rkhunter wrote:http://www.0xebfe.net/blog/2013/03/30/f ... andromeda/Many people seem to have been fooled by that. http://www.lastline.com/analysis-of-an-evasive-backdoor
A forum for reverse engineering, OS internals and malware analysis
rkhunter wrote:http://www.0xebfe.net/blog/2013/03/30/f ... andromeda/Many people seem to have been fooled by that. http://www.lastline.com/analysis-of-an-evasive-backdoor
2b15d7f5195f766e5151c4da772c5965c6d6eccb
b6e6850bca9ae2440c9a6f3fc19c999f2b81fec3
f6c60be8656242d4024d6f93dfc992d681e0442c
1925a0119584288d48bd54bd5b5a992788705f86
388c37ecbd40d531dd03afce462ccfc563924a8b
9a2192f413ac99127f14e9da708a49c97261a078
c6a5c476d0f662adf4d74e26b6bdbb592c57d7d6
d196982db154ef8ab98ce96a0e5053808983c51e
e69054e9f00af5fff867dc1ad95946c0aae3a6b8
f6c60be8656242d4024d6f93dfc992d681e0442c
8a262d6e513c60f10ef0b117de92b3db79885088
EP_X0FF wrote:SHA1Any idea if they/some are the "reloaded" version namely "Andromeda 2.7" or the old version?
Code: Select all2b15d7f5195f766e5151c4da772c5965c6d6eccb b6e6850bca9ae2440c9a6f3fc19c999f2b81fec3 f6c60be8656242d4024d6f93dfc992d681e0442c 1925a0119584288d48bd54bd5b5a992788705f86 388c37ecbd40d531dd03afce462ccfc563924a8b 9a2192f413ac99127f14e9da708a49c97261a078 c6a5c476d0f662adf4d74e26b6bdbb592c57d7d6 d196982db154ef8ab98ce96a0e5053808983c51e e69054e9f00af5fff867dc1ad95946c0aae3a6b8 f6c60be8656242d4024d6f93dfc992d681e0442c 8a262d6e513c60f10ef0b117de92b3db79885088
exitthematrix wrote:Any idea if they/some are the "reloaded" version namely "Andromeda 2.7" or the old version?Check all that detected as Gamarue.I, maybe that is what you are looking for.
mov eax, main
call eax
298097a499a1e45314c7eaabb109ba7da70f4bf0
e3dcbd78ff5959e30f5645613474beac45f5554a
0e6f901a8193bac8ff5ca70325aceb63ed0c2476
19c1effb5294eb1d59ec530b73a4526d8a882107
19f8e7ac332db4d1508e7ac25f1f5591834f31cb
36129292066f264d46fdbe7ab67b976aa79421a6
4756a1687d8027ddab4a5efa034dbb1de2cc017d
ba09891a52d71d2ad2cc1acc76c8b774c34f1491
c9ca537a994bc4ec79128bbc5771252c08ca8fa6
e080a9a86da2ec9a20938d82c9ee983989414847
e3dcbd78ff5959e30f5645613474beac45f5554a
f881727c18fdb1a9fdf65f2dc6e18ceced6be226
SMS-MMS Id505044