http://scan.antispyware-free-scanner.com/ looks like this:
It pushes an installer that is hosted at
http://files.as-pro-xp-download.com/. This installer downloads the actual rogue application executable.
And, finally the rogue application looks like this!

Detections for the installer and rogue executable are not very good at this moment. VirusTotal scan results of the installer and rogue application executable can be found here and here respectively.
0 comments:
Post a Comment