A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #27879  by leeno
 Mon Feb 15, 2016 4:23 pm
Hi Guys ,

I am posting MS details of the Malware but i lack information on the hashes for these samples . It would be great if you could share the samples .
1.
Details :
https://www.microsoft.com/security/port ... Spursint.A
2.
Details :
http://www.microsoft.com/security/porta ... 2/Hadsruda
3.
Details :
https://www.microsoft.com/security/port ... in32/Peals

Warm Regards

Leeno
 #27886  by skyhighatrist
 Wed Feb 17, 2016 9:42 am
Win32\Peals sample (using hash from McAfee).

https://home.mcafee.com/VirusInfo/Virus ... 67994#none

MD5: 7ae2189384d66b5009836faec62bb104
SHA1: f9c927bec2dad31561ad4eb58e811eb2be380179
SHA256: 32c7baee44aea9b745f38389e6a9be8b885dc026c94535623ed0cd78e2aa1bd2

Zip password is "infected" (without quotes).
password: infected
(1.02 MiB) Downloaded 56 times
I'll keep trying to find the others...