bookwormsbiorhythm.top(Smoke Loader + TeamViewer Rat)

Smoke Loader is used to infect with team viewer rat 4.34-2mb size of executable.

Domains :

bookwormsbiorhythm.top
charlesadvanced.top

Ip’s :

185.81.113.86:80
200.7.98.161:80
104.16.41.2:443
217.23.11.14:80
23.51.123.27:80
92.122.201.2:443
92.122.122.136:80

Samples :

hxxp://185.81.113.106/ital2.exe
hxxp://200.7.105.4/ital1.exe
hxxp://200.7.98.161/myonly3d.exe
hxxp://theplatonicsolid.com/cftmon.exe
hxxp://memorywedge.net/11/cftmon.exe

hxp://memorywedge.net/11/1.zip :
The whole archive(shells,emailer,samples), his gmail adress to.This guy looks like big russki hecker.

Categories: Uncategorized