A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #27303  by maddog4012
 Wed Nov 25, 2015 3:55 pm
Do you have any samples or hash values for ModPOS
 #27325  by R136a1
 Thu Nov 26, 2015 9:09 pm
Hi folks,

some info about this malware can be found here: http://www.isightpartners.com/2015/11/modpos/

Because the report does not mention any file hashes (which sucks!), I thought I give it a try and finally found some droppers. Might be older versions, since the PE time stamps date back to 2012. Anyway, better than nothing...

Droppers:
https://www.virustotal.com/en/file/4e32 ... /analysis/
https://www.virustotal.com/en/file/2aa3 ... /analysis/
https://www.virustotal.com/en/file/6c9d ... /analysis/
https://www.virustotal.com/en/file/4739 ... /analysis/
https://www.virustotal.com/en/file/f4ea ... /analysis/

Main driver component can be found here: http://www.kernelmode.info/forum/viewto ... =20&t=4119

Regards
Attachments
PW: infected
(288.58 KiB) Downloaded 98 times