A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #22364  by forty-six
 Wed Mar 05, 2014 4:35 pm
GMO w/ RK dropped via Angler.
Code: Select all
bcdedit.exe -set TESTSIGNING ON
%s\drivers\%s.sys
runas
ComSpec
\\.\NtSecureSys
SeShutdownPrivilege
kernel32
IsWow64Process
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
*EUDC*
ZwQuerySystemInformation
ntdll.dll
svchost.exe
SystemDefaultEUDCFont
EUDC\%d
ObReferenceObjectByHandle
ZwDuplicateToken
ObOpenObjectByPointer
PsReferencePrimaryToken
PsInitialSystemProcess
ObfReferenceObject
IoGetCurrentProcess
KeDelayExecutionThread
WinExec
GetModuleFileNameA
GetTickCount
GetSystemDirectoryA
CloseHandle
GetLastError
GetCurrentProcess
Sleep
GetExitCodeThread
WaitForSingleObject
CreateThread
Attachments
(453.11 KiB) Downloaded 81 times