SHA1: 53b1ce48f2b0cf3c7028184676be7b21485bd45a
MD5: ab551ebc28e4cbcdcb44b1175e14038b
Some "trash" or script-kiddie...targeted on profit extraction from games and AhnLab-V3 AV killing. By it this is Dropper/Win32.OnlineGameHack.
Under UPX with driver on board and dll (in resourse section).
Driver:
SHA1: dc0a214282c96306586ac3dffd1540af3f547d42
MD5: 52d513b5bf0dbbfdc9ecc928415a8457
Trojan/Win32.KillAV by AhnLab-V3
5/42 https://www.virustotal.com/file/1c87c17 ... /analysis/
Targeted for kill processes:
:facepalm:
Just for fun:
:facepalm:
Dll:
SHA1: fe852d011be23db6d560528bd027f03dcd80274a
MD5: 3ba32ad45dcb77eb14fd375a843f10cc
Trojan/Win32.OnlineGameHack by AhnLab-V3
23 / 42 https://www.virustotal.com/file/9b6c4c9 ... /analysis/
Masked as WinSock Helper
Dropped to: C:\WINDOWS\system32\WinSocketA.dll
Autorun from AppInit: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
Targeted for kill:
Targeted for hooking a lot of functions in processes:
MD5: ab551ebc28e4cbcdcb44b1175e14038b
Some "trash" or script-kiddie...targeted on profit extraction from games and AhnLab-V3 AV killing. By it this is Dropper/Win32.OnlineGameHack.
Under UPX with driver on board and dll (in resourse section).
Driver:
SHA1: dc0a214282c96306586ac3dffd1540af3f547d42
MD5: 52d513b5bf0dbbfdc9ecc928415a8457
Trojan/Win32.KillAV by AhnLab-V3
5/42 https://www.virustotal.com/file/1c87c17 ... /analysis/
Targeted for kill processes:
naveragent.exeTargeted for unhook splicing of SSDT-services that hooks by driver AhnRghNt.sys.
nsavsvc.npc
nsvmon.npc
nvcagent.npc
nvc.npc
nvcopt.npc
v3lsyc.exe.exe
v3ltray.exe
v3light.exe
v3medic.exe
syrtsry.aye
ayagent.aye
alyac.aye
ayupdsrv.aye
aytask.aye
naveragent.exe
nvcsvcmgr.npc
nvcupgrade.exe
AYTask.aye
:facepalm:
Just for fun:
\??\My_LinkDropped driver to C:\WINDOWSJytVKZN.sys
\Device\my_Device
d:\desktop\öÝÀöïÒ2222\SYS\i386\DDK_HelloWorld.pdb
:facepalm:
Dll:
SHA1: fe852d011be23db6d560528bd027f03dcd80274a
MD5: 3ba32ad45dcb77eb14fd375a843f10cc
Trojan/Win32.OnlineGameHack by AhnLab-V3
23 / 42 https://www.virustotal.com/file/9b6c4c9 ... /analysis/
Masked as WinSock Helper
Dropped to: C:\WINDOWS\system32\WinSocketA.dll
Autorun from AppInit: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
Targeted for kill:
AYAgent.aye
AYUpdSrv.aye
AYServiceNT.aye
AYRTSrv.aye
SystemMon.exe
SkyMon.exe
nsvmon.npc
nvc.npc
nvcagent.npc
Nsavsvc.npc
V3LTray.exe
V3LSvc.exe
V3Light.exe
SgSvc.exe
sgrun.exe
InjectWinSockServiceV3.exe
Targeted for hooking a lot of functions in processes:
iexplore.exe
dnf.exe
MapleStory.exe
lin.bin
ff2client.exe
heroes.exe
ExLauncher.exe
TERA.exe
OTP.exe
AION.bin
wow.exe
fairyclient.exe
dkonline.exe
Diablo III.exe
explorer.exe
Attachments
pass:infected
(2.6 KiB) Downloaded 52 times
(2.6 KiB) Downloaded 52 times
pass:infected
(28.52 KiB) Downloaded 54 times
(28.52 KiB) Downloaded 54 times
pass:infected
(36.94 KiB) Downloaded 58 times
(36.94 KiB) Downloaded 58 times