0 Members and 1 Guest are viewing this topic.
hxxp://94.247.2.123/ ---> fake av scan craphxxp://avscanonline.com//install/ ---> spawns the .exe...
94.247.2.123/Install.exe
hxxp://avscanonline.com/promo/?tid=fin&aid=run1
hxxp://avscanonline.com/inst.php?tid=fin&aid=run1
File name: AV2009Setup.exeFile size: 162304 bytes MD5: 7509d6f880ef598f969e8f2908a78eef
94.247.2.123:80 - [avscanonline.com] Request: GET /src.php Response: 200 "OK" Request: GET /install/zip.zip Response: 200 "OK"
File name: zip.zipFile size: 162304 bytes MD5: 7509d6f880ef598f969e8f2908a78eef
hxxp://www.antivirus-protection.us/support