Cycle Calculator for Women 4.3.exe
http://www.virustotal.com/file-scan/rep ... 1294851668
http://www.virustotal.com/file-scan/rep ... 1294851668
Attachments
(386.46 KiB) Downloaded 62 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:Cycle Calculator for Women 4.3.exeDot net container working as muldrop (spawns IE copy with injected CyberGate v1.07.5 RAT dll inside), additionally drops this
http://www.virustotal.com/file-scan/rep ... 1294851668
EX! wrote:Hello!If you look at memory region dump you attached you will find PE inside packed with UPX containing in resource section "CYBERGATE" item. When you load unpacked exe from this dump into debugger you will notice it create process svchost.exe in suspended state for self-injection. In binary clearly visible numerous:
I think it's Cybergate, but is very similar to XtremeRat, what do you think?
Bye!
VT :
https://www.virustotal.com/es-ar/file/a ... 380807573/
hXXp://fabpasadena.com/includes/js/calendar/Certificaciones%20Calificacion%20Tributaria%20y%20para%20Fiscales.zip
http://urlquery.net/report.php?id=6273753
VT: Dump
https://www.virustotal.com/es-ar/file/1 ... /analysis/
00C82310 ASCII "Portions Copyrig"
00C82320 ASCII "ht (c) 1999,2003"
00C82330 ASCII " Avenger by NhT",0
00C82AAB MOV EDX,DumpedXT.00C82B00 UNICODE "x.html"
00C82B00 UNICODE "x.html",0
00C831E4 UNICODE "CyberGat"
00C831F4 UNICODE "e",0