A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #19960  by EP_X0FF
 Fri Jul 05, 2013 2:31 am
Hello,

actually

Image

this is all trojan code. You can make own sample :)

Regards.
 #19962  by hx1997
 Fri Jul 05, 2013 5:35 am
EP_X0FF wrote:Hello,

actually

this is all trojan code. You can make own sample :)

Regards.
Yeah so it is!

But some strings are blurred so I can't make a working sample.

It would be better if I could get a working one.

Thanks for the info! :-)
 #19965  by Xylitol
 Fri Jul 05, 2013 7:17 am
blured code are ftp informations, i don't really get the problem :|
just by looking the non-blured part you can already identify the guys use the free service of 000webhost (netau.net)
edit: you can thanks a guys from Eset, i've asked them the sample.
Attachments
infected
(332.73 KiB) Downloaded 67 times