| HTTP Requests: | [70.38.11.165] | |
| | http://70.38.11.165/admin/cgi-bin/get_domain.php?type=site | |
| | Content html: av-best.info | |
| | | |
| | http://70.38.11.165/admin/cgi-bin/get_domain.php?type=download | |
| | Content html: download.av-best.info | |
| | | |
| | [174.142.113.206] | |
| | hxxp://download.av-best.info/en/PE/2.exe | |
| | hxxp://download.av-best.info/en/PE/3.exe | |
| | hxxp://download.av-best.info/en/PE/en/PE/N1.CAB | |
| | hxxp://download.av-best.info/en/PE/en/PE/QWProtect.dll | |
| | hxxp://download.av-best.info/en/PE/en/PE/svchost.exe | |
| | | |
| | |
| | | |
| File info: | 2.exe | |
| File size | 53248 Bytes | |
| MD5 | 364f5d30dba520937f9f3b7979b389b1 | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA | |
| | Received on 03.28.2009 22:08:07 (CET) | |
| | 8/39 (20.52%) | |
| ThreatExpert: | Report | |
| Prevx: | Report | |
| | | |
| | |
| | | |
| File info: | 3.exe | |
| File size | 257536 Bytes | |
| MD5 | b7d14c7ea7844057efcfd1a41ddc530f | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA | |
| | Received on 03.28.2009 22:08:18 (CET) | |
| | 6/39 (15.39%) | |
| ThreatExpert: | Report | |
| | | |
| | |
| | | |
| File info: | AntiVirusInstaller.exe | |
| File size | 53278 Bytes | |
| MD5 | f8d38325d9570ce3320f04e9d5278466 | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA | |
| | Received on 03.28.2009 22:08:19 (CET) | |
| | 8/38 (21.06%) | |
| ThreatExpert: | Report | |
| | | |
| | |
| | | |
| File info: | N1.CAB | |
| File size | 504489 Bytes | |
| MD5 | c37aa0887be14b68381301e24ddaf8fb | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA / Trojan.Win32.Tibs | |
| | Received on 03.28.2009 22:08:51 (CET) | |
| | 5/38 (13.16%) | |
| | | |
| File info: | N1.exe | |
| File size | 527360 Bytes | |
| MD5 | 2d6a49219639d63428b91eb7647ce491 | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA / Trojan.Win32.Tibs | |
| | Received on 03.28.2009 22:09:09 (CET) | |
| | 5/38 (13.16%) | |
| ThreatExpert: | Report | |
| | | |
| | |
| | | |
| File info: | QWProtect.dll | |
| File size | 697856 Bytes | |
| MD5 | 1b6c35cb941eaa9f6325a449cb6770b0 | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA | |
| | Received on 03.28.2009 22:09:01 (CET) | |
| | 4/38 (10.53%) | |
| Prevx: | Report | |
| ThreatExpert: | Report | |
| | | |
| | |
| | | |
| File info: | svchost.exe | |
| File size | 80896 Bytes | |
| MD5 | c2613b801da4c8b6967d6da05c0443ed | |
| | | |
| VirusTotal: | Report Alias: Trojan.Win32/FakeXPA | |
| | Received on 03.28.2009 22:08:47 (CET) | |
| | 10/38 (26.32%) | |
| Prevx: | Report | |
| ThreatExpert: | Report | |