Thanks to Tim for providing the samples. Inside the attachment is my attempt to unpack the packed file (packed with VMProtect). I can't fix the stolen OEP bytes. If anyone can help, please post your findings :)
More information: http://blog.trendmicro.com/trendlabs-se ... m-malware/
More information: http://blog.trendmicro.com/trendlabs-se ... m-malware/
Attachments
password:infected
(345 KiB) Downloaded 148 times
(345 KiB) Downloaded 148 times
@xorsthingsv2