A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #22978  by Blaze
 Mon May 26, 2014 11:24 am
Droppers + driver attached.

Exe:
a5923e1efd90be7542c779184f4a7843
f681b38447a16e4d6c9ae4837bfb407b

Sys:
fb7a765c02c06123958c20512c1b8e6a
Attachments
(571 KiB) Downloaded 123 times
 #23027  by thisisu
 Tue Jun 03, 2014 5:50 am
Credits to Malekal_morte for providing dropper on his website.

.sys + .exe/dropper attached

syshost.exe -- dabea808bb91f02e158cdbcbf3e8a790 -- https://www.virustotal.com/en/file/2b64 ... 401773988/
79051d41d365f350.sys -- ca82853fd71df06831edf7ffede4b1d5 -- https://www.virustotal.com/en/file/b94e ... 401773274/
Attachments
necursgen.png
occurs after reboot
necursgen.png (143.47 KiB) Viewed 767 times
pass: infected
(109.07 KiB) Downloaded 133 times
 #23464  by achn30
 Tue Jul 29, 2014 10:18 pm
I have some thing here: virustotal.com/en/file/c8b6ae219c944f4a6362b22dad1a3cf25a31ca2dbe5ec96d645c031ad7332bf0/analysis/1406668147/
but actually i stuck in unpacking ... lot of anti-debugging tricks ://
 #23467  by EP_X0FF
 Wed Jul 30, 2014 4:07 am
It is Necurs downloader.
  • 1
  • 4
  • 5
  • 6
  • 7
  • 8