A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #8760  by nullptr
 Tue Sep 27, 2011 5:14 am
markusg wrote:Install.exe
MD5   : 559a09461edbf7c31640db8e617e214d
https://www.virustotal.com/file-scan/re ... 1317051570
This is Rebhip/Spatet variant.
Decrypt stage 1, TensilCrypt - http://www.virustotal.com/file-scan/rep ... 1317099707
Decrypt stage 2 - http://www.virustotal.com/file-scan/rep ... 1317099535

edit: TensilCrypt can throw an error due to AntiVM. Just search for (VIRTUAL, VBOX, Sbie.dll etc) strings and change them.
All in attachment.
Attachments
pwd: malware
(548.38 KiB) Downloaded 50 times
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7