A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #3155  by 4r0
 Wed Oct 20, 2010 12:17 pm
And those samples? TDSS x64 too (both of them)?
Attachments
Password: infected
Looks like TDSS x64

(119.36 KiB) Downloaded 64 times
Password: infected
May be TDSS x64

(114.46 KiB) Downloaded 70 times
 #3156  by EP_X0FF
 Wed Oct 20, 2010 12:26 pm
Yes.

bdesvr.zip
[main]
version=0.03
aid=30020
sid=0
builddate=4096
rnd=1770027372
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://kangojim1.com/;hxxps://lkaturi71.com/;hxxps://rukkeianno.in/;hxxps://neywrika.in/;hxxps://86b6b6b6.com/
wsrv=hxxp://rudolfdisney.com/;hxxp://crozybanner.com/;hxxp://imagemonstar.com/;hxxp://funimgpixson.com/;hxxp://bunnylandisney.com/
psrv=hxxp://cri71ki813ck.com/
version=0.15
load.zip
[main]
version=0.03
aid=40583
sid=0
builddate=4096
rnd=1202660629
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://nichtadden.in/;hxxps://li1i16b0.com/;hxxps://zz87jhfda88.com/;hxxps://n16fa53.com/;hxxps://01n02n4cx00.cc/;hxxps://lj1i16b0.com/
wsrv=hxxp://clikcpixelabn.com/;hxxp://thinksn0taeg.com/;hxxp://jimgwarehouse.com/;hxxp://getbestbaner.com/;hxxp://pixelratator.com/
psrv=hxxp://clkh71yhks66.com/
version=0.15

Same buggy stuff, nothing new.
Attachments
pass: malware
(182.86 KiB) Downloaded 59 times
 #3158  by Blur
 Wed Oct 20, 2010 3:32 pm
Hm, I've checked this sample on 3 vms. It seems to be incompatible with cracked win7 (yes i use cracked windows on my vmwares :) oh c'mon). The only way to boot in that case is to use f8->disable driver signing... Epx0ff are you using cracked windows hehe :)
 #3159  by gjf
 Wed Oct 20, 2010 3:40 pm
Blur wrote:Hm, I've checked this sample on 3 vms. It seems to be incompatible with cracked win7 (yes i use cracked windows on my vmwares :) oh c'mon). The only way to boot in that case is to use f8->disable driver signing... Epx0ff are you using cracked windows hehe :)
What is the way to crack? I believe there was a simple conflict because of similar booting stage patching.
 #3160  by EP_X0FF
 Wed Oct 20, 2010 3:52 pm
Blur wrote:Epx0ff are you using cracked windows hehe :)
Both samples were analyzed under clean Windows XP SP3 x86 licensed copy.
This bootkit renders XP and 2003 to be unbootable in all cases.
However second sample failed to infect mbr and died after reboot.
x64 Windows 7 well infected and working after reboot (in my case).

edit:
of course every time before infecting machine, disk image restored from clean copy.
Last edited by EP_X0FF on Wed Oct 20, 2010 4:16 pm, edited 1 time in total. Reason: edit
  • 1
  • 26
  • 27
  • 28
  • 29
  • 30
  • 60