I don't know how really new this sample, but it uses 0x4C, however if author will only change key, it's not so hard to brute-force.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:http://www.virustotal.com/file-scan/rep ... 1303920299This one with different xor byte (0xC4) and with less functionality on board.
.text:00910903 SpyEye_DecryptCycle:
.text:00910903 mov dl, [eax+ecx]
.text:00910906 xor dl, 0C4h
.text:00910909 sub dl, [eax+ecx-1]
.text:0091090D mov [eax+ecx], dl
.text:00910910 dec eax
.text:00910911 test eax, eax
.text:00910913 jg short SpyEye_DecryptCycle
ssyn spyeyetracker.abuse.ch 443 3600config_pomidorka.zip - decrypted config data from first sample (DDoS plugin included)
195.226.218.136:30000;vmLacswsoJaEk;sysadmin;qwe123;http://www.cushyhost.com/download.php?img=224
markusg wrote:E3677975003727A9EE60023D0ADB08001DEC7958.exeFind attached decrypted config.bin
http://www.virustotal.com/file-scan/report.html?id=8f478f0e053fe0abd74f92fd6777e812c6826e124d1836c5016ece8964de01af-1304177506
hxxp://193.107.172.11/~brbrabr1/gate.php;1200
hxxp://maf3support.com/~brbrabr1/gate.php;1200
hxxp://maf4support.com/~brbrabr1/gate.php;1200
Xylitol wrote:loc: turaminich.co.cc/zcontent/catalog/bin/rar.exeDecrypted attached as Xylitol_decrypted.zip
hxxp://dug6.jz8ofdji.com/q3calw8k/gate.php;90Both with AntiRapport on board.
hxxp://h4au.ijp2fmtf.net/q3calw8k/gate.php;90