A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20755  by R136a1
 Mon Sep 09, 2013 8:52 am
Hi there,

my latest article about a downloader with "rootkit" capabilities:
http://thegoldenmessenger.blogspot.de/2 ... f-old.html

Samples attached.

Regards
Attachments
PW: infected
(70.39 KiB) Downloaded 34 times
PW: infected
(39.93 KiB) Downloaded 34 times
 #20756  by EP_X0FF
 Mon Sep 09, 2013 9:55 am
This is variant of old Haxdoor lolkit. It suffered from bugs related to hooking as well (no WP bit clean, MP unfriendly etc). Unworkable junk.