Security Shield rogue, full undetected: https://www.virustotal.com/file-scan/re ... 1295541138
Attachments
see archive comment for password
(267.91 KiB) Downloaded 77 times
(267.91 KiB) Downloaded 77 times
A forum for reverse engineering, OS internals and malware analysis
Xylitol wrote:Security Shield rogue, full undetected: https://www.virustotal.com/file-scan/re ... 1295541138No surprise :) These guys has very good cryptor support. And it's server side, same sample downloaded few minutes after yours, the same but different :)
markusg wrote:are there no urls for the last 2 or have i missed :-)hxxp://satel12vc.co.cc/inst.exe :)
Xylitol wrote:i dont like guys who request something when he have only one post.I'm looking to infect a billion computers with it BWHAHAHAHA! No, I am looking for it for research. I've been studying computer security for 2 years and have taken a course called Offensive Security -> (http://www.offensive-security.com/). Also run my own Youtube security channel in case your interested-> (http://www.youtube.com/user/redcodefinal). I wanted to A:See what it installs, where it installs it, reg keys it uses etc. (I know I can find this on the internet but, I like to do things myself) and then I want to fuzz the application to see if I can create a usable buffer overflow. I was really hoping to make my own solution as a learning tool. Also sorry @EP_X0FF, I'm new and kind of suck, please forgive me ;_;.
seem he have anti-vm but i'm lazy to find them...
why do you need it?
Thank you for your purchase, Windows Scan!
Your activation code: 0973467457475070215340537432225
EDS URL: http://edsfull.com/customers/dl/Defrag.exe
Contact us through Help&Support section in the Windows Scan menu or by phone +1-877 282 0139