TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Why is the #2 torrent in DHT a 25Mb file named AF.dat?

40 pointsby lcrsover 9 years ago

12 comments

eliover 9 years ago
Looks like this piece of Windows malware: <a href="https:&#x2F;&#x2F;malwr.com&#x2F;analysis&#x2F;NDI4YmUxNjM0ZTUwNDY0OWFhNjM3YzFiZmY1YmQ4ZDU&#x2F;" rel="nofollow">https:&#x2F;&#x2F;malwr.com&#x2F;analysis&#x2F;NDI4YmUxNjM0ZTUwNDY0OWFhNjM3YzFiZ...</a><p>It uses a data file called AF.dat and connect to bittorrent.
评论 #10608311 未加载
评论 #10608313 未加载
slaterover 9 years ago
<a href="http:&#x2F;&#x2F;www.exterminate-it.com&#x2F;malpedia&#x2F;file&#x2F;af.dat" rel="nofollow">http:&#x2F;&#x2F;www.exterminate-it.com&#x2F;malpedia&#x2F;file&#x2F;af.dat</a> maybe?
评论 #10608275 未加载
jondumbauover 9 years ago
i&#x27;m pretty sure the most popular torrent in the DHT doesnt have 644 downloads in the last week.<p>this must be measuring downloads&#x2F;hits from btdigg.org (only), so someone is linking directly to it and relying on them to jump clients into the DHT perhaps?
评论 #10608342 未加载
lcrsover 9 years ago
For the curious, the magnet link is: magnet:?xt=urn:btih:a4a75d2e4095d457467777673e96cd331575b511&amp;dn=AF<p>file(1) has nothing to say about it but at a glance it doesn&#x27;t look like a uniform encrypted blob...
geoahover 9 years ago
If I was making a botnet I would use the DHT to download updates, settings etc. Not sure what else.
untogover 9 years ago
That whole list is kind of fascinating. Interesting to see the movies and shows that are particularly popular when it comes to piracy (Marvel, Marvel, Marvel...)
评论 #10608344 未加载
J_Darnleyover 9 years ago
I&#x27;m going to guess at a password database of some kind, perhaps a &quot;rainbow table&quot;. There seem to be frequent occurrences of long strings of the alphabet. Byte value counts are almost equal.
评论 #10608301 未加载
brudgersover 9 years ago
Somewhat Related: <a href="http:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2015&#x2F;11&#x2F;16&#x2F;the-most-popular-curl-download-by-a-malware&#x2F;" rel="nofollow">http:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2015&#x2F;11&#x2F;16&#x2F;the-most-popular-curl-...</a><p>Discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10574011" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10574011</a>
rverbitskyover 9 years ago
SHA256:459b05fe2dbd56cb0f31babdf722c40bd7ce061c7701fdbb56dfb382e8cd2371<p>File name: AF.dat<p>Detection ratio: 0 &#x2F; 55<p><a href="https:&#x2F;&#x2F;www.virustotal.com&#x2F;en&#x2F;file&#x2F;459b05fe2dbd56cb0f31babdf722c40bd7ce061c7701fdbb56dfb382e8cd2371&#x2F;analysis&#x2F;1448148451&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.virustotal.com&#x2F;en&#x2F;file&#x2F;459b05fe2dbd56cb0f31babdf...</a>
0x0over 9 years ago
There&#x27;s another curious entry too, &quot;x86&quot;, with filenames consisting of a random collection of unzipping .dlls and other weird stuff... Why would anyone want to torrent such a seemingly useless collection of random files?
评论 #10608407 未加载
mappuover 9 years ago
P2P update for a videogame?
oh_sighover 9 years ago
Malware or child porn