A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7811  by EP_X0FF
 Mon Aug 01, 2011 12:37 pm
Buckrogers wrote:Initially I thought it was the dropper, but apparently this dir is created and deleted on every boot.
It is hidden by NtQueryDirectoryFile hook in Explorer.
 #7884  by EP_X0FF
 Sun Aug 07, 2011 1:45 pm
gritland wrote:http://www.virustotal.com/file-scan/report.html?id=c37427fb19d01c8b3eb657cd7e322c272772506545f87733ea0230cb9c67d292-1312720402
Equal to this and this.

Updated gates list.
hxxp://www.solodiyi.com/main/gate.php;100
hxxp://www.verdumnn.com/main/gate.php;100
hxxp://www.aaggrreesssor.com/main/gate.php;100
hxxp://www.trressuryy.com/main/gate.php;100
 #7974  by EP_X0FF
 Sat Aug 13, 2011 3:00 am
SpyEye 1.3.x

Base path x:\Romano.Bin, file and config file names are hexadecimal random.
Crap is failed to hide itself after installation Image

Pass for decrypted config: FD9EBD0F32D1D60DB9E58344C38FABEF

Gates:
hxxp://banistabank.ru/ko.php;300
hxxp://eewtoopqq.ru/www5.php;300
Plugins: customconnector, ccgrabber.

Original 0/ 43 (0.0%)
http://www.virustotal.com/file-scan/rep ... 1313203186

Unpacked 17/ 42 (40.5%)
http://www.virustotal.com/file-scan/rep ... 1313203802
Attachments
pass: malware
(172.95 KiB) Downloaded 57 times
  • 1
  • 21
  • 22
  • 23
  • 24
  • 25
  • 42