Tyupkin: Manipulating ATM Machines with Malware ~ http://securelist.com/blog/research/669 ... h-malware/
NCR ATM API Documentation Available on Baidu ~ http://www.f-secure.com/weblog/archives/00002751.html
Man arrested in Tyupkin malware cyber attack on UK ATMs ~ http://www.itgovernance.co.uk/blog/man- ... n-uk-atms/
Backdoor:MSIL/Sidkey.A ~ http://www.microsoft.com/security/porta ... ey.A#tab=2
Backdoor.Padpin ~ http://www.symantec.com/security_respon ... 99&tabid=2
XFS 3.20 in attachment for testing purpose, XFS can be downloaded also from the official site here: http://www.cen.eu/work/areas/ict/ebusin ... s-xfs.aspx
Backdoor.MSIL.Tyupkin.a:
https://www.virustotal.com/en/file/b670 ... 412753212/
Backdoor.MSIL.Tyupkin.c:
https://www.virustotal.com/en/file/1616 ... 412753210/
https://www.virustotal.com/en/file/8bb5 ... 412753217/
Backdoor.Win32.Tyupkin.d:
https://www.virustotal.com/en/file/853f ... 412753215/
interesting offsets:
0x41FCF8
0x41FB6D
0x41FACB
9 = Auto remove
3 = Time extend
2 = Dispense cassette menu
1 = Hide Tyupkin
0 = Show Tyupkin
NCR ATM API Documentation Available on Baidu ~ http://www.f-secure.com/weblog/archives/00002751.html
Man arrested in Tyupkin malware cyber attack on UK ATMs ~ http://www.itgovernance.co.uk/blog/man- ... n-uk-atms/
Backdoor:MSIL/Sidkey.A ~ http://www.microsoft.com/security/porta ... ey.A#tab=2
Backdoor.Padpin ~ http://www.symantec.com/security_respon ... 99&tabid=2
XFS 3.20 in attachment for testing purpose, XFS can be downloaded also from the official site here: http://www.cen.eu/work/areas/ict/ebusin ... s-xfs.aspx
Backdoor.MSIL.Tyupkin.a:
https://www.virustotal.com/en/file/b670 ... 412753212/
Backdoor.MSIL.Tyupkin.c:
https://www.virustotal.com/en/file/1616 ... 412753210/
https://www.virustotal.com/en/file/8bb5 ... 412753217/
Backdoor.Win32.Tyupkin.d:
https://www.virustotal.com/en/file/853f ... 412753215/
interesting offsets:
0x41FCF8
0x41FB6D
0x41FACB
9 = Auto remove
3 = Time extend
2 = Dispense cassette menu
1 = Hide Tyupkin
0 = Show Tyupkin
Attachments
no password
(333.49 KiB) Downloaded 258 times
(333.49 KiB) Downloaded 258 times
infected
(204.46 KiB) Downloaded 340 times
(204.46 KiB) Downloaded 340 times