Hi All,
Anyone got Citadel 1.3.5.1 Rain Edition Sample? Better if C&C still works. Thank you.
Regards,
A forum for reverse engineering, OS internals and malware analysis
kalptarunet wrote:Hi,
Looking samples for Gozi-Prinimalka, please find few known MD5 listed below.
http://blogs.rsa.com/rsafarl/cyber-gang ... u-s-banks/
Known Gozi Prinimalka MD5 Hashes:
MD5: 09f75a3fcaeb2c46dd67b666a109d844
MD5: c89e960e0155bd9c78889b415de82f55
MD5: a8bc29c5ae35a634adbe63d43a2efaab
MD5: e4065c9aa45afc54003ca2d7ae6f15f1
MD5: ca54385bb345f20454ec0cd1f01ca9f9
Thanks in advance.
--KTX
swapnilpatil1188 wrote:Hi guys,
I'm looking for particular sample of,
a) Dirt Jumper DDos Bot
b) MD5 f29b1089b3f5e076d4d4bd2a3a02d3cb
c) This is Link of virus total analysis
https://www.virustotal.com/file/02422d9 ... /analysis/
Thank you.
eyalbd1 wrote:Hey guys,
I am looking for this Trojan - http://vms.drweb.com/virus/?i=1817029
It comes in many shapes, the most common are -
File Name : UrnatlarRiml.dll
File Size : 13824 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 295b77a25284a7822dfeb5a1039fe526
SHA1 : 5cf9dfddc7f0756f10b97011d966b24ceca8aff8
Online report : http://r.virscan.org/bebb794918f3fee1790ef146ae7aef5f
And
File Name : AsmohtuStuzq.dll
File Size : 13824 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 2dc5f6df3379594bb98d037137b654d1
SHA1 : ae6070e7190f704101c5f32da9edd0dce064127e
Online report : http://r.virscan.org/8c6fc692e7ab1a20d418eeae5492659d
Many thanks.
kodo wrote:Hello!Have a look on the Gauss thread.
Looking for Gauss [...]
Xylitol wrote:C3B8AD4ECA93114947C777B19D3C6059kodo wrote:Hello!Have a look on the Gauss thread.
Looking for Gauss [...]
kodo wrote:alright, i'm sorry, it's in attach.Xylitol wrote:C3B8AD4ECA93114947C777B19D3C6059kodo wrote:Hello!Have a look on the Gauss thread.
Looking for Gauss [...]
ED2B439708F204666370337AF2A9E18F
not found in your pack, but i seen em on VT
Xylitol wrote:hanan wrote:I am looking for a work with the name of TSPY_YUNSIP.E (this is the name that Trend Micro AV gives me , but it seems that it can't clean).
I am don't have a MD5 or SHA-1 for it, but i have done some search and i have found a page from VirusTotal :
https://www.virustotal.com/file/37ab92f ... /analysis/
and another page from Symantec:
http://www.symantec.com/security_respon ... 99&tabid=2
I would like to get the virus by name, if that possible , since i am assume that there are some variants of it and the page i gave from VT is just one of them.
Thanks.