Fresh PbBot bootkit dropper.
Obvious Korean targeted malware is obvious.
Very short analysis:
6B92F6E2390444EB52562E494F87D392 (Legit installer + Downloader) -> Drop & Execute ->
-> CA536C5C9C3BAD792D503F4279F0FFB8 (Downloader) -> Download & Execute -> 39AEC94919064E03CD11B487AEE08CFA (Bootkit)
... and more payloads... 294AEB00F6945BF8867C0400D87393B0 (explorer.exe inside(tm)), 61EC58BC4B61E17E75E3033F657D36CD (OnlineGameHack)
More detailed analysis:
Plite Bootkit Spies on Gamers (by Bitdefender)
Some strings:
Code: Select all...
FAT12
FAT16
FAT32
NTFS
\\.\PHYSICALDRIVE0
_uninsep.bat
...
inflate 1.1.3 Copyright 1995-1998 Mark Adler
- unzip 0.15 Copyright 1998 Gilles Vollant
...
Invalid partition table
Error loading operating system
Missing operating system
...
Invalid partition table
Error loading operating system
Missing operating system
no active partition found
read error while reading drive
partition signature != 55AA
:Repeat
del "%s"
if exist "%s" goto Repeat
rmdir "%s"
del "%s"
...
explorer.exe
...
explorer.exe
_GBP
...
_C_FILE_INFO=
...
Invalid partition table
Error loading operating system
Missing operating system
------- IsPMSInstalled -------------
C:\Windows\system32
Windows folder not exist!
golfinfo.ini
C:\Windows\system32\golfinfo.ini
.exe
------- ExistAgentFile -------------
agent file name :
C:\Windows\system32
Windows folder not exist!
C:\Windows\system32
capture file path :
Starting GBP...
_GBP
_GBP
RestoreSectorNum:
RestoreSize:
Boot Sector number:
Reading boot sector Failed!
SectorsPerCluster:
winlog file already exist!
File Creating Fail!
File Creating Fail!
Get File System Failed!
Install OK!!
Please reboot
Install failed!!
Please reboot
FAT12
FAT16
FAT32
NTFS
Read Mbr Sector failed!!!
Reading Fail!
Writing Fail!
Not FAT32!
Read FAT Failed!
Read FAT Failed!
Finding "
" from
Read FAT Failed!
Finding File Name:
Not Found!
Found!
Finding File Name:
Not Found!
Found!
----------- FAT32_CreateFile -------------
Already Exist!
-------- FAT32_ReplaceFileData ---------
Does Not Exist!
Creating File Name:
Writing Cluster Count:
Read FAT Failed!
Written Cluster Count:
Read FAT Failed!
NTFS
Not NTFS!
Finding File Name:
Reading boot sector Failed!
Reading MFT Failed!
Finding directory Fail:
Found!
Writing Sector Count:
Written Sector Count:
Finding:
Index buffer count
change directory entry success
read standard attribute of prev file failed
find filename attribute of prev file failed
write new file record failed
Get Data Attribute failed
WriteAttributeDataFromDisk failed
ReplaceFileDataAttr failed
-------------- NTFS_CreateFile ------------
Start.exe
0.000
Directory Rec No:
File Rec No:
Creating File Record
Reading File Record failed
Creating Directory Entry
--------- NTFS_ReplaceFileData --------
Not Found
Directory Rec No:
File Rec No:
Reading File Record failed
...
MS Run-Time Library - Copyright (c) 1992, Microsoft Corp
_C_FILE_INFO=
------- IsPMSInstalled -------------
C:\Windows
Windows folder not exist!
gbp.ini
C:\Windows\gbp.ini
Starting GBP...
Unpartition Sector Number:
ReadInitData failed!
_GBP
GBP Data Error!
Boot Sector number:
Reading boot sector Failed!
SectorsPerCluster:
File Creating Fail!
File Creating Fail!
Get File System Failed!
Install OK!!
Please reboot
Install failed!!
Please reboot
FAT12
FAT16
FAT32
NTFS
Read Mbr Sector failed!!!
Reading Fail!
Writing Fail!
Not FAT32!
Read FAT Failed!
Read FAT Failed!
Finding "
" from
Read FAT Failed!
Finding File Name:
Not Found!
Found!
Finding File Name:
Not Found!
Found!
----------- FAT32_CreateFile -------------
Already Exist!
-------- FAT32_ReplaceFileData ---------
Does Not Exist!
Creating File Name:
Read FAT Failed!
Read FAT Failed!
NTFS
Not NTFS!
Finding File Name:
Reading boot sector Failed!
Reading MFT Failed!
Finding directory Fail:
Found!
Finding:
Index buffer count
change directory entry success
read standard attribute of prev file failed
find filename attribute of prev file failed
write new file record failed
Get Data Attribute failed
WriteAttributeDataFromDisk failed
ReplaceFileDataAttr failed
-------------- NTFS_CreateFile ------------
Start.exe
0.000
Directory Rec No:
File Rec No:
Creating File Record
Reading File Record failed
Creating Directory Entry
--------- NTFS_ReplaceFileData --------
Not Found
Directory Rec No:
File Rec No:
Reading File Record failed
...
VirusTotal result(s):
Currently, MBR only. I'm too lazy to upload. :twisted:
mbr.bin 1/44
https://www.virustotal.com/file/2c781e0 ... /analysis/
P.S. PbBot is not new malware! :(
P.P.S. Thank you, EP_X0FF! :)