A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29444  by EP_X0FF
 Tue Oct 18, 2016 4:25 am
ikolor wrote:next ..

https://www.virustotal.com/en/file/0f2c ... 445443584/
bedia1.exe - MSIL/Golroted
dugefia2.exe - MSIL/Golroted
bejodea.exe.exe - MSIL obfuscated dropper-injector (zombified vbc.exe type) for modified MailPassView program.
Doc3.doc - Office macro virus O97M/Donoff
Doc5.doc - Office macro virus O97M/Donoff
Doc6.doc - Office macro virus O97M/Donoff

Thread split.