Author Topic: Honeypots forgotten Links...  (Read 11855 times)

0 Members and 1 Guest are viewing this topic.

April 21, 2012, 12:01:46 pm
Reply #60

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236






April 22, 2012, 10:00:18 am
Reply #66

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://www.regnow.com/softsell/visitor.cgi?affiliate=13326&action=site&vendor=8052&ref=http://www.awem.com/files/pacboy.exe
Suspicious

http://128.111.48.236/view.php?hash=a56767818bd4addadf69ac8ac4eca2fb&t=1335088515&type=js





April 23, 2012, 07:40:38 am
Reply #71

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://minecraft.filecook.com/
redirects ---> to

Code: [Select]
http://download.filecook.com/download3.php?n=MineCraft_v1_0.exe
TR/Dldr.NoAsk.A
Win32:PUP-gen [PUP]
unknown virus Win32/DH.FF8801A5{00000000-00000020-00804002-00000000}
TrojanDownloader.Generic.ujc
Artemis!90DA2A390057
Win32/TrojanDownloader.Agent.REE
Posible_Worm32
suspected of Trojan.Downloader.gen.h
Trojan.Win32.Generic.pak!cobra


http://128.111.48.236/view.php?hash=423978e5f1a76e4cd7904478cbdddf04&t=1335165961&type=js
http://anubis.iseclab.org/?action=result&task_id=1d2dfb0f53a0d1ba4112afbb0b06cbc5a
https://www.virustotal.com/url/2d02070da1fef3c1ad275d14438cb187fbc0ba8a39008df79b5801279d25d30b/analysis/1335166008/
https://www.virustotal.com/url/637cc8b01e12a8101bda9c57f296b04c2e9e3baf56e60943b75d8cf01ddbb11b/analysis/1335166096/
https://www.virustotal.com/file/255aead7d27bb8fa658d7ab3f3a5660856c719b7700a0cce22a9fd387a7ed354/analysis/1335166322/

April 25, 2012, 12:37:06 pm
Reply #72

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236

April 25, 2012, 12:54:50 pm
Reply #73

dlipman

  • Special Access
  • Full Member

  • Offline
  • *

  • 44
    • Multi-AV Scanning Tool
Code: [Select]
www.axito.com/Download/wrar380nl.exe

WinRAR from 2008, False Positives

Code: [Select]
www.axito.com/Download/7z465.exe

7-Zip 4.65 from 2009,  False Positives

Code: [Select]
http://www.axito.com/Download/PSsetup.exe

This too appears to be a False Positive for a possible PostScript print driver or some other form.

April 26, 2012, 10:10:52 am
Reply #74

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://www.2shared.com/file/10073685/81fbf320/AionKtz_125English.html
http://dc104.2shared.com/download/1LAUZdY8/AionKtz_125English.rar?tsid=20120426-092139-995279e7

TR/PSW.Magania.clza
PSW.OnlineGames3.BDHX
Trojan.Generic.3283892


https://www.virustotal.com/file/62be6a141f487435647165ae94724d8c2b391fdc922565002214c1f5c109792e/analysis/1335432391/

Code: [Select]
http://www.aionktzbot.com/files/AionKtz_126English.rar
http://www.2shared.com/file/10541005/f0cb2672/AionKtz_126English.html

Win32:Malware-gen
HEUR:Trojan.Win32.Generic
VirTool:Win32/Obfuscator.XZ

https://www.virustotal.com/url/cc234718262f5d6e01e8e5ec6fbde52f1a8b3589c49e77aa2b99e261d24ee7bb/analysis/1335432561/
https://www.virustotal.com/file/76596f36f5676d4c0179ba19c8aa4e3f17aff7b4bdba8ac89d7c03f836926ff3/analysis/1335432564/

Code: [Select]
http://www.2shared.com/file/10296534/d2684b7c/AionKtz_RURussia102rar.html
PSW.OnlineGames3.BDHX
Artemis!F7FB32F5F9C7
Trojan/Magania.clza


https://www.virustotal.com/file/4c362d9d68229e67f214a09ef5bf9405e485533645289755e6ba5e6b44cfc5eb/analysis/1335433853/

Code: [Select]
http://www.aionktzbot.com/files/AionKtz_126French.rar
PSW.OnlineGames3.BDHX
Backdoor.Win32.Agent.bfop
VirTool:Win32/Obfuscator.XZ


https://www.virustotal.com/url/17d7f0902420b72089212fa98d6d010e07145c0a204e6b0619d3ea65d7904a80/analysis/1335434111/
https://www.virustotal.com/file/9316ef38d2250bf931496aa2977d82be1745abb746de15abf99d6652bb54d8ed/analysis/1335434114/

Code: [Select]
http://www.aionktzbot.com/files/AionKtz_126Swedish.rar
HEUR:Trojan.Win32.Generic
Trojan.Generic.3283892
Trojan/Magania.clza


https://www.virustotal.com/url/c0d9bc330bfcbaaf51a020478cb920248a6dc0d2d86f8ed8dc3817e60a9026bc/analysis/1335434465/
https://www.virustotal.com/file/3d34742828931f39b174c78b139dc46ff4a83cbb9287a4fd76f9cb7b10d6f92f/analysis/1335434470/