A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #23048  by EP_X0FF
 Thu Jun 05, 2014 6:47 am
Virus:Win32/Floxif is a family of viruses that infect Windows executable and DLL files to download and install other malware onto your computer.

MD5 00add4a97311b2b8b6264674335caab6
SHA1 3688de985909cc9f9fa6e0a4f2e43d986fe6d0ec
SHA256 812af0ec9e1dfd8f48b47fd148bafe6eecb42d0a304bc0e4539750dd23820a7f

https://www.virustotal.com/en/file/812a ... /analysis/

Complete description can be found here

Malware payload dll (drops to %CommonProgramFiles%\System\symsrv.dll)
https://www.virustotal.com/en/file/eaf7 ... /analysis/

Floxif name comes from dll export name "FloodFix".
Attachments
pass: infected
(262.09 KiB) Downloaded 132 times