Captain Obvious to the rescue? It would be so cool if it wasn't so obvious from the thread.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
ReviewsAntivirus wrote:This is ZeroAccess?This one is ZeroAccess CLSID.
AFFBA411A853948FEACB50E75EA18DC4 - https://www.virustotal.com/file/a54fd0d ... /analysis/
Tigzy wrote:It's me or they have removed every easy findable signature (ZwQueryFileEa)?There are 2 variants of Sirefef 2012 infector. Both with different infection methods and different shellcode
In the last dropper, I only see ASLR bit switched and a code part:
ReviewsAntivirus wrote:This is ZeroAccess?Yes all Sirefef. All modules in attach.
DC68B058868FC998D775A4922D8CD44C - https://www.virustotal.com/file/1d16b57 ... /analysis/
EF2F92E2E543F57EE40A1DB37C111D73 - https://www.virustotal.com/file/5d71358 ... /analysis/