Caphaw (Shylock) threads merged.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
kmd wrote:hi
looking for Wolcape.A, Wolcape.B rootkit, bootkit components of Shylock.
http://www.welivesecurity.com/2013/02/2 ... ct-plugin/
Win32/Wolcape.A (driver) 766da148d74f7ea9aca692246a945bd70da6cf18
Win32/Wolcape.B (bootkit dropper) f8da98763e345f42c62db02e51bf5d80342cd4d2
kmd wrote:hiHehehe, Matrosov article entertaining. Yes indeed after reading this cool story with a lot of IDAPro+HexRays screenshots (don't forget also always put some Hiew screenshot - no matter how actually useless this program - it has cool blue hackers view, I also bought it - specially for screenshots), you can think it is something "wow" and super fancy. No it is not.
looking for Wolcape.A, Wolcape.B rootkit, bootkit components of Shylock.
http://www.welivesecurity.com/2013/02/2 ... ct-plugin/
Win32/Wolcape.A (driver) 766da148d74f7ea9aca692246a945bd70da6cf18
Win32/Wolcape.B (bootkit dropper) f8da98763e345f42c62db02e51bf5d80342cd4d2
C:\Utils>rootkitrevcons
RootkitRevealer v1.10 - Rootkit detection utility
Copyright (C) 2005 Bryce Cogswell and Mark Russinovich
Sysinternals - www.sysinternals.com
You may not redistribute RootkitRevealer without express written
permission. Contact licensing@sysinternals.com for information.
C:\WINDOWS\SYSTEM32\0.EDP:
Description: Hidden from Windows API.
Date: 3/15/2013 4:50 PM
Size: 27.38 KB
C:\WINDOWS\SYSTEM32\0EDP:
Description: Hidden from Windows API.
Date: 3/15/2013 4:50 PM
Size: 107.00 KB
kmd wrote:Matrosov sharply criticized yestarday when this article was posted on habrahabr, http://habrahabr.ru/company/eset/blog/171929/, watch comments.I don't see anything to blame him in not professionalism. Even having all this screenshots you can't reproduce malware. Programming tricks? Maybe, but I don't see if he posted anything related to antiemulation for example, or any wise trick to detect VM/Sandboxing. Anything else is not important. As for Carberp and "hacker" magazine article, well I broke my mind while reading the part related to injection, work with section objects described even by Richter, and I don't see anything really dangerous in posting it to public (especially in a way as he wrote).