Here is another sample with some improvements. aswMBR wasn't able to remove it, but detected TDL4. mbr.exe missed it. TDSSKiller still got it. I did not use any other tools, yet. Tested on Windows XP Sp3 (atapi + iaStor).
From the config.ini
From the config.ini
Code: Select all
VT-Report: http://www.virustotal.com/file-scan/rep ... 1304819009[main]
version=0.03
aid=40787
sid=0
builddate=351
rnd=1482476501
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://4tag16ag100.com/;hxxps://zna61udha01.com/;hxxps://dg6a51ja813.com/;hxxps://7gaur15eb71.com/;hxxps://ka18i7gah10.com/
wsrv=hxxp://bangl24nj14.com/;hxxp://lkeopee32.com/;hxxp://63.223.106.16/;hxxp://63.223.106.17/;hxxp://iau71nag001.com/;hxxp://baj19kall10.com/
psrv=hxxp://cikh71ynks66.com/;hxxp://clkh71yhks66.com/
version=0.15
Attachments
pw=infected
(132.6 KiB) Downloaded 100 times
(132.6 KiB) Downloaded 100 times