A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #8062  by rkhunter
 Wed Aug 17, 2011 5:26 am
It uses GPU module for attack to Bitcoins.

Technical description:
http://www.symantec.com/business/securi ... 15-5847-99

http://www.symantec.com/connect/blogs/b ... anbadminer

When it comes to mining, Badminer contains functionality to deal with all eventualities. It detects the type of computer that it is running on and then activates the appropriate “machinery” to dig through the hashes to reach the hidden treasures. If it determines the computer has a high-spec graphics card with a fast enough graphics processing unit (GPU), it uses the appropriate packages to leverage the immense processing power of the GPU to literally move through the mountains of hashes to reach the valuable bitcoins. Conversely if a low-spec computer is found, then it will wheel out the basic bitcoin mining tools, which will result in much slower throughput. To perform the mining functions, the Trojan contains both the RPC miner and Phoenix miner programs. The latter can take advantage of the extra power of the GPU for bitcoin mining.

Symantec wrote that it creates key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32, i. e. with driver on board.

May be anyone could share sample?
 #8064  by dcmorton
 Wed Aug 17, 2011 6:33 am
Haven't tracked down a sample yet, but here's a ThreatExpert and VT scan for what looks like a sample to me.

MD5: 0761d41068167c83047d06b89f497343

http://www.threatexpert.com/report.aspx ... b89f497343
http://www.virustotal.com/latest-report ... b89f497343

This one looks like it could also be one as well.

MD5: 46871a2806802d155b0a285a89d4ff74

http://www.threatexpert.com/report.aspx ... 5a89d4ff74
http://www.virustotal.com/latest-report ... 5a89d4ff74
 #8067  by rkhunter
 Wed Aug 17, 2011 7:21 am
Without driver, register itself (srvsysdriver32) as service HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32,
%windir%\sysdriver32.exe srv.
 #9401  by p4r4n0id
 Tue Oct 25, 2011 12:16 pm
dcmorton wrote:Haven't tracked down a sample yet, but here's a ThreatExpert and VT scan for what looks like a sample to me.

MD5: 0761d41068167c83047d06b89f497343

http://www.threatexpert.com/report.aspx ... b89f497343
http://www.virustotal.com/latest-report ... b89f497343

This one looks like it could also be one as well.

MD5: 46871a2806802d155b0a285a89d4ff74

http://www.threatexpert.com/report.aspx ... 5a89d4ff74
http://www.virustotal.com/latest-report ... 5a89d4ff74

Got this one 0761d41068167c83047d06b89f497343, attached.

p4r4n0id
Attachments
pwd:infected
(231.69 KiB) Downloaded 47 times