Note: This site is distributing Rogue “Fake” Anti-Malware product. Do not visit, pay, or download the software discussed below.
The eAntivirusPro rogue we reported just yesterday has already updated its binary and new domain names have been created for it as well. The file has been added to the database in /lithium-malware/
Site: hxxp://e-antiviruspro.com/ and hxxp://eantivirus-payment.com
File: eAntivirusProInstaller.exe
VirusTotal: Result: 5/36 (13.89%)
File size: 2005796 bytes
MD5…: d6ab2ca11f4f2e6d457caf281a48fb7e
SHA1..: 6d39bc235eaadadddf8396941332518bea8fce1c
SHA256: be4611e5f5a2bf768deb506efff629aa2c15e8330d0295df4e325b306ae56da4
SHA512: 3eda0ba944717f68f11f14ae407762b7df121ffe985d5f01e1fce15d64043006
10e022d2000185176971c0d294ab7acf4197ad186c104b29243530a6d625478c
File: eAntivirusProInstaller.exe
VirusTotal: Result: 17/36 (47.22%)
File size: 576808 bytes
MD5…: 443b2dad596eba290e3e542867a1c91d
SHA1..: e8981359f475e71437a55d1751c9da3ebbfb3dbb
SHA256: d77e120cebfea826885690efcd48a457a9907a8a33606b5d59dee47ebdde103e
SHA512: a9c0bde9839ddc1431269f08f6355ca60a4478d78d20997aeb5f5abd3a272bcb
6089cce9166b9f3b7eb6bcd76bea7876c92485b88229c39e75cc75b8f20d56e4


