Showing posts with label supern0va. Show all posts
Showing posts with label supern0va. Show all posts

Tuesday, 5 June 2012

Backdoor.Bot.LameNova

When kids go into winlock business this is the result.


The malware come from a blackhole exploit kit
• dns: 1 ›› ip: 83.69.226.165 - adresse: ODOPODCPHUTGQERTS.CO.CC

Packed with VB, the original bin is also in VB...


Login:

Stats (before reset)


 Bots:

 Tasks:

 Loader:

Winlocker:

 Brute:

 Popup:

Settings:

 Options:

Files:

http://mmmoney1.com/new/
http://mmmoney1.com/panel/
• dns: 1 ›› ip: 178.73.210.237 - adresse: MMMONEY1.COM
C*\AC:\Users\iZER0x\Desktop\supern0va\france\Project1.vbp

Avast "SmokeLdr" fail