Malware targeting French people
FileLocker.exe (465.5 KB)
a02aff753dffb13ad034ca67aed985d8
f53cb550bc4d6193a42f8aa2ec348e8cc89728e9
b47f15d1093fd6466e040d3ee786a18e25f8980d3db33465d2acbafe8b0f6850
deobfuscated.exe (294.5 KB)
2ee9b110cd784d6bcdf663c9249ebee4
3d84dfd0f7dd95f26a9a47dd16149602bf8cfb56
459a487b0ad80fc56c06fca73eb80b3268bd423eaf6da5a1b400a7b5c19fb957
- obfuscated with .NET Reactor 4.5+
- Password stored on HKEY_CURRENT_USER\\Software
- Encrypt: TripleDES
- Send client data via EMail
- Blog info: http://nyxbone.com/malware/jobcrypter.html
FileLocker.exe (465.5 KB)
a02aff753dffb13ad034ca67aed985d8
f53cb550bc4d6193a42f8aa2ec348e8cc89728e9
b47f15d1093fd6466e040d3ee786a18e25f8980d3db33465d2acbafe8b0f6850
deobfuscated.exe (294.5 KB)
2ee9b110cd784d6bcdf663c9249ebee4
3d84dfd0f7dd95f26a9a47dd16149602bf8cfb56
459a487b0ad80fc56c06fca73eb80b3268bd423eaf6da5a1b400a7b5c19fb957
- obfuscated with .NET Reactor 4.5+
- Password stored on HKEY_CURRENT_USER\\Software
- Encrypt: TripleDES
- Send client data via EMail
- Blog info: http://nyxbone.com/malware/jobcrypter.html
Attachments
(389.14 KiB) Downloaded 133 times
nyxbone.com
Twitter: @nyxbone
Twitter: @nyxbone