A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #9379  by rough_spear
 Sun Oct 23, 2011 6:49 pm
Hi All,
ZAccess Dropper. :twisted:

File name - X
VT link - http://www.virustotal.com/file-scan/rep ... 1319244459
MD5 : a381c34ae0ce20140e0abf84398f87e2
SHA1 : 604a30bce63cfe812465edc8544985ed5d39e248
SHA256: 5d927bb725a3fcfb5a9c04813b3d4b41b587f206d555eedaf260216bca99d2ea
ssdeep: 1536:vDG/kmsGmVpiQ1RZxGHi2CM32kRctzb6K:6e7ui2CM32kG
File size : 59392 bytes

Regards,

rough_spear. ;)
Attachments
password - malware.
(46.82 KiB) Downloaded 96 times
 #9449  by rkhunter
 Sat Oct 29, 2011 2:58 pm
markusg wrote:GeoStar.3D.GeometrieBaukasten.keygen.exe
MD5   : a94f8cccea9b9dbc923ac128053fb0cc
https://www.virustotal.com/file-scan/re ... 1319897872
http://www.threatexpert.com/report.aspx ... 28053fb0cc
http://camas.comodo.com/cgi-bin/submit? ... bf69322983
Registers in winlogon->shell, create fake service, using $NtUninstallKB23832$\816222785.
Attachments
(892 Bytes) Downloaded 64 times
 #9551  by rough_spear
 Sat Nov 05, 2011 7:46 pm
Hi, :D
ZAccess files and plugins from ZAccess infected systems. 8-)

File name - X
VT link - http://www.virustotal.com/file-scan/rep ... 1320132829

File name - 800000cb.@
VT link - http://www.virustotal.com/file-scan/rep ... 1320320210

File name - 80000000.@ (comparatively low detection)
VT link - http://www.virustotal.com/file-scan/rep ... 1320514888

File name - ad4.tmp.exe (I don't know what it is, i tried running it in sandbox and vm but yields no result, malware or innocent file) :?:
VT link - http://www.virustotal.com/file-scan/rep ... 1320495081

Regards,

rough_spear. ;)
Attachments
password - malware.
(206.5 KiB) Downloaded 65 times
 #9557  by EP_X0FF
 Sun Nov 06, 2011 4:40 am
rough_spear wrote:File name - ad4.tmp.exe (I don't know what it is, i tried running it in sandbox and vm but yields no result, malware or innocent file) :?:
This is small console application that checks files in windows directory for suspicious ads and logs results into C:\AlternateDataStreams.log
Code: Select all
sprintf(&Buffer, "%-12s %s", "Status", "ADS File Path");
WriteToDebugLog(&chDebugLogFileName, &Buffer);
WriteToDebugLog(&chDebugLogFileName, "===============================================================");
sprintf(&Buffer, "%-12s %s", "Infected", &chFileName);
WriteToDebugLog(&chDebugLogFileName, &Buffer);
printf("\n%s", "===============================================================");
printf(" \nADS Found !!!");
printf("\n%s", "===============================================================");
 #9608  by cjbi
 Wed Nov 09, 2011 3:24 pm
Hello all

ZeroAccess files from infected machine.

VirusTotal result(s):
dogsex_08.avi.exe.vir (17/42 (40.5%)) http://www.virustotal.com/file-scan/rep ... 1320850765

DriverObject_Memory_Dump_1.vir (2/42 (4.8%)) http://www.virustotal.com/file-scan/rep ... 1320847615
DriverObject_Memory_Dump_2.vir (5/42 (11.9%)) http://www.virustotal.com/file-scan/rep ... 1320847937

Desktop.ini.vir (37/43 (86.0%)) http://www.virustotal.com/file-scan/rep ... 1320852484

X.vir (14/42 (33.3%)) http://www.virustotal.com/file-scan/rep ... 1320850806
80000000.@.vir (19/42 (45.2%)) http://www.virustotal.com/file-scan/rep ... 1320846649
800000cb.@.vir (19/43 (44.2%)) http://www.virustotal.com/file-scan/rep ... 1320846229
800000cf.@.vir (13 /43 (30.2%)) http://www.virustotal.com/file-scan/rep ... 1320846317
kmddsp.tsp wrote:z00clicker3
Interesting... 8-)
Attachments
pw: malware
(462.86 KiB) Downloaded 60 times
 #9711  by rough_spear
 Tue Nov 15, 2011 6:29 pm
Hi All, :D
One more ZAccess rootkit sample. :evil:

Web link -
hxxp://hotpic.cc/anurag+9+pro+rar.exe
hxxp://hotpic.cc/atm.breakout.catcher.exe

VT link -http://www.virustotal.com/file-scan/rep ... 1321265328

MD5 : 0413641a36d16b40d3a39a4423d9f49f
SHA1 : 8b84fc0a374a84f97003cdc0885e939081e61ad9
SHA256: 594602dcfca8322af28a6d312e5fccb0d07901916b385ff0c3f0fdd67157e95a
ssdeep: 6144:2QMBL1mXDin/MqgTrLj7IL9pKpVQTvS0RhS/Xa6e2Ah2vrn:XMLmX2/MLnvYIqvS+hAKp2
AMvz
File size : 340480 bytes

File name - X
VT link - http://www.virustotal.com/file-scan/rep ... 1321230520
MD5 : b74577535fa7046e1951ebf208287ae9
SHA1 : 26da3c198c55dbb5cff1f361435ae7199b484db4
SHA256: f6cfb3680a14d78684dd52068c8c68eea3c4404e8e0add11acc442f4646421e6
ssdeep: 1536:oU5D7/Ot6d1srOYbBdYGK5xVU+hkBjHs:oa34WsnXYP5jU+OBI
File size : 60416 bytes


Regards,


rough_spear. ;)
Attachments
password - malware.
(350.31 KiB) Downloaded 67 times
  • 1
  • 14
  • 15
  • 16
  • 17
  • 18
  • 38