Author Topic: hs.3-151.zlkon.lv -(94.247.3.151)  (Read 30952 times)

0 Members and 1 Guest are viewing this topic.

April 14, 2009, 06:09:52 am
Reply #15

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 17, 2009, 04:47:05 am
Reply #16

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
Exploits:

Code: [Select]
hxxp://liteautogreatest.cn

Wepawet

Code: [Select]
hxxp://liteautogreatest.cn/cache/readme.pdf

Wepawet for readme.pdf
VirusTotal for readme.pdf - 5/40 (12.5%)

Code: [Select]
hxxp://liteautogreatest.cn/cache/flash.swf

VirusTotal for flash.swf - 4/39 (10.26%)

Code: [Select]
hxxp://liteautogreatest.cn/load.php?id=5

VirusTotal for load.exe - 12/40 (30%)
Anubis report for load.exe

Botnet C&C: 78.109.29.112

Quote
78.109.29.112:80
Request: GET /new/controller.php?action=bot&entity_list=&uid=1&first=1&guid=1824245000&rnd=981633 
Response: 200 "OK" 

April 19, 2009, 05:51:13 pm
Reply #17

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
PDF/Flash exploits
Code: [Select]
liteupyourride.cn
Code: [Select]
liteupyourride.cn/cache/readme.pdfhttp://www.virustotal.com/analisis/46adc25de221146ea1a2458c97602518 6/40
http://wepawet.cs.ucsb.edu/view.php?hash=4925255f3716377f7fcb7c9bfb038795&t=1240163655&type=js

Code: [Select]
liteupyourride.cn/cache/flash.swfhttp://www.virustotal.com/analisis/470c291cdcc653d9fa59067bcd0e2549 0/40

readme.pdf redirects to
Code: [Select]
litehitscar.cn/load.php?id=5
flash.swf redirects to
Code: [Select]
autobestwestern.cn/load.php?id=7&0
Ruining the bad guy's day

April 19, 2009, 06:04:34 pm
Reply #18

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 19, 2009, 06:49:09 pm
Reply #19

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
autobestwestern.cn/load.php?id=7&0
finditbig.cn/load.php?id=0
lotwageronline.cn/load.php?id=0
bestfindaloan.cn/load.php?id=0
casinobigtop.cn/load.php?id=0
findbigthinker.cn/load.php?id=0
nanotopdiscover.cn/load.php?id=0
http://www.virustotal.com/analisis/07cbfa835cf93c2f866d7e7fa18eabf5 10/40
Ruining the bad guy's day

April 21, 2009, 06:07:44 pm
Reply #20

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 24, 2009, 12:24:26 pm
Reply #21

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 26, 2009, 06:51:42 am
Reply #22

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

April 27, 2009, 02:52:55 am
Reply #23

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

April 27, 2009, 07:14:07 pm
Reply #24

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day