201.28.43IP is :92.241.176.18??
Quote from: SysAdMini on February 23, 2010, 03:17:30 pmQuote from: jackberri on February 23, 2010, 02:52:48 pmQuote from: jackberri on February 23, 2010, 02:45:03 pmIP:91.201.28.43IP is :92.241.176.18??The first ip (91.201.28.43) is wrong
You can modify your existing messages.
hxxp://rapidshare.com/files/354880881/powt
hxxp://googlanaliktics.com/QWEASDZXCV/gate.phphxxp://googlanaliktics.com/german/US/config.bin