A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #10385  by rough_spear
 Thu Dec 15, 2011 6:03 pm
Hi All, :D
W32.Sality.U

One more sample of Sality. :twisted:
this file is trojan.hello.A1 which is infected by sality.

Regards,

rough_spear. ;)
Attachments
password - malware
(86.8 KiB) Downloaded 151 times
 #17830  by Mosh
 Wed Jan 23, 2013 6:53 pm
Hi All

I'm new on malware analysis and i would share with you a small analysis that I did.

I took the sample: 60bd4776338ea598d4f1964c01616468 and I found the device and driver name

Image

Image

Later with the help of WinDbg i found the driver in the address 0x82a73b30 and then i could view the structure

Image

Then i review the DriverInit memory position and i found with a interesting function in the address 0xf7bcab50, i dont know what exactly this function does, but when i revise this memory position i found the string list for the antivirus.

Image

Image


See you ;)