pigindrin wrote:Hello EP_XOFF, according to your response (page 24), I ´ve checked it and the spyeye version (.exe) is the same. But, I ´ve re-analyzed the sample and it seems the webinject is not the same. Could it be possible?Yes it is possible, servers list and other stuff of the same botmaster can be updated since they moving from server to server periodically after getting into trackers.
The C&C to where the malware connects is "263rdasd.com/hfgf/gate.php". Could give me a hand in order to get the webinject? Thanks!
Pass for decrypted config of your sample B8861AB9ED87B79CC01DA26263373342
Both from binary and from archive configs attached
Attachments
(215.05 KiB) Downloaded 52 times
(5.37 KiB) Downloaded 48 times
Ring0 - the source of inspiration