TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Why is the #2 torrent in DHT a 25Mb file named AF.dat?

40 点作者 lcrs超过 9 年前

12 条评论

eli超过 9 年前
Looks like this piece of Windows malware: <a href="https:&#x2F;&#x2F;malwr.com&#x2F;analysis&#x2F;NDI4YmUxNjM0ZTUwNDY0OWFhNjM3YzFiZmY1YmQ4ZDU&#x2F;" rel="nofollow">https:&#x2F;&#x2F;malwr.com&#x2F;analysis&#x2F;NDI4YmUxNjM0ZTUwNDY0OWFhNjM3YzFiZ...</a><p>It uses a data file called AF.dat and connect to bittorrent.
评论 #10608311 未加载
评论 #10608313 未加载
slater超过 9 年前
<a href="http:&#x2F;&#x2F;www.exterminate-it.com&#x2F;malpedia&#x2F;file&#x2F;af.dat" rel="nofollow">http:&#x2F;&#x2F;www.exterminate-it.com&#x2F;malpedia&#x2F;file&#x2F;af.dat</a> maybe?
评论 #10608275 未加载
jondumbau超过 9 年前
i&#x27;m pretty sure the most popular torrent in the DHT doesnt have 644 downloads in the last week.<p>this must be measuring downloads&#x2F;hits from btdigg.org (only), so someone is linking directly to it and relying on them to jump clients into the DHT perhaps?
评论 #10608342 未加载
lcrs超过 9 年前
For the curious, the magnet link is: magnet:?xt=urn:btih:a4a75d2e4095d457467777673e96cd331575b511&amp;dn=AF<p>file(1) has nothing to say about it but at a glance it doesn&#x27;t look like a uniform encrypted blob...
geoah超过 9 年前
If I was making a botnet I would use the DHT to download updates, settings etc. Not sure what else.
untog超过 9 年前
That whole list is kind of fascinating. Interesting to see the movies and shows that are particularly popular when it comes to piracy (Marvel, Marvel, Marvel...)
评论 #10608344 未加载
J_Darnley超过 9 年前
I&#x27;m going to guess at a password database of some kind, perhaps a &quot;rainbow table&quot;. There seem to be frequent occurrences of long strings of the alphabet. Byte value counts are almost equal.
评论 #10608301 未加载
brudgers超过 9 年前
Somewhat Related: <a href="http:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2015&#x2F;11&#x2F;16&#x2F;the-most-popular-curl-download-by-a-malware&#x2F;" rel="nofollow">http:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2015&#x2F;11&#x2F;16&#x2F;the-most-popular-curl-...</a><p>Discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10574011" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=10574011</a>
rverbitsky超过 9 年前
SHA256:459b05fe2dbd56cb0f31babdf722c40bd7ce061c7701fdbb56dfb382e8cd2371<p>File name: AF.dat<p>Detection ratio: 0 &#x2F; 55<p><a href="https:&#x2F;&#x2F;www.virustotal.com&#x2F;en&#x2F;file&#x2F;459b05fe2dbd56cb0f31babdf722c40bd7ce061c7701fdbb56dfb382e8cd2371&#x2F;analysis&#x2F;1448148451&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.virustotal.com&#x2F;en&#x2F;file&#x2F;459b05fe2dbd56cb0f31babdf...</a>
0x0超过 9 年前
There&#x27;s another curious entry too, &quot;x86&quot;, with filenames consisting of a random collection of unzipping .dlls and other weird stuff... Why would anyone want to torrent such a seemingly useless collection of random files?
评论 #10608407 未加载
mappu超过 9 年前
P2P update for a videogame?
oh_sigh超过 9 年前
Malware or child porn