Page 1 of 1
Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 1:42 am
by dlimanov
Anyone has samples from the FireEye's blog:
https://www.fireeye.com/blog/threat-res ... ecord.html
I think 372f1e4d2d5108bbffc750bb0909fc49 is the one that starts the show.
Re: Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 2:41 pm
by p1nk
From my quick search of the listed hashes, none are on VT.
Re: Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 3:09 pm
by stevegs1821
needs to go in the Request area . . but ..
+1
Re: Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 3:32 pm
by Xylitol
a guy who wrote research said he cant share
Re: Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 7:07 pm
by billbudsocket
I call bullshit. None of the 14 hashes from the report show up in VT.
Re: Sample of FireEye's BootKit?
PostPosted:Tue Dec 08, 2015 9:10 pm
by frame4-mdpro
billbudsocket wrote:I call bullshit. None of the 14 hashes from the report show up in VT.
Jeez, not all the malware is on VT you know, especially not the really "juicy" ones -- they even admit to this; I'd say they have about 70% give-or-take. There are a lot of occasions (read: malware campaigns) where malware samples do not appear on VT, period.
Re: Sample of FireEye's BootKit?
PostPosted:Wed Dec 09, 2015 1:16 pm
by robemtnez
billbudsocket wrote:I call bullshit. None of the 14 hashes from the report show up in VT.
372f1e4d2d5108bbffc750bb0909fc49 is the installer, the other hashes belong to resources obtained from the same malware. They won't upload anything to VT if the the investigation is still running.
Re: Sample of FireEye's BootKit?
PostPosted:Thu Dec 10, 2015 10:18 pm
by rexor
billbudsocket wrote:I call bullshit. None of the 14 hashes from the report show up in VT.
Just some notes, about the report from fireeye:
- - No explanation about the way this thing does the installation.
- FireEye does not share it
- Nothing is not VT
- The sample supports x64/x32 and is a bootkit
I'd guess there is some sort of zero-day inside the dropper/loader which could explain most of the above.
So, let's wait till the right time come for the share
Re: Sample of FireEye's BootKit?
PostPosted:Fri Dec 11, 2015 3:36 am
by p1nk
With it being described as a threat that's been around for a while, it's strange to not have more public hashes.
Re: Sample of FireEye's BootKit?
PostPosted:Thu Jan 28, 2016 4:55 am
by EP_X0FF
Another crap from BIOS era. "Advanced by design". Closed and moved to completed.