A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12778  by thisisu
 Wed Apr 18, 2012 8:09 am
EP_X0FF wrote:@thisisu

Can you please share the source of your Sirefef droppers? If possible PM me.
Sent you a PM :)
___

MD5: a504d4e47975d58dd72c6ce9799df0ea
https://www.virustotal.com/file/6f2ed90 ... /analysis/
Oak Technology Inc. .DLLs
Attachments
pass: infected
(160.53 KiB) Downloaded 53 times
 #12781  by EP_X0FF
 Wed Apr 18, 2012 9:12 am
thisisu wrote:MD5: a504d4e47975d58dd72c6ce9799df0ea
https://www.virustotal.com/file/6f2ed90 ... /analysis/
Oak Technology Inc. .DLLs
Blackhole which hosts this dropper was generous. There are actually few Sirefef droppers, one from it pretty fresh (see attach). https://www.virustotal.com/file/9fe5b66 ... /analysis/

Same multistage installation + infection of system driver (seems infection code has been updated).

Complete list of malware from BH EK


6354578DE170FA554068BE9E521F83688316BF1E
ACAF9645770895719D38E97AA3DE214F743E6A6A
1453C26567D47FA2E4CED92D1DC5C20DCDC7368A
0E04A3B23C4EFC04A9E0AE49B96BFD3ED6308D99
408EFA8E16CF9F11B283AC685D4DB5A0C94A5B0D
53B2B484D2B11630FCACF1453DC350415404CFCA
96BD740F883123E67825D5F7C8D4A55D06FF38FA

They are Sirefef and Fake AV's. Probably daily basis update.
Attachments
pass: infected
(286.34 KiB) Downloaded 68 times
 #12893  by int0
 Wed Apr 25, 2012 7:31 am
thisisu wrote:MD5: 5cc3bf6dff6aef5951c85ab0169d0f51
https://www.virustotal.com/file/41393c5 ... /analysis/
Oak Technology Inc. .DLLs
Thnx for the sample, there are new features in this sample. VFS folder $NtUninstall%u$ is not reparse point anymore and its redirected to \SystemRoot\System32\config so user actually sees fake content also it now logs your search history into file named "oemid" in VFS folder. Definitely useful sample thnx!
  • 1
  • 28
  • 29
  • 30
  • 31
  • 32
  • 38