ModPOS #27303 by maddog4012 Wed Nov 25, 2015 3:55 pm Do you have any samples or hash values for ModPOS Username maddog4012 Posts 82 Joined Mon Aug 04, 2014 6:53 pm
Re: ModPOS #27307 by benkow_ Wed Nov 25, 2015 4:59 pm if you have access to VT: https://www.virustotal.com/en/file/2004 ... /analysis/ (source: https://twitter.com/Seifreed/status/669543251804835840 and http://www.monerisusa.com/support/~/med ... 14JUL.ashx ) Username benkow_ Posts 85 Joined Sat Jan 24, 2015 12:14 pm
Re: ModPOS #27308 by Xylitol Wed Nov 25, 2015 5:02 pm attached. Attachments 20048e58bb35370f9e54575221da9b6728d47e5eb5404cb30912fd99288f7d52.zip infected (94.43 KiB) Downloaded 96 times Registration Problems and FAQ - Rules For Malware Requests Username Xylitol Rank Global Moderator Posts 1706 Joined Sat Apr 10, 2010 5:54 pm Location Seireitei, Soul Society Contact
ModPOS (Backdoor.Straxbot, TrojanDropper:Win32/Rortiem.A) #27325 by R136a1 Thu Nov 26, 2015 9:09 pm Hi folks, some info about this malware can be found here: http://www.isightpartners.com/2015/11/modpos/ Because the report does not mention any file hashes (which sucks!), I thought I give it a try and finally found some droppers. Might be older versions, since the PE time stamps date back to 2012. Anyway, better than nothing... Droppