A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #9494  by Maxstar
 Tue Nov 01, 2011 10:46 am
@Tom1266
I found one variant of BKA- UKASH trojan.ransom sample but i'm not sure this is the same because I currently not able to test this sample.
http://www.virustotal.com/file-scan/rep ... 1319799832
MD5 : 471fd17cd53bc60623c8501332544fc2
Attachments
(36 Bytes) Downloaded 42 times
PW Infected
(159.28 KiB) Downloaded 54 times
 #9496  by tom1266
 Tue Nov 01, 2011 1:16 pm
@ Maxstar

thx for sample, but it isnt. It is a Winlocker, but not the one what i look for.

thx Tom
 #9516  by EP_X0FF
 Thu Nov 03, 2011 3:34 am
tom1266 wrote:Hello, I'm looking for particular sample of

a) Gema UKASH Trojaner (Winlocker/Ransom), new variant of BKA- UKASH Trojaner (no jashla.exe, mahmud.exe)
b) MD5 ?
c) look like hier http://blog.botfrei.de/2011/10/gema-tro ... en-gewand/

anyone get sample can share here for analyse, thx for your help
See http://www.kernelmode.info/forum/viewto ... 9515#p9515 for sample