![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
Our Honeypot caught this piece of malware that presents itself as some sort of poorly written app.
A few buttons here and there... My guess is that this app should be hidden, and that it would simulate user clicks, hence generating money for the scammers... Well, my PC froze on it, so I was able to capture it. It strongly reminds me of the old Porn Trojan. ![]() After a hard reboot, I noticed that my Desktop's wallpaper had been changed: ![]() It creates several files set to run at startup: ![]() Very soon after, it was porn galore on my machine. Better stay away from this! The file is somewhat detected on Virus Total: ![]() Jerome Segura Malware ID: *d75eca38884f44926ff51f84b0033be6.zip |
||
![]() |
| Thread Tools | |
| Display Modes | |
|
|