tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5765
|
Posted: Fri Jan 25, 2008 1:39 am Post subject: [MIRT#7547] Trojan-PSW on 60.190.118.15 AS4134 |
|
|
Malware Alert Full Report: /Trojan_PSW_malware7547.html Changed status to confirmed malware.IP Converted: 60.190.118.15
dword = 1019115023
hex1 = 0x3cbe760f
hex2 = 0x3c.0xbe.0x76.0xf
oct = 074.0276.0166.017
1.exe at this location is malware called Trojan-PSW.Win32.OnLineGames.pgn (Kaspersky)
The files 2.exe 3.exe 4.exe 5.exe all the way up to and including 26.exe at this location are all malware by various names.View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134
"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"<br />
Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
| Quote: | | http://60.190.118.15/new/1.exe |
|
|