In attach you will find tdl3 droppers collected by me during tdl3 hunting from september 2009 till end of march 2010. Because they are not useful for me (since detection/removal methods were developed) I decided to upload it here because I know very well how hard it sometimes obtain rootkit samples.
There maybe some duplicate droppers (the same version, all md5 stamps are different).
Archive including old first tdl3 generation samples, z00clicker samples (including one most recent) and tdl3 second generation samples:
All samples dated by time when they were added to my database not their release date. Non filtered database currently contains ~1000 tdl3 droppers (most of them just a re-crypts of 3.2xx version) and I'm doing some cleanup.
There maybe some duplicate droppers (the same version, all md5 stamps are different).
Archive including old first tdl3 generation samples, z00clicker samples (including one most recent) and tdl3 second generation samples:
- 3.17
- 3.20
- 3.22
- 3.23
- 3.24
- 3.241
- 3.25
- 3.26
- 3.27
- 3.271
- 3.272
- 3.273
All samples dated by time when they were added to my database not their release date. Non filtered database currently contains ~1000 tdl3 droppers (most of them just a re-crypts of 3.2xx version) and I'm doing some cleanup.
Ring0 - the source of inspiration