ZeroAccess payload fetched from network just now. Include fresh compiled dll.
win32 Sirefef payload
- 000000cb
- 00000004
- 00000008
- 80000000
- 80000032
SHA1
84d27814aa3734393d9739dea9db2058dd8ef486
61023a418c73264f0a514f93c39ada01391b6e15
a3aa67884223f3e8f8c52afdbc779dcb19ff00e6
97d178f9f9541e90c2a527c3ff97a43a1b69cb25
6e181f5c9031430d1c4f36b99779d4f9d51eb208
win64 Sirefef payload
- 000000cb
- 00000004
- 00000008
- 80000000
- 80000032 (included for wow64 compatibility)
- 80000064 (compiled 1 Apr 2013)
SHA1
b4182854f7531e4f363e641ebdba33e3d9dfa691
a03758c7daf6e246059c3eebaa67244615d037d4
061a3739739904f13a5b9adcbf4ac2e8a3157b18
46c1319ee38510c365a4226621de30bdf7e462ff
810e28d4e7b28d658dc48a82f0c65b46149aae89
2b4144391ab409ec1017691fe54b16b951e3ec4d