Alert: the website of "The State Archive of the Kiev region" (dako.[gov].ua) currently is being used to spread malware.
cc @krasnomovets
-
Show this thread
-
Replying to @malwrhunterteam @krasnomovets
Infected at least a day ago. Yesterday it gave (SmokeLoader): https://www.virustotal.com/en/file/bdec28fe61f7c5343f0c1bca8ec59ed7edc0e8ba75ead57ee670592d74116f46/analysis/1504041848/ … Right now (not checked yet): https://www.virustotal.com/en/file/a026a30bbb1111843e866b5237f7fb4735d4a9a2e4116967ab1afebe42671c7a/analysis/1504097415/ …pic.twitter.com/RyG6rW5Baa
2 replies 4 retweets 7 likes -
Replying to @malwrhunterteam @krasnomovets
Yesterday the Smoke sample loaded this: https://www.virustotal.com/en/file/ceed8ecda3b215601c85db21d7fb69aae8e82cc43a9608ff43c62b11535e3a5c/analysis/1504029691/ … cc
@JAMESWT_MHT@Antelox@James_inthe_box2 replies 2 retweets 3 likes -
Replying to @malwrhunterteam @krasnomovets and2 replies 0 retweets 4 likes
Indeed, nice catch Antelox! Drops a copy of itself as usual to user's %appdata%\roaming folder, eg: https://virustotal.com/#/file/069720a6ecc3c410a9696333dc2459da74f2e3ef3a3fd2b2940df1d7068b36b9/detection …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.