A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #8387  by EP_X0FF
 Fri Sep 02, 2011 11:56 pm
SpyEye v1.3.45

Pass for decrypted config: D822B811023197A44BF9BA0116660963

Gates:
hxxp://www.fullfreepoker.info/gate1.php;120
hxxp://www.p0k3r.info/gate.php;460
hxxp://www.m4st3r.eu/gate;360
Plugins: customconnect, ccgrabber, ffcertgrabber, rdp, socks5, spySpread.

Original, unpacked and decrypted config in attach.

VT 30/ 44 (68.2%)
http://www.virustotal.com/file-scan/rep ... 1315006986
Attachments
pass: malware
(837.23 KiB) Downloaded 71 times
 #8389  by EP_X0FF
 Sat Sep 03, 2011 1:27 pm
SpyEye v1.2.99

Pass for decrypted config: B958C8D4ED8EE82523308468ED8EAAE3

Gates:
hxxp://ping.indiatours.gen.in/ads/gate.php
hxxp://indiatoursback.in/ads/gate.php
hxxp://indiatoursbck.gen.in/ads/gate.php
hxxp://siriusprojback.net.in/ads/gate.php
Original, unpacked and decrypted config in attach.

VT 30/ 44 (68.2%)
http://www.virustotal.com/file-scan/rep ... 1315055010

SpyEye v1.3.4x

Pass for decrypted config: AB39D0B8B0C6CFAD363E328D66C8ACB3

Gates:
hxxp://totdisseny.net/gate.php;90
hxxp://dongdog.ru/_cp/gate.php;90
hxxp://orgnetpro4u.ru/_cp/gate.php;90
hxxp://bannermegan2all.ru/_cp/gate.php;90
hxxp://feelfree2us.ru/_cp/gate.php;90
hxxp://orgnetpro4u.uni.cc/_cp/gate.php;90
hxxp://bannermegan2all.uni.cc/_cp/gate.php;90
hxxp://feelfree2us.uni.cc/_cp/gate.php;90
hxxp://orgnetpro4u.cz.cc/_cp/gate.php;90
hxxp://bannermegan2all.cz.cc/_cp/gate.php;90
hxxp://feelfree2us.cz.cc/_cp/gate.php;90
Original, unpacked and decrypted config in attach as Malware2.rar

VT 26 /44 (59.1%)
http://www.virustotal.com/file-scan/rep ... 1314983610
Attachments
pass: malware
(243.02 KiB) Downloaded 60 times
pass: malware
(276.75 KiB) Downloaded 56 times
 #8396  by EP_X0FF
 Sun Sep 04, 2011 1:40 am
SpyEye v1.3.4x

Pass for decrypted config: 9C7E5474950BB49E47B6DD88D6B2906F

Capable to distribute itself through available shared network drives as autorun worm, so be careful.

Gates:
hxxp://91.223.82.20/account/gate.php;60
hxxp://dailyforexedge/account/gate.php;60
Plugins: customconnect, ftp backconnect, socks5.

Original, decrypted + config in attach.

VT 31 /44 (70.5%)
http://www.virustotal.com/file-scan/rep ... 1315097553
Attachments
pass: malware
(1.2 MiB) Downloaded 75 times
 #8398  by EP_X0FF
 Sun Sep 04, 2011 10:24 am
SpyEye v1.3.4x

Payload of the Blackhole exploit kit (nnm.copyfighter.org/main.php?page=096ecc0d8a14102c)

Pass for decrypted config: 130CBE0950491F6148A65482B9B50CC4

Gates:
hxxp://secur3storag3.com:8080/pic1s0fs.php;150
hxxp://war9932rerew.co.cc:8080/pic1s0fs.php;150
hxxp://refg4thu56j7kfbnm.cz.cc:8080/pic1s0fs.php;150
hxxp://tbyu657ib7k67iddro.cx.cc:8080/pic1s0fs.php;150
hxxp://uybkyukn78k67rvjyro.co.cc:8080/pic1s0fs.php;150
hxxp://hgbu67bjyrturtyuk.info:8080/pic1s0fs.php;150
hxxp://hgbu67bjyrturtyuk.org:8080/pic1s0fs.php;150
hxxp://fgbnutyfhfgjdfghjil.cn:8080/pic1s0fs.php;150
hxxp://fgbnutyfhfgjdfghjil.com:8080/pic1s0fs.php;150
hxxp://h2323yrturtyuk.com:8080/pic1s0fs.php;150
Plugins: customconnector

Original + decrypted config in attach.

VT 10/ 44 (22.7%)
http://www.virustotal.com/file-scan/rep ... 1315129430
Attachments
pass: malware
(265.79 KiB) Downloaded 61 times
 #8427  by nullptr
 Tue Sep 06, 2011 7:08 am
SpyEye
Plugins:
ccgrabber
connector2
mch_3_5

Gates:
hxxp://tiritopi.org/mainapp/gate4df.php;350
hxxp://chesterfield.net.in/default.php;300
hxxp://dekormorion.ru/includes/route.php;500
unpacked - http://www.virustotal.com/file-scan/rep ... 1315292248
original - http://www.virustotal.com/file-scan/rep ... 1315292343

Everything in attachment.
Attachments
pwd: malware
(583.42 KiB) Downloaded 61 times
 #8456  by EP_X0FF
 Wed Sep 07, 2011 5:59 pm
SpyEye v1.3.4x

Payload of Blackhole exploit kit (jy6d.com/main.php?page=032e0888f2c5d72e)

Pass for decrypted config: B4EF3D9AF202D34BC9EE08E5892BCFF5

Gates:
hxxp://win32updatenow.com/_pigeons_/_go.php;90
hxxp://allegro.gmb.pl/UNIPARTS/gdb1115/P1021029.php;90
hxxp://orumearchsdelaltruk.info/_cp/gate.php;90
Plugins: customconnector, ActiveAZ.

Original, decrypted + config in attach.

VT 6/ 44 (13.6%)
http://www.virustotal.com/file-scan/rep ... 1315417934
Attachments
pass: malware
(258.44 KiB) Downloaded 61 times
 #8519  by EP_X0FF
 Sun Sep 11, 2011 1:18 am
Dictionary based brute-force.
  • 1
  • 24
  • 25
  • 26
  • 27
  • 28
  • 42