A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4778  by Meriadoc
 Fri Jan 28, 2011 9:24 am
Recent small pack I gleaned from Chinese malicious urls and forums. Haven't looked at them yet, just a cursory scan with Dr.W (included) some not flagged.

hotfile
or
megaupload
pass=malware
Attachments
scan report
(4.7 KiB) Downloaded 34 times
 #14817  by rough_spear
 Sun Jul 22, 2012 1:26 pm
Hi All, :D
15 different malwares from blackhole C&C server.
which also includes necurs rootkit.

TR/PSW.Zbot.2355 hxxp://91.121.75.7/files/56e24
TR/Hilasy.A.2 hxxp://91.121.75.7/files/58d4f
TR/Injector.ASF hxxp://91.121.75.7/files/625ef
TR/Rogue.KD.665403 hxxp://91.121.75.7/files/6ab17
TR/Drop.Necurs.A.8 hxxp://91.121.75.7/files/6dfaa
Unknown exe hxxp://91.121.75.7/files/7279c
TR/Dldr.Cutwail.BE.32 hxxp://91.121.75.7/files/79c45
TR/Citadel.A.1 hxxp://91.121.75.7/files/86b3a
DR/Delphi.Gen hxxp://91.121.75.7/files/8e002
TR/Rogue.KD.667376 hxxp://91.121.75.7/files/a6b01
BDS/Simda.A.17 hxxp://91.121.75.7/files/bb769
TR/PSW.Zbot.Y.2268 hxxp://91.121.75.7/files/c50b0
TR/PSW.Zbot.Y.2335 hxxp://91.121.75.7/files/cb27f
TR/Rogue.kdv.667978 hxxp://91.121.75.7/files/cd1d8
TR/Crypt.ZPACK.Gen2 hxxp://91.121.75.7/files/d4fc7

Regards,

rough_spear. ;)
Attachments
password - infected.
(3.18 MiB) Downloaded 76 times