Write-up from Kaspersky from back in Nov.
SHA256:
Packed w/ UPX (UPX 0/1)
Executing in a non-intended environment only makes a few changes to the OS, like:
SHA256:
Code: Select all
Anyone ever take a look into this malware? Share your findings and experiences. I've taken a very quick and limited look so far...dce2d575bef073079c658edfa872a15546b422ad2b74267d33b386dc7cc85b47
Packed w/ UPX (UPX 0/1)
Executing in a non-intended environment only makes a few changes to the OS, like:
Code: Select all
Nothing gets dropped here afaik due to the detection and nature of the environment.HKLM\SOFTWARE\Microsoft\DownloadManager
Code: Select all
Opens IE to the Gusanito webpage, which is the Spanish translation "An endeering term to describe shady, scared and mischievous people. Spanish translation - Worm/Caterpillar."HKU\S-1-5-21-2143623086-3970857485-2198902424-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache\IExplore\WWW_OpenURL
"This Regin driver recurrently checks that the current IRQL is set to PASSIVE_LEVEL using the KeGetCurrentIrql() function in many parts of the code, probably in order to operate as silently as possible"