| Title |
Age |
Expires |
Views |
Comments |
Format |
| PoC of the IptabLeX windows version exists |
Oct 15th, 2014 |
Never |
3966 |
0 |
asm |
| Multiple China DDoS-er/backdoor payloads w/long shell cmd |
Oct 14th, 2014 |
Never |
6483 |
0 |
javascript |
| .IptabLes|x comeback frade8c.com:9162 |
Oct 13th, 2014 |
Never |
3141 |
0 |
bash |
| China Windows DDoSer w/USA CNC 23.91.3.246 |
Oct 5th, 2014 |
Never |
3558 |
0 |
asm |
| China Crooks White List snagged by MMD |
Sep 22nd, 2014 |
Never |
11219 |
0 |
text |
| RFI - Bossa |
Sep 15th, 2014 |
Never |
4187 |
0 |
text |
| Redundant Exploit Multi-Arc attack of BossaBot |
Sep 8th, 2014 |
Never |
3984 |
4 |
asm |
| Redundant dirs for RFI attack BossaBot #Malwaremustdie! |
Sep 8th, 2014 |
Never |
4794 |
0 |
asm |
| Chinese ELF: profild && keymap22 highlights.. |
Sep 2nd, 2014 |
Never |
3783 |
0 |
asm |
| China Elf Malware & Kernel Exploit Factory |
Sep 2nd, 2014 |
Never |
3411 |
0 |
javascript |
| Elf Remote DDoS Management Tools from China |
Jul 29th, 2014 |
Never |
11172 |
8 |
mmix |
| TAOBAO China ELF DDoS'er |
Jul 28th, 2014 |
Never |
12492 |
7 |
mmix |
| I'm a mu mu mu? Just a Crap! |
Jul 27th, 2014 |
Never |
3279 |
0 |
javascript |
| Installation of the Autostart Scripts | China DDoSer |
Jun 16th, 2014 |
Never |
3852 |
8 |
asm |
| Network Interface grabbed | China DDoSer |
Jun 16th, 2014 |
Never |
4696 |
4 |
asm |
| Server sensitive info's grabbed | China DDoSer |
Jun 16th, 2014 |
Never |
3716 |
4 |
asm |
| Updater function | China DDoS'er |
Jun 16th, 2014 |
Never |
3675 |
0 |
asm |
| Zbic Decompression Data | China DDoSer |
Jun 16th, 2014 |
Never |
3994 |
0 |
asm |
| DNS Flood Thread | China DDoSer |
Jun 16th, 2014 |
Never |
4283 |
0 |
asm |
| SYN Flood Thread | China DDoSer |
Jun 16th, 2014 |
Never |
4128 |
0 |
asm |
| Recent Incident of Linux ELF (LD_PRELOAD) libworker.so |
Jun 10th, 2014 |
Never |
4430 |
0 |
javascript |
| Case #8 - Journey to Abused FTP |
Jun 4th, 2014 |
Never |
3494 |
0 |
javascript |
| #MMD| xx(32|64)'s Symbol table | Elf analysis |
May 12th, 2014 |
Never |
8556 |
0 |
text |
| libworker.so ALIVE sites |
May 10th, 2014 |
Never |
4479 |
0 |
text |
| #MalwareMustDie! libworker.so malware library infected sites |
May 9th, 2014 |
Never |
5866 |
4 |
text |
| Fake Installer downloads PUP Backdoor |
May 2nd, 2014 |
Never |
3029 |
0 |
javascript |
| Mapping of PC Spambot April 2014 Upatre/GMO |
Apr 25th, 2014 |
Never |
5555 |
0 |
text |
| Kelihos Infection APRIL 18th 2014 / last 16h monitoring |
Apr 17th, 2014 |
Never |
3822 |
0 |
text |
| Kelihos Infection APRIL 17th 2014 / 12h |
Apr 17th, 2014 |
Never |
4459 |
0 |
text |
| April 14th ~ Recorded #SSH Bruter Attacker Top List |
Apr 15th, 2014 |
Never |
5846 |
0 |
text |
| American Express Phishing April 12 2014 |
Apr 12th, 2014 |
Never |
3819 |
0 |
javascript |
| List of recent SSH default user's login attacker's IPs |
Apr 10th, 2014 |
Never |
5604 |
0 |
text |
| Four full set of spam campaign gameovers |
