Edi wrote:Isn't the dropper MD5 b4ac366e24204d821376653279cbad8 (232448 bytes)? I just can't find out whats the encryption routine. Anyone know?this is not the dropper, just a pnf file, where file are being stored in crypted format.
the dropper, is stored in a word doc. currently only very few people have this dropper and this won't change until microsoft has released an official patch. and even then i doubt it will be released to the public, because it would reveal the company that was targeted by this attack.