A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29514  by xors
 Sat Nov 05, 2016 9:02 pm
Hi all,

I am trying to find the following sample. Hope someone can download it from Virustotal.

SHA256: 4bfe2216ee63657312af1b2507c8f2bf362fdf1d63c88faba397e880c2e39430
 #29519  by MindfreaK
 Tue Nov 08, 2016 1:50 am
Interesting paper. Does somebody know when the binary was found ?
Or can somebody provide vt link?
Does somebody know where the name Sednit comes from ?
 #29529  by EP_X0FF
 Thu Nov 10, 2016 3:44 am
2016 is the year when primitive and badly written 32bit SSDT hooker is an advanced persistent threat. Does clowns from Cymmetria already posted about it? I've heard their main clown blahblah something to CNN (how funny trash "security analyst" speaking on trash media).
 #29537  by xors
 Thu Nov 10, 2016 1:52 pm
Just for curiosity. Can someone also provide the following sample?

b1900cb7d1216d1dbc19b4c6c8567d48215148034a41913cc6e59958445aebde

It's the x86 driver.