Author Topic: Honeypots forgotten Links...  (Read 11847 times)

0 Members and 2 Guests are viewing this topic.

May 17, 2012, 12:01:14 pm
Reply #90

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
https://64.16.211.20/dl/software/ipeye.exe

May 17, 2012, 12:45:49 pm
Reply #91

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
https://64.16.211.20/dl/software/ipeye.exe

To my PM Buddy:
No matter, a IP Scanner is MALWARE, nomatter which way you turn it. The file is classified for over 6 Years as Malware to leading AVScanners. There would have been enough time to classify it as f/p or whatsoever.

BTW, Cain & Abel, is also classified by Paretologic as Malware since 2010. See

http://www.malwareblacklist.com/searchClearingHouse.php?search=net-security.org

So:first look then think, next time you write PMs. THX. Cheers.

May 17, 2012, 02:04:45 pm
Reply #92

dlipman

  • Special Access
  • Full Member

  • Offline
  • *

  • 44
    • Multi-AV Scanning Tool
IP Port Scanners are grey-ware.  You found it on a security site hosting it for use by security professionals.

They are tools that have legitimate uses but may be used maliciously.  Thus they are grey area software and not really malware and may be classified as a PUP, Tool, Hacktool, etc.

If you had a downloader or a dropper that included an IP Port Scanner and you showed how it was being used maliciously in a particular process then that would be beneficial because you would be passing on that information of the tool being used in a particular technique. 

Are you going to tell me those old archivers you posted about in late April were malware ? 
Do you remember your posting the "WinRAR from 2008" and "7-Zip 4.65 from 2009" ?
How about those UPX compressed files ?


There is so much REAL malware out there; Ransom, Bobax, ZeroAccess, FakeAlert, TDSS family, Cridex, Exploit files/code pages, the various bots (Zbot, Rbot, Qakbot, GAObot, SDbot, etc). Cutwail, Mebroot, Bredolab, Hiloti, Randex, Harniq, Sinowal, etc, etc.

Post URLs to samples of the above and not grey-ware tools, false positives and at-best heuristics.

May 17, 2012, 02:33:53 pm
Reply #93

EP_X0FF

  • Special Members
  • Hero Member

  • Offline
  • *

  • 254
    • KernelMode.info
Code: [Select]
https://64.16.211.20/dl/software/ipeye.exe

To my PM Buddy:
No matter, a IP Scanner is MALWARE, nomatter which way you turn it. The file is classified for over 6 Years as Malware to leading AVScanners. There would have been enough time to classify it as f/p or whatsoever.

BTW, Cain & Abel, is also classified by Paretologic as Malware since 2010. See

http://www.malwareblacklist.com/searchClearingHouse.php?search=net-security.org

So:first look then think, next time you write PMs. THX. Cheers.

This is not malware. Maximum as it can be rated - "Hacktool" or PUA. But itself this tool is not malicious at all. You are wasting your and others time posting complete junk. If you disagree then give us please a *analysis* (not a result from fake av's considering everything as malware and skipping any real malware) to prove this file is malicious software.

May 19, 2012, 01:04:14 pm
Reply #94

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://8.153.cc/0705/Password%20Agent.rar
Trojan.Win32.MicroFake.ba

May 19, 2012, 01:59:12 pm
Reply #95

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://205.196.121.158/qhm92or2r8qg/y5m992hvmfy6myx/Zynga.exe
Trojan.Win32.Jorik.Llac.ash

May 20, 2012, 03:45:46 pm
Reply #96

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
i2307.in/2012/04/08/page/2/
links from/to

Code: [Select]
http://install.secure-softwaremanager.com/installer/zcdownload/c061a9ad328c637a2d044ef0daf638c86cefde9c8845b33c39e219fa4500e8d7e1589a5693:70522e5fd1a61b0f77a4cb83a0f1ecd3?ld=1
redirects to:

Code: [Select]
http://a.cryingbabee.com/IC/GPLAppBundler78/37280/1/9ff58cab-2959-41a2-b777-c4f7c3442ece/MPLSetup.exe
code is suspicious/malicious

not-a-virus:AdWare.Win32

May 21, 2012, 05:29:27 pm
Reply #97

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://www.regeasycleaner.com/RegistryEasy_Lite.exe
Risky

May 23, 2012, 02:08:08 pm
Reply #98

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://premiumstorage.info/v54
Suspicious Adware

May 24, 2012, 11:40:46 am
Reply #99

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://rivia.net/Products/Friendzee/Friendzee_Setup.exe
Potential Malware

May 24, 2012, 03:11:32 pm
Reply #100

EP_X0FF

  • Special Members
  • Hero Member

  • Offline
  • *

  • 254
    • KernelMode.info
Code: [Select]
http://rivia.net/Products/Friendzee/Friendzee_Setup.exe
Potential Malware


Your analysis to prove "potentiality"? Maybe you will mail your Kaspersky guy for confirmation?

Actually this is installer for Windows Mobile 5 application, dated back to 2007(!).

http://rivia.net/Friendzee.aspx

May 24, 2012, 03:35:54 pm
Reply #101

dlipman

  • Special Access
  • Full Member

  • Offline
  • *

  • 44
    • Multi-AV Scanning Tool
Your analysis to prove "potentiality"? Maybe you will mail your Kaspersky guy for confirmation?

Actually this is installer for Windows Mobile 5 application, dated back to 2007(!).

http://rivia.net/Friendzee.aspx


May 25, 2012, 01:20:23 pm
Reply #102

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://dubno-rada.rv.ua/components/com_jcomments/libraries/joomlatune/ajax.js
Trojan Script

May 25, 2012, 06:22:47 pm
Reply #103

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
http://download-soft99.info/engine/classes/js/dle_js.js

http://download-soft99.info/engine/classes/js/jquery.js

http://download-soft99.info/engine/classes/js/jqueryui.js

Trojan Scripts

May 26, 2012, 10:34:06 am
Reply #104

GaryDee

  • Sr. Member

  • Offline
  • ****

  • 236
Code: [Select]
adideco.es/wp-includes/js/l10n.js?ver=20101110
Trojan JS