Dating bigmir net updating network architecture

by  |  21-Jan-2020 11:16

Alexey Prokopenko registered the domain on the 03rd of August 2013 via … The payload’s MD5 hash 66bde60fd4aba61aee7e3498a1622b09 is associated with different filenames according to Virus Total.

PWS: Win32/Fareit will first attempt to post data as seen below. Since the domain can’t be resolved (suspended), the binary tries to find out if the network is down or not by performing a few lookups. This payload is not only associated to this malvertisement incident, the same binary was delivered via the auto-update feature in Sendori it seems (according to the VT filenames).

