Subject
Make your life better with us. We are looking for staff
Body
Retoneva Ltd. recruits agents for business relations ....
The malicious Flash file contains a link to retoneva.com/?gzsucorqqbbmvcbordw (404 error) and is using ActionScript 3.0 packages.
Below is a general overview of it's construction.
The 3 text fields contain some very strange strings if you ask me ...
Textbox acts as a "listbox" and contains line1 & line2 & line3.
A treeview is sometimes better to show depencies.
A similar incident was reported by Alex from Sunbelt. Reference.
______________________________
File details and scan.
Filename: kasopjngqsz1.swf
File size: 3058 bytes
MD5...: 68bf96f8d78f236d9e6e23ccdeeec832
SHA1..: 5bae8a12037db13cbfb56a42b904d18beabee28b
SHA256: 435bae7c7591ced74d0b43b7fdb793d07405512c5f00b538174988b6bb6f9792
PEiD..: -
PEInfo: -
packers (Kaspersky): Swf2Swc
scan result: 0/35 (0%)







