A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #21757  by Xylitol
 Sat Dec 21, 2013 12:21 pm
This is not new and it's mainly based on N0PE Systems.
i guess you refer to this http://news.softpedia.com/news/Trojan-F ... 0796.shtml
Code: Select all
The threat was first identified by a security researcher from Malwared.ru, who posted a picture of the threat’s command and control (C&C) panel on Twitter.
bullshit, the threat was first identified on vx.vault, malware was downloaded from a zeus if i remember, i saw that on cuckoo.
Attachments
infected
(558.53 KiB) Downloaded 60 times
infected
(1.33 MiB) Downloaded 66 times
 #21766  by Linkcabin
 Sun Dec 22, 2013 1:12 pm
Checked out these decryption scripts these guys give and they work on most of the encryption. All keys I found were in plain text which I thought was funny.

http://www.arbornetworks.com/asert/2013 ... f-ferrets/
Xylitol wrote:This is not new and it's mainly based on N0PE Systems.
i guess you refer to this http://news.softpedia.com/news/Trojan-F ... 0796.shtml
Code: Select all
The threat was first identified by a security researcher from Malwared.ru, who posted a picture of the threat’s command and control (C&C) panel on Twitter.
bullshit, the threat was first identified on vx.vault, malware was downloaded from a zeus if i remember, i saw that on cuckoo.
Correct the panel is from N0PE but the bin isn't.