A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #17639  by p4r4n0id
 Mon Jan 07, 2013 11:06 am
Hi Guys,

Besides Reveton , Cridex B and Shitkit are you familiar with some other samples that communicates with C&C over SSL? Samples also needed,

Thx,

p4r4n0id
 #17641  by EP_X0FF
 Mon Jan 07, 2013 12:59 pm
TDL3/TDL4.
 #17643  by Userbased
 Mon Jan 07, 2013 4:07 pm
Ngrbot and Insomnia are both irc bots that are capable of using ssl irc connections for C&C.
Here's a sample of SSL using insomnia with an active C&C.
Attachments
Password is "infected" without quotes.
(229.39 KiB) Downloaded 68 times