Advertisement
Neonprimetime

Ransom.c!env rejlmv.hopto.org

Feb 10th, 2015
383
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.70 KB | None | 0 0
  1. Ransom.c!env
  2. Reported by neonprimetime security
  3. http://neonprimetime.blogspot.com
  4.  
  5. ****
  6.  
  7. McAfee alert seen seconds are the URL get request below
  8.  
  9. C:\Users\xxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b981a992.exe
  10. Ransom.c!env
  11.  
  12. ****
  13. Suspicious URL Get Request
  14.  
  15. GET /j_86zfsy/7a49d85b1f66850e02570d025103025304580302505a055902555058060f5101;150000;152 HTTP/1.1
  16. Accept: */*
  17. Accept-Language: en-SG
  18. Referer: http://rejlmv.hopto.org/cssvejklrus2pzktoh5cbr8nbpef71jv5w4jfvp223tjd9h
  19. x-flash-version: 15,0,0,152
  20. Accept-Encoding: gzip, deflate
  21. User-Agent: Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
  22. Host: rejlmv.hopto.org
  23. Connection: Keep-Alive
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement