downloaded binary

CastleCops -> Web Malware Links

Author: Barracuda1 PostPosted: Thu Jun 26, 2008 6:25 pm    Post subject: downloaded binary

While testing ColonialBankECERTv04510.exe, it downloaded:

hxxp://66.199.248.197/classes3/content/uploads/iiowk.exe

which has poor (heuristic only) coverage. It contacted mukili-com23.name and sex-porti.net periodically.

Author: tetak PostPosted: Thu Jun 26, 2008 10:20 pm    Post subject:

Thanks for posting the link. I've added the file to the malware listserv.

CastleCops Link/p1101168-MD5_3424b8af74b0d63fd9b5ce3ab30d2934_iiowk_exe.html



CastleCops -> Web Malware Links

All times are GMT

Page 1 of 1


Powered by phpBB © 2001 phpBB Group