A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #18688  by Maxstar
 Mon Mar 25, 2013 10:44 am
I found some weird file, probably it is a scrambled file with dummy data to avoid detection.
The file is zipped 850kb and unpacked 130MB.
Code: Select all
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SQLDriver]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hmmm"
"hkey"="HKLM"
"command"="C:\\Documents and Settings\\Username\\Application Data\\SQLDriver\\hmmm.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"SQLDriver"="C:\Documents and Settings\Username\Application Data\SQLDriver\hmmm.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SQLDriver"="C:\Documents and Settings\Username\Application Data\SQLDriver\hmmm.exe"

Process: C:\Documents and Settings\Username\Application Data\SQLDriver\hmmm.exe
Attachments
PW = infected
(849.83 KiB) Downloaded 78 times
 #18689  by EP_X0FF
 Mon Mar 25, 2013 11:52 am
Blackshades NET aka Ainslot under something named "VIP Crypter" dotnet primitive obfuscator-injector. 130 Mb of zero data as overlay. In attach decrypted. Posts moved.
Attachments
pass: malware
(155.5 KiB) Downloaded 62 times
 #19587  by EP_X0FF
 Mon Jun 10, 2013 2:16 am
markusg wrote:think belongs to this topic
SHA256:
7c353f2c7aead1c323a3cb70238c8d86be2f048b92fc367d771ea386a1242a76 
Dateiname:
AcroRd32.exe 
Erkennungsrate:
0 / 47  
https://www.virustotal.com/de/file/7c35 ... /analysis/
Blackshades with dotnet crypter.
Code: Select all
D:\BlackshadesProject\bs_net\server\server.vbp
Posts moved.
 #20636  by Wack0
 Thu Aug 29, 2013 1:15 pm
bao wrote:https://www.virustotal.com/en/file/033e ... 377765203/
http://anubis.iseclab.org/?action=resul ... ormat=html
not bitcoin miner, actually BlackShades RAT packed using HF-style autoit crypter that uses rarsfx with 7MB of random junk in it where 6 files are actually used.

Image

unpacked in attach.
Attachments
(167.31 KiB) Downloaded 67 times