A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #31645  by waffles2.0
 Tue Jun 12, 2018 8:46 am
In this blog post by Qihoo 360 they document CVE-2018-5002: http://blogs.360.cn/blog/cve-2018-5002-en/

It seems like they are the only people who have reversed it, unfortunately they have decided to hide a section of the MD5s

***salary.xlsx - MD5: ******517277fb0dbb4bbf724245e663
malicious SWF (Shock Wave File) file - MD5: ******66491a5c5cd7423849f32b58f5
decrypted SWF - md5: ******e78116bebfa1780736d343c9eb

Has anyone found more information or has access to the decrypted Shockwave file that contains the exploit?
Thanks.
 #31671  by waffles2.0
 Thu Jun 14, 2018 7:47 am
Thanks maddog! It's too bad the C2 server is down now so we can't get the SWF files.
 #31672  by xors
 Thu Jun 14, 2018 9:42 am
swf
Attachments
(25.88 KiB) Downloaded 17 times