Hi there,
ESET (Aleksandr Matrosov) released an analysis of an interesting new Bootkit:
Win32/Gapz: steps of evolution
Win32/Gapz: New Bootkit Technique
Hashes of droppers and MBR are as follows:
Win32/Gapz.A (dropper)
SHA1 hash: 1f206ea64fb3ccbe0cd7ff7972bef2592bb30c84
Win32/Gapz.A (dropper)
SHA1 hash: dff6933199137cc49c2af5f73a2d431ce2e41084
Win32/Gapz.B (dropper)
SHA1 hash: e4b64c3672e98dc78c5a356a68f89e02154ce9a6
Win32/Gapz.C (dropper)
SHA1 hash: 85fb77682705b06a77d73638df3b22ac1dbab78b
Win32/Gapz.C (MBR)
SHA1 hash: b37afc51104688ea74d279b690d8631d4c0db2ad
If someone can provide a sample, please upload. Thanks!
ESET (Aleksandr Matrosov) released an analysis of an interesting new Bootkit:
Win32/Gapz: steps of evolution
Win32/Gapz: New Bootkit Technique
Hashes of droppers and MBR are as follows:
Win32/Gapz.A (dropper)
SHA1 hash: 1f206ea64fb3ccbe0cd7ff7972bef2592bb30c84
Win32/Gapz.A (dropper)
SHA1 hash: dff6933199137cc49c2af5f73a2d431ce2e41084
Win32/Gapz.B (dropper)
SHA1 hash: e4b64c3672e98dc78c5a356a68f89e02154ce9a6
Win32/Gapz.C (dropper)
SHA1 hash: 85fb77682705b06a77d73638df3b22ac1dbab78b
Win32/Gapz.C (MBR)
SHA1 hash: b37afc51104688ea74d279b690d8631d4c0db2ad
If someone can provide a sample, please upload. Thanks!
Malware Reversing
http://www.malware-reversing.com
http://www.malware-reversing.com