A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #14655  by rkhunter
 Sun Jul 15, 2012 11:33 am
SHA1: 799b13fc163c040b224410f8d69c5efbd1bee9fe
MD5: 1db68c69d45d240d7efc9e3997003845


One more dropper with payload in attach.
Attachments
pass:infected
(290.54 KiB) Downloaded 74 times
 #14675  by SecConnex
 Mon Jul 16, 2012 5:51 am
I don't know about the Sirefef tool against the latest. I do know the Services tool helps repair broken/damaged Services, as I just used it recently. I actually used it for somebody whose install of ESET products was not allowing updates. After the Service Repair Tool, ESET software functioned.
 #14945  by dumb110
 Tue Jul 31, 2012 8:06 am
SHA1:0e4a18c535452158d24dcd714a898e9acb9ebd11
MD5: fb58aa523e31161b7c2654b31eb62076

Brand new! https://www.virustotal.com/file/3a5c7a4 ... /analysis/

0/42... http://anubis.iseclab.org/?action=resul ... ormat=html
Attachments
Pw: infected
(171.82 KiB) Downloaded 72 times
Last edited by dumb110 on Tue Jul 31, 2012 8:39 am, edited 1 time in total.
 #14974  by EP_X0FF
 Thu Aug 02, 2012 7:16 am
dumb110 wrote:SHA1:0e4a18c535452158d24dcd714a898e9acb9ebd11
MD5: fb58aa523e31161b7c2654b31eb62076

Brand new! https://www.virustotal.com/file/3a5c7a4 ... /analysis/

0/42... http://anubis.iseclab.org/?action=resul ... ormat=html
It isn't new, simple crypter refined. Actually most components are the same, some dated back to beginning of July.
Attachments
pass: malware
(76.84 KiB) Downloaded 56 times
 #14976  by EP_X0FF
 Thu Aug 02, 2012 7:31 am
dumb110 wrote:https://www.virustotal.com/file/beeda9d ... /analysis/
attached...
Not password protected - removed and reuploaded in combined archive (inside your original dropper, decrypted dropper and all extracted payload files). Current Sirefef updates only addressing detection of p2p.32.dll (n32) as most detected component after dropper itself.
Attachments
pass: malware
(387.61 KiB) Downloaded 62 times
  • 1
  • 23
  • 24
  • 25
  • 26
  • 27
  • 56