A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5629  by EP_X0FF
 Thu Mar 24, 2011 2:54 pm
markusg wrote:facebookhack.exe
http://www.virustotal.com/file-scan/rep ... 1300977346
Spatet/Rebhib

In attach fully unpacked Delphi stub.

https://www.virustotal.com/file-scan/re ... 1300978074

posts moved.
Attachments
pass: malware
(253.25 KiB) Downloaded 33 times
 #5749  by EP_X0FF
 Wed Mar 30, 2011 3:55 pm
markusg wrote:setup.exe
http://www.virustotal.com/file-scan/rep ... 1301404961
Spatet/Rebhib (Crypter + UPX). In attach fully unpacked Delphi stub.

https://www.virustotal.com/file-scan/re ... 1301500067
STUB [MainUnit]
Base64
Windows
System
SysInit
Types
uIE7_decode
UnitDiversos
TlHelp32
UnitServerUtils
AclAPI
AccCtrl
wcrypt2
uURLHistory
ActiveX
Messages
CryptApi
uRASReader
IEpasswords
Pstoreclib
PSTORECLib_TLB
unitStartup
UnitComandos
deleteUnit
UnitPasswords
EditSvr
UnitInstalacao
UnitSettings
UnitVariaveis
UnitSandBox
UnitInjectLibrary
Posts moved.
Attachments
pass: malware
(246.37 KiB) Downloaded 42 times
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7