A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #11012  by STRELiTZIA
 Fri Jan 13, 2012 7:24 pm
Thanks.

Sample by EX!:
Pass for decrypted config: 1D877A868F11E87E27D03C3026BC37CE

Gates:
hxxp://veroabelos0.com/~abrvalg2/gate.php;600
hxxp://srepolik20.com/~abrvalg2/gate.php;600
hxxp://neropisap.com/~abrvalg2/gate.php;600
hxxp://opionisa0.com/~abrvalg2/gate.php;600
Collectors:
veroabelos0.com:8081
srepolik20.com:8081
neropisap.com:8081
opionisa0.com:8081
Attachments
(46.86 KiB) Downloaded 65 times
 #11025  by EX!
 Sat Jan 14, 2012 7:28 am
SpyEye.


https://www.virustotal.com/file/0f2ce4a ... 326525304/

Gates:
hxxp://veroabelos0.com/~abrvalg2/gate.php;1200 <--- Online
hxxp://vikingwer5.com/~abrvalg2/gate.php;1200
hxxp://daber45ex4.com/~abrvalg2/gate.php;1200
hxxp://cras86exa45.com/~abrvalg2/gate.php;1200
hxxp://kabr234exa46.com/~abrvalg2/gate.php;1200

Collectors:
veroabelos0.com:8081
vikingwer5.com:8081
daber45ex4.com:8081
cras86exa45.com:8081
kabr234exa46.com:8081


Password for decrypted config: 5180434427834B7D7C5D6B03AC241BC2


:D
Attachments
(186.32 KiB) Downloaded 86 times
 #11171  by EP_X0FF
 Fri Jan 20, 2012 5:39 pm
rkhunter wrote:SpyEye under new cryptor/obfuscator - VirTool:Win32/Obfuscator.LL (usual record - EyeStye.N does not working as can see)

MD5: 303351e5b05e93fd8780ef18c6daeeb6
3/43

Pass for decrypted config: 130CBE0950491F6148A65482B9B50CC4

Gates from customconnector cfg
hxxp://onlineebank.info:8080/pic1s0fs.php;150
hxxp://1nbank.info:8080/pic1s0fs.php;150
Attachments
(5.19 KiB) Downloaded 68 times
 #11192  by EP_X0FF
 Sat Jan 21, 2012 3:25 pm
Attachments
pass: malware
(173.85 KiB) Downloaded 85 times
  • 1
  • 33
  • 34
  • 35
  • 36
  • 37
  • 42