A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #4878  by Meriadoc
 Fri Feb 04, 2011 1:22 pm
Played with a Chinese coded tool called 'mdecoder' a long time ago and was recently reminded of it after seeing some logs posted on a forum.

example :

select log goes to clipboard
Log generated by anonymous use mdecoder 0.67
[Root] hxxp://baidu.x0day.com:88/images/foots.html?www.sciam.com.cn
[Script] hxxp://baidu.x0day.com:88/images/tests.js?test
[Exp] hxxp://baidu.x0day.com:88/images/ie/test.html (Exploit.Ie0dayCVE0806.a)
[Virus] hxxp://ds.84ny.com/data/home/qiyou.exe
[Iframe] hxxp://baidu.x0day.com:88/images/cf/cf.html
[Iframe] hxxp://baidu.x0day.com:88/images/cf/ok.html
[Flash] hxxp://baidu.x0day.com:88/images/ah/f45.swf
[Exp] hxxp://baidu.x0day.com:88/images/mm/mm.htm (Exploit.IEAurora.a)
[Script] hxxp://ds.84ny.com/data/home/qiyou.exe
[Script] hxxp://js.users.51.la/3880410.js
There's no help, but the tool is in english, mostly :)

with a little use you will find out how it works.

you will have to translate as the google translate links went to the wrong page.
mtian most recent version of MDecoder v0.67
MDecoder hidden features and history version download
mdecoder may be dead as the source is up for sale but it may interest someone to have a look at it in a vm.
Attachments
(1.52 MiB) Downloaded 112 times