A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29441  by EP_X0FF
 Mon Oct 17, 2016 2:10 pm
ikolor wrote:Kevin MacLeod - Virtutes Instrumenti


https://www.virustotal.com/en/file/52fb ... 473181867/
This is muldrop trojan. It drops AutoIt executable and executes AutoIt script which is obfuscated RunPE code. Actual malware stored inside this script as encrypted data. Final payload is MSIL/Omaneat trojan spy (in attach). Posts moved.
Attachments
pass: infected
(307.89 KiB) Downloaded 51 times
 #29451  by EP_X0FF
 Tue Oct 18, 2016 8:18 am
ikolor wrote:Thanks buddy

https://www.virustotal.com/en/file/10b4 ... 471032239/
11.exe - MSIL/Omaneat damaged
clean_file.exe - MSIL/Omaneat
new_clean.exe - MSIL/Omaneat
clear.exe - browsers cookie removal tool
e_clean.exe - MSIL/Omaneat
goog_test_file.exe - MSIL/Omaneat
stub101.exe - Win32/Mrophine
putty.exe - http://www.putty.org/
k_clean.exe - MSIL/HawkEye

Posts moved.