performsizm.exe
http://www.virustotal.com/file-scan/rep ... 1305564580
http://www.virustotal.com/file-scan/rep ... 1305564580
Attachments
(263.68 KiB) Downloaded 53 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:performsizm.exeSpyEye v1.3
http://www.virustotal.com/file-scan/report.html?id=2a01c8cdea1150ef81f460da174fa724bfa6e1e5c1cab8d975384b7b886e70ba-1305564580
hxxp://gameopiloris.com/svf/ksk.php;300
hxxp://ogmetakeloris.com/svf/ksk.php;300
markusg wrote:winxnet.bin.exeThis SpyEye v1.3 more interesting. It has antivm on board (probably part of skiddie crypter). Actually it looks for VmWare/VirtualPC/Sandbox/QEMU by checking specific registry keys, volume serial numbers and user names. If you interested have a look here @004415A7 (remove UPX first), if something is detected it will exit. Right after VM check located decryption procedures and main payload.
http://www.virustotal.com/file-scan/report.html?id=321f75d35930d32e5f5300efb500f6ad1337f0cbffd39b633c8a977aedb7ab44-1305560314
hxxps://mishurka.ru/mail/form.php;3600Hehe, SpyEye likes Kaspersky Lab :) see certificates grabber plugin
hxxps://hireiar.ru/web/trope.php;3600
hxxps://interwirez.ru/ale/one.php;3600
hxxps://sepostin.ru/update/womt.php;3600
hxxps://100wiles.ru/ars/being.php;3600
hxxps://krifis.ru/da/net.php;3600
hxxps://poleposx.ru/nit/big.php;3600
hxxps://jivat.ru/lo/bus.php;3600
sww wire cvv2 gostev bmw bugatti stock porche mustang satan 666 z0mbie
markusg wrote:Recycle.Bin.exeSpyEye v1.3
http://www.virustotal.com/file-scan/rep ... 1305711879
markusg wrote:Recycle.Bin.exeAbsolutely the same SpyEye posted previously.
http://www.virustotal.com/file-scan/rep ... 1305820802
hxxp://cnc0098510m.cz.cc/mmmmmmaaaaaa/gate.phpPass to decrypted config: A32A0302C2BA8C87B59553525929553F
markusg wrote:Washer2.rar.exeSpyEye v1.3
http://www.virustotal.com/file-scan/report.html?id=6b9284c3732fae2ccc12673f4702c889e3e68cbb6667a3c5bf2882f199b1645a-1306153577
hxxp://host-checkker.net/ASdhgas6d/sdhgas/yrgdate13.php;350http://www.virustotal.com/file-scan/rep ... 1306154511
hxxp://befirstchild.net/bFeIN_L/50x.html.php;350
hxxp://nofrostengland.com/hYtgfE/dgTrfdbbbf.php;350