Hum I don't know the name for these:
2 sample of the same family:
a077a9dc0c191621b1b4ca3e9801da2a https://www.virustotal.com/fr/file/a253 ... 445461460/
16e0879b63ffd98ab5adfca27e78a7aa https://www.virustotal.com/fr/file/cf06 ... 445461458/
All attached
2 sample of the same family:
a077a9dc0c191621b1b4ca3e9801da2a https://www.virustotal.com/fr/file/a253 ... 445461460/
16e0879b63ffd98ab5adfca27e78a7aa https://www.virustotal.com/fr/file/cf06 ... 445461458/
Code: Select all
fa1e987e4290da75f3bdb661f51f8e2b - https://www.virustotal.com/fr/file/52b6 ... 445461458/Fuck OFF
Hello AV
GetProcAddress
CreateProcessW
SetThreadContext
VirtualAllocEx
WriteProcessMemory
NtUnmapViewOfSection
CreateProcessW
VirtualFree
ReadProcessMemory
NtUnmapViewOfSection
ntdll.dll
0xDEADBEEF
FindResource
Kernel32.dll
GetWindowsDirectoryW
Kernel32.dll
SYSTEMROOT
\system32\drivers\avc3.sys
\system32\drivers\aswSP.sys
\system32\drivers\aswFsBlk.sys
\system32\drivers\pavproc.sys
\system32\drivers\pavboot64.sys
\system32\drivers\cmdhlp.sys
\system32\drivers\inspect.sys
\system32\drivers\cmdmon.sys
\system32\drivers\AVGIDSErHr.sys
\system32\drivers\avgdiskx.sys
\system32\drivers\avgidsdriverlx.sys
\system32\drivers\mbam.sys
\system32\drivers\mbamchameleon.sys
\system32\drivers\kl1.sys
\system32\drivers\klif.sys
ExitProcess
CreateMutexW
VirtualFree
GetConsoleWindow
GetLastError
VirtualAlloc
GetEnvironmentVariableA
FindFirstFileA
Sleep
GetModuleFileNameW
GetProcAddress
GetModuleHandleA
GetFileSize
CreateProcessW
WriteFile
ReadFile
CreateFileW
CloseHandle
FindResourceW
LoadResource
SizeofResource
LockResource
VirtualProtect
GetThreadContext
GetCurrentProcess
GetModuleHandleW
ReadProcessMemory
TerminateProcess
ResumeThread
KERNEL32.dll
ShowWindow
USER32.dll
SHGetFolderPathW
SHELL32.dll
RtlUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
ping -n 1 127.0.0.1 > nul
start /b "" "%AppData%\EEbeFAMMrx.exe"
ping -n 3 127.0.0.1 > nul
del "%AppData%\EEbeFAMMrx.exe"
(goto) 2>nul & del "%~f0"
BM60
Code: Select all
+ VB stuff inside this one.MSVBVM60.DLL
ance
0g62l
Form1
Stpe
POS_TIME
RCount
Arial
LCount
Arial
S_USB
GHOST
VB5!
INSTALL_B
UNISTALL_B
UPDATE_B
DW_EXEC
N_CONNECT
F_UAC
F_EXIST
S_EXEC
MELT
MY_PATH
G_OS
FTPUPLOAD
A_ANUBIS
D_REG
D_TASK
A_OLLY
A_SAND
A_SYS
A_BOX
A_VM
D_API
DropBox
S_PROTECT
C_DATA
R_DATA
A_MALWR
A_NORMAN
A_WINE
A_FIREWALL
M_BYTES
E_286
G_ARC
D_PROTECT
S_XOR
G_RAM
G_CPU
G_GPU
G_HD
B_64
G_BETWEEN
A_RES
P_PWD
P_FTP
P_MAIL
P_UDP
P_HTTP
P_SCREEN
P_WALLET
P_SPAM
P_KEYLOGGER
C_EOF
P_DSPREAD
N_COMMANDS
PING_SITE
GR_COMMAND
0g62l
LCount
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
POS_TIME
S_USB
GHOST
Stpe
Form
RCount
wininet.dll
DeleteUrlCacheEntryA
SHELL32
IsUserAnAdmin
hhO@
KERNEL32
Sleep
LoadLibraryA
FindExecutableA
hXP@
ShellExecuteA
GetModuleFileNameA
GetStartupInfoW
h4Q@
CreateToolhelp32Snapshot
Process32First
Process32Next
h$U@
CloseHandle
hhU@
GetCurrentProcessId
NTDLL
NtUnmapViewOfSection
h8X@
NtWriteVirtualMemory
NtSetContextThread
NtResumeThread
h$Y@
NtGetContextThread
hpY@
NtAllocateVirtualMemory
CreateProcessW
VBA6.DLL
:u9k
InternetCloseHandle
InternetOpenA
InternetOpenUrlA
All attached
Attachments
infected
(170.49 KiB) Downloaded 105 times
(170.49 KiB) Downloaded 105 times