A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15526  by kareldjag/michk
 Wed Sep 05, 2012 5:11 pm
Hi
The rootkit terminology comes first from the Unix world on the 90"s, followed in 2000s years by the Windows platform.
On Unix systems, a rootkit could be a simple script that hides sockets, a shell or a more complete toolkit.
Then just to share a few samples, as most files are available at Packetstorm servers...
Just begins by the Russian Mafix Team Rootkit, like many other Russian team, known for its custom and cybercrime services.
Mafix Rootkit
VT 2010 https://www.virustotal.com/file/793e0c7 ... /analysis/

VT 2012 https://www.virustotal.com/file/793e0c7 ... 346864094/

Edit. Title and typo
Attachments
Orginal file inside a password (kernelmode.info) protected zip
(285.93 KiB) Downloaded 65 times
 #16190  by kareldjag/michk
 Sun Oct 21, 2012 1:11 pm
hi

A fresh one for Apple world, OSX Rubilyn Rootkit
https://www.virustotal.com/file/0793629 ... 350821937/

https://www.virustotal.com/file/1f1be28 ... 350824387/
http://r.virscan.org/report/8cb0769ab0e ... 64df6.html
Is it serious to trust antivirus...even Flashback trojan coders have not included massive anti-av routines
http://waxy.org/2012/04/flashback_troja ... n_antivir/
Attachments
password: kernelmode.info
(46.3 KiB) Downloaded 68 times