A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4481  by GMax
 Sun Jan 16, 2011 12:34 pm
FileName: Private_Brute.exe
Size: 534 Kb (546816 byte)
Data/Time compile: 01.01.2011 / 14:19:51 UTC
MD5: 3C09A47B4A673A9E46CB0DE70B02454D
PEiD: ['BobSoft Mini Delphi -> BoB / BobSoft']
http://www.virustotal.com/file-scan/rep ... 1295177816
http://www.threatexpert.com/report.aspx ... e70b02454d
Image

Unlock key: 10293838
Attachments
pas: malware
(203.74 KiB) Downloaded 89 times
 #5492  by Xylitol
 Wed Mar 16, 2011 10:42 am
winlock generator found in the web according to my search it was from december 2010
https://www.virustotal.com/file-scan/re ... 1300267030

generated ransomware are huge ~435 Kb

Image

Image

Image

generated winlock:
Image

disas winlock:
Image

Image

----
Edit: Found a winlock source
Image
Attached.
--------
Edit again: Found the version 0.3 of the winlock builder
https://www.virustotal.com/file-scan/re ... 1299569441

Image

Image

Image


Edit again, again (lol): This winlock generator remind me one sample found by Gmax in Jan 2k11:
http://www.kernelmode.info/forum/viewto ... 4481#p4481
the Winlock builder was made in december 2010, i'm pretty sure the sample of GMax was generated by this.
Attachments
See archive comment for password
(271.94 KiB) Downloaded 64 times
See archive comment for password
(612.13 KiB) Downloaded 61 times
See archive comment for password
(275.32 KiB) Downloaded 58 times
 #6041  by Xylitol
 Mon Apr 25, 2011 3:54 pm
WinLocker Builder v0.4 is in the wild, i think we will see soon new variants.

Image

Image

Image

Image

Generated winlock (4/41 (9.8%)) http://www.virustotal.com/file-scan/rep ... 1303744185

difference btw the 0.3 and the 0.4 on the serial check it use a simple xor
Attachments
See archive comment for password
(589.94 KiB) Downloaded 60 times
See archive comment for password
(634.48 KiB) Downloaded 55 times
A sort of Keygen i've made using the previous source code of WinLocker
(199.69 KiB) Downloaded 56 times
 #6913  by EP_X0FF
 Thu Jun 23, 2011 7:21 am
Primitive Winlock (probably created through Winlock generator).

Image

Unblock key: 816908 (created as result of xor operation over 922039 and key asd9sa786ves)

http://www.virustotal.com/file-scan/rep ... 1308812764
http://www.virustotal.com/file-scan/rep ... 1308560423

In attach both original and unpacked (removed VB crypter and UPX).
Attachments
pass: malware
(405.75 KiB) Downloaded 67 times
 #13455  by GMax
 Sun May 27, 2012 8:29 pm
Image

unlock code = '611138??0702824' xor 'asd9sa786ves'

Number to call: 8(917)970-46-69
Unlock code: 725809876151910
Attachments
pass: malware
(311.66 KiB) Downloaded 74 times