A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15659  by EP_X0FF
 Tue Sep 18, 2012 12:07 pm
Nothing interesting, all mad skills and pretty lame, however it was delivered directly to me, so I decided to post it there. Written on VB and crypted with some RunPE based cryptor. Connects to various Yandex hosted narod.ru sites to obtain "hello.txt" with further instuctions I guess. In attach original and decrypted. ICQ message with links to this malware spammed from various ICQ accounts. Uses WScripting to copy file/add autorun reg entries (userinit = "c:\windows\system\winlogon.exe") as "update"

Some fun string from inside
E:\code c#\hspam\test\icq spamer crypted pseudornd\Project1.vbp
Attachments
pass: malware
(118.27 KiB) Downloaded 54 times
 #16700  by EP_X0FF
 Mon Nov 19, 2012 1:03 pm
Another one dropped just now.
Attachments
pass: malware
(144.66 KiB) Downloaded 46 times