MD5: a2e6b61bc477038a0d5b0fac279723ee
12/43
12/43
Attachments
pass:infected
(72.63 KiB) Downloaded 112 times
(72.63 KiB) Downloaded 112 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:from infected pcThis is Ramnit bundled with SdtRestore driver.
c:\project\demetra\loader~1\drivers\ssdt\driver~1\objfre_win7_x86\i386\SdtRestore.pdbAttached decrypted dropper. Posts moved.
markusg wrote:this is a damaged filetry to change mz to MZ and pe to PE
dumb110 wrote:New varient of ramnit in attach! :DIt isn't new, or not even refined. It simple hexed as pointed above.
https://www.virustotal.com/file/e68d075 ... 343465556/