A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #17599  by EP_X0FF
 Fri Jan 04, 2013 5:31 pm
Aleksandra wrote:MD5: 059789e2e3920a773d12c0706c80896b
SHA1: 685c517483788734538cef992ea35332f744908f
https://www.virustotal.com/file/f189b7accd52d6bd415f193c8ce9e1edb6248d712ef656b1ed6b53250bfad9f2/analysis/
Gate: hxxp://94.102.63.196/_cp/gate.php;300

pass for decrypted config: 2C6C79E4A55E89B12DB309127695B09A

Decrypted exe and config in attach (was VB runpe).

ver=10348
Attachments
pass: malware
(115.28 KiB) Downloaded 88 times
 #17606  by Xylitol
 Fri Jan 04, 2013 6:31 pm
Code: Select all
SYN1: http://94.102.63.196/f1/
CN1: http://94.102.63.196/l1/
hydra -l admin -P pwd.lst -s 80 -w 64 -f -V 94.102.63.196 http-post-form "/f1/ajax/login.php:password=^PASS^:Wrong password"
hydra -l admin -P pwd.lst -s 80 -w 64 -f -V 94.102.63.196 http-post-form "/l1/mod/auth.php:pass=^PASS^:Wrong password"
 #18790  by Xylitol
 Mon Apr 01, 2013 12:03 pm
Code: Select all
hxx://SuperAdsDomain.ru/bl/build___0cf972e4.exe

hXXp://91.231.156.42/_cp/gate.php
http://91.231.156.42/adm/frmcp/
http://91.231.156.42/adm/maincp/

guid=6.1.7600!ADMIN-PC!78599FED&ver=10348&ie=8.0.7600.16385&os=6.1.7600&ut=Admin&ccrc=BDC13D7B&md5=f414ee4ce5ca2900932ec075aab76947&plg=ccgrabber;customconnector;ftpb
admin:16B21AE0C9A2D4EB106B505FB8F08510:521:35
http://www.virustotal.com/file/53d03128 ... 364817703/
Attachments
infected
(182.77 KiB) Downloaded 89 times
 #18799  by EP_X0FF
 Mon Apr 01, 2013 5:52 pm
Pass for decrypted config: AB39D0B8B0C6CFAD363E328D66C8ACB3

customconnector config
Code: Select all
hxxp://91.231.156.42/_cp/gate.php;300
hxxp://mrricco.com/_cp/gate.php;300
hxxp://mrpokko.com/_cp/gate.php;300
hxxp://mrdep.net/_cp/gate.php;300
hxxp://mrovi.net/_cp/gate.php;300
hxxp://mrtony.com/_cp/gate.php;300
hxxp://frenking.com/_cp/gate.php;300
hxxp://pidlisro.com/_cp/gate.php;300
hxxp://tiskaliorg.net/_cp/gate.php;300
hxxp://stradivarri.com/_cp/gate.php;300
hxxp://bet365x7.net/_cp/gate.php;300
Decrypted dropper attached.

https://www.virustotal.com/en/file/d985 ... /analysis/
Attachments
pass: infected
(110.4 KiB) Downloaded 78 times
(5.34 KiB) Downloaded 75 times
  • 1
  • 38
  • 39
  • 40
  • 41
  • 42