TIP: Click on subject to list as thread! ANSI
echo: alt-comp-anti-virus
to: ALL
from: VIRUS GUY
date: 2014-11-01 12:49:00
subject: Re: An Urgent Court Notic

Dustin wrote:
 
> > If anyone wants this sample, let me know.  I have no idea if
> > Dustin has been doing anything with the samples I've been posting.
> 
> I've been downloading them as I have the time and taking them apart,
> as I have the time. So far, it's general boring ####, trivial really.

If you've taken them apart, why don't you submit to VT the
random-named.exe file that these droppers create and link to in the
registry run keys?

Submit a few of them to VT and post the link, so we can see how well the
internal payload of these droppers is detected.

Here, try this one:

http://www.filedropper.com/copyofdocumentoct-31-2014-3

The anubis report in my previous post says it creates the file
dotsfhre.exe (although it's probably a random name so what-ever you come
up with would have a different name).
--- NewsGate v1.0 gamma 2
* Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)

SOURCE: echomail via QWK@docsplace.org

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.