A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #16091  by kalptarunet
 Thu Oct 18, 2012 12:12 am
Hi,

Looking below sample, appreciate if some one able to help me.

MD5: d0d335fbc6d9fdbaf8a0af44ae2944c7
SHA1: 5c8ff79400f965e269c6a213e640e2d15dbebb52

C2 callback:
http://antivirus.9899.com.ar/meeting/upgrade.exe /meeting/upgrade.exe

Sandbox Analaysis:

http://malwr.com/analysis/d0d335fbc6d9f ... 4ae2944c7/
http://jsunpack.jeek.org/dec/go?report= ... 9f49d5ae31

Thanks,

-KTX
 #16108  by Xylitol
 Thu Oct 18, 2012 4:24 pm
kalptarunet wrote:Hi,

Looking below sample, appreciate if some one able to help me.

MD5: d0d335fbc6d9fdbaf8a0af44ae2944c7
SHA1: 5c8ff79400f965e269c6a213e640e2d15dbebb52

C2 callback:
http://antivirus.9899.com.ar/meeting/upgrade.exe /meeting/upgrade.exe

Sandbox Analaysis:

http://malwr.com/analysis/d0d335fbc6d9f ... 4ae2944c7/
http://jsunpack.jeek.org/dec/go?report= ... 9f49d5ae31

Thanks,

-KTX
Attachments