A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28626  by EP_X0FF
 Mon Jun 06, 2016 12:21 pm
VT links posting are great, now attach the actual files or your post makes absolutely no sense.
 #28649  by tildedennis
 Thu Jun 09, 2016 12:40 am
Couple more blogs on this one:

- http://www.cert.pl/news/11379/langswitch_lang/en
- http://phishme.com/bolek-leaked-carberp ... campaigns/

Attached the config for 91.215.154.155:

- .raw_config file is the decrypted JSON object returned from the C2. The Data keys are base64 and either contain binary data or another JSON object
- .config file is a lightly parsed version showing the inner JSONs

Comak (or anyone) know why the name "Bolek" ?
Attachments
(2.43 MiB) Downloaded 68 times
(866.62 KiB) Downloaded 71 times
 #28651  by comak
 Thu Jun 09, 2016 2:27 pm
tildedennis wrote: Comak (or anyone) know why the name "Bolek" ?
I think because the guy who named is lacking imagination... ;]
bolek is a shorter form of a common name "Bolesław" in .pl.

btw, thanks for cfgs, you got them from cnc? or rip them from memory?