A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #10779  by rkhunter
 Wed Jan 04, 2012 6:25 am
Was catched on NgrBot infected machine.

Installs itself to %windir%.
Opens ports at compromised system, i. e. backdoor.
Also is IRC bot, established connection with IRC server.

http://www.microsoft.com/security/porta ... %2fPushbot

http://www.threatexpert.com/report.aspx ... da8582113f

http://anubis.iseclab.org/?action=resul ... ormat=html
Attachments
pass:malware
(33.1 KiB) Downloaded 79 times
 #14203  by Waves97
 Sat Jun 23, 2012 6:36 pm
Hi! This new malware that appeared on Facebook:
Attachments
password: infected
(164.41 KiB) Downloaded 72 times
 #14204  by Flamef
 Sat Jun 23, 2012 6:47 pm
Yes i saw it too and took a sample.One of my friends was infected by this and asked for assistance,it keeps spamming something about Angela Merkel.
I think it's a dropper,hopefully EP_X0FF and others may be able to enlighten us.I lost the URL from where it comes from due to problems with my VM,sorry.
 #14211  by Flamef
 Sat Jun 23, 2012 8:34 pm
Waves97 wrote:@Flamef
It's scan one of sample in my submission.
So we got the same sample and it seems it's unique.
 #14218  by GMax
 Sun Jun 24, 2012 8:39 am
Waves97 wrote:Hi! This new malware that appeared on Facebook:
Unpacked file without import
Attachments
pas: malware
(23.86 KiB) Downloaded 55 times