Apr 5th, 2014 |
Never |
3380 |
0 |
javascript |
| UPATRE ZZP of ZGMO campaign via Spam attachment |
Mar 26th, 2014 |
Never |
3265 |
0 |
javascript |
| Upatre downloading Zeus Gameover (GMO) |
Mar 26th, 2014 |
Never |
3200 |
0 |
javascript |
| Nuclear bai bai |
Mar 22nd, 2014 |
Never |
3137 |
0 |
text |
| Nuclear RU part 3 |
Mar 22nd, 2014 |
Never |
3299 |
0 |
text |
| Nuclear RU part 2 |
Mar 22nd, 2014 |
Never |
3082 |
0 |
text |
| Nuclear OVH & DB |
Mar 22nd, 2014 |
Never |
3299 |
0 |
text |
| Nuclear RU part 1 |
Mar 18th, 2014 |
Never |
3510 |
0 |
text |
| GoogleCode RECENT Malware Abuse list (only).. |
Mar 16th, 2014 |
Never |
3132 |
0 |
text |
| Trojan bankings served in Google Code |
Mar 16th, 2014 |
Never |
3624 |
0 |
text |
| #MalwareMustDie! Recent Upatre downloads encrypted Zbot/GMO |
Mar 14th, 2014 |
Never |
3971 |
0 |
javascript |
| Taiwan Kelihos infection Log |
Mar 12th, 2014 |
Never |
3329 |
0 |
text |
| "Wattering" RAT HAVEX INFECTION VERDICT |
Mar 10th, 2014 |
Never |
35223 |
0 |
java |
| Logger, Backdoor SMTP, Downloader from China |
Mar 8th, 2014 |
Never |
3157 |
0 |
javascript |
| Citadel PoC |
Mar 3rd, 2014 |
Never |
3455 |
0 |
text |
| When Traffer and Infector crooks work together |
Mar 2nd, 2014 |
Never |
3272 |
0 |
javascript |
| Amazon/Google abuse: |
Feb 27th, 2014 |
Never |
4103 |
0 |
php |
| Tango Down Check: Nuclear follow up |
Feb 27th, 2014 |
Never |
3522 |
0 |
javascript |
| Kuluoz Reversing "QUICK" Notes |
Feb 14th, 2014 |
Never |
3160 |
0 |
asm |
| Hacked Site with the US IRC Server'S Perl ShellBot |
Feb 12th, 2014 |
Never |
5088 |
0 |
perl |
| #MalwareMustDie - Decoding Kelihos Simda download FakeAV |
Feb 10th, 2014 |
Never |
4181 |
0 |
javascript |
| Have a "xmlrpc.php" & GooDork for Breakfast |
Feb 6th, 2014 |
Never |
3467 |
0 |
xml |
| Phishing AMEX Script (neutralized) |
Feb 5th, 2014 |
Never |
8044 |
13 |
javascript |
| A wtf suspicious TDS.. |
Jan 27th, 2014 |
Never |
3349 |
0 |
text |
| Forensics Data - PowerLocker $str(MemDumps) |
Jan 17th, 2014 |
Never |
3014 |
0 |
text |
| #Nuclear EK infection domain chains.. |
Jan 16th, 2014 |
Never |
3194 |
0 |
text |
| #Simda Payload callbacks Traffic (origin: Kelihos Botnet) |
Jan 16th, 2014 |
Never |
2958 |
0 |
text |
| #Cridex Trojan Infection IP Source per Jan 17 2014 |
Jan 16th, 2014 |
Never |
4866 |
0 |
text |
| Trojan/PWS Win32/Cridex RETURNS |
Jan 15th, 2014 |
Never |
3411 |
9 |
text |
| FUD Kelihos |
Jan 14th, 2014 |
Never |
2887 |
0 |
text |
| Kuluoz - Latest Version | Binary DUMP Analysis |
Jan 14th, 2014 |
Never |
11685 |
10 |
text |
| Shadow Logger Registry Trace in Memory Dump (forensics) |
Jan 2nd, 2014 |
Never |
11922 |
5 |
text |
| Shadow Logger Process Record |
Jan 2nd, 2014 |
Never |
3176 |
0 |
text |
| Shadow Logger PE Strings |
Jan 2nd, 2014 |
Never |
4085 |
0 |
text |
| #MMD Tango Down 311/2,989 |
Dec 2nd, 2013 |
Never |
2966 |
0 |
text |
| SURBL CryptoLocker |
Nov 13th, 2013 |
Never |
4221 |
0 |
text |
| BOTNET KULUOZ/ ASPROX BACK WITH NEW EXCYPTION |
Nov 12th, 2013 |
Never |
3191 |
0 |
text |
| Nuclear EK Landing Page in Japan serves Citadel |
Nov 8th, 2013 |
Never |
2825 |
0 |
javascript |
| FaceBook IM & Web Driven Facebook Trojan with DGA Downloader |
Nov 7th, 2013 |
Never |
9088 |
0 |
javascript |
| #MalwareMustDie - MORE Zbot Trojans UP and ALIVE |
Nov 5th, 2013 |
Never |
2821 |
0 |
text |
| #MalwareMustDie! ZEUS links that needed to nuke down: |
Nov 5th, 2013 |
Never |
2958 |
0 |
text |
| #MalwareMustDie - #PoC of HOW Kelihos Infecting via RedKit |
Nov 5th, 2013 |
Never |
3029 |
0 |
text |
| #MalwareMustDie! Zombie PCs used by Botnet & Malware |
Nov 4th, 2013 |
Never |
3185 |
0 |
text |
| The cracking of 709days used by RunForrestRun DGA |
Nov 2nd, 2013 |
Never |
3354 |
0 |
javascript |
| DGA (PseudoRandom Domain) RunForrestRun, Decoding 1st Step |
Nov 2nd, 2013 |
Never |
3371 |
4 |
javascript |
| #MalwareMustDie! Zeus Variant Payloads |
Oct 30th, 2013 |
Never |
3102 |
0 |
text |
| #malwareMustDie - The #w00tw00t Attack log |
Oct 20th, 2013 |
Never |
15977 |
2 |
apache |
| YAra rule: Citadel |
Oct 15th, 2013 |
Never |
3050 |
0 |
text |
| #MalwareMustDie! Peeking at Recent Blackhole via IncomingFAX |
Sep 19th, 2013 |
Never |
3030 |
0 |
text |
| KELIHOS MALWARE DETECTION RATIO - BY AV SCANNING AT VT |
Aug 31st, 2013 |
Never |
3052 |
8 |
text |
| OP CleanUp Kelihos, CN: Polandia/Polska |
Aug 13th, 2013 |
Never |
3040 |
0 |
text |
| OP CleanUp Kelihos, CN: Japan |
Aug 13th, 2013 |
Never |
3488 |
0 |
text |
| OP CleanUp Kelihos, CN: Romania |
Aug 13th, 2013 |
Never |
3007 |
0 |
text |
| OP CleanUp Kelihos, CN: Russia |
Aug 13th, 2013 |
Never |
3607 |
0 |
text |
| OP CleanUp Kelihos, CN: USA |
Aug 13th, 2013 |
Never |
4175 |
0 |
text |
| OP CleanUp Kelihos, CN: India |
Aug 13th, 2013 |
Never |
2946 |
0 |
text |
| #MalwareMustDie - Kelihos Botnet IP Aug 11, 2013 take 1 |
Aug 11th, 2013 |
Never |
39541 |
0 |
text |
| #MalwareMustDie - Kelihos Botnet IP AUg 11, 2013 |
Aug 11th, 2013 |
Never |
3186 |
0 |
text |
| #MalwareMustDie! Kelihos BotNet IP TOTAL Aug 10th 2013 |
Aug 10th, 2013 |
Never |
8295 |
0 |
text |
| Chekcing Latest Kelihos .COM domains sinkhole status |
Aug 10th, 2013 |
Never |
2901 |
0 |
text |
| #MalwareMustDie! Last milking today, sorted unique : 1307ip |
Aug 10th, 2013 |
Never |
2775 |
0 |
text |
| Kelihos Hit US IP.. |
Aug 9th, 2013 |
Never |
3140 |
0 |
text |
| #MalwareMustDie! Kelihos BotNet IP-2 Aug 10th 2013 |
Aug 9th, 2013 |
Never |
4579 |
0 |
text |
| #MalwareMustDie - Log of Report of ANOTHER 2 Kelihos domains |
Aug 9th, 2013 |
Never |
2749 |
0 |
text |
| #MalwareMustDie - Log of Report of 2 more Kelihos domains |
Aug 9th, 2013 |
Never |
2759 |
0 |
text |
| #MalwareMustDie! Kelihos BotNet IP Aug 10th 2013 |
Aug 9th, 2013 |
Never |
9122 |
0 |
text |
| #MalwareMustDie - Log of Report of 8 more Kelihos domains |
Aug 9th, 2013 |
Never |
2980 |
0 |
text |