Another 3 samples with same crypter, just with a few differences
7 / 41 https://www.virustotal.com/file/1bd5f61 ... /analysis/
MD5: 31cf2ccf68f7a1619557b4419df695a7
SHA1: f88a9ddf11fa6a897c555ce9116dba931fde22c5
16 / 41 https://www.virustotal.com/file/5de9d8d ... /analysis/
MD5: 48f9e3ac24d25d29d6bf49d740315e93
SHA1: 07196dbb66efb55d76b5e90c38142bc33f97e346
8 / 42 https://www.virustotal.com/file/b22548b ... /analysis/
MD5: 76b3cb955487f1665040c5647bf12f56
SHA1: 6840405767e8af443346933daed0897ce111a73e
Copies itself with random name into %appdata%\random_folder_name\random_file_name
Autorun from HKCU\Software\Microsoft\Windows\CurrentVersion\Run\{CLSID}
Completely hangs my WinXPSP3 (with help of injections)...
Anti-emu trick
7 / 41 https://www.virustotal.com/file/1bd5f61 ... /analysis/
MD5: 31cf2ccf68f7a1619557b4419df695a7
SHA1: f88a9ddf11fa6a897c555ce9116dba931fde22c5
16 / 41 https://www.virustotal.com/file/5de9d8d ... /analysis/
MD5: 48f9e3ac24d25d29d6bf49d740315e93
SHA1: 07196dbb66efb55d76b5e90c38142bc33f97e346
8 / 42 https://www.virustotal.com/file/b22548b ... /analysis/
MD5: 76b3cb955487f1665040c5647bf12f56
SHA1: 6840405767e8af443346933daed0897ce111a73e
Copies itself with random name into %appdata%\random_folder_name\random_file_name
Autorun from HKCU\Software\Microsoft\Windows\CurrentVersion\Run\{CLSID}
Completely hangs my WinXPSP3 (with help of injections)...
Anti-emu trick
Attachments
pass:infected
(769.17 KiB) Downloaded 71 times
(769.17 KiB) Downloaded 71 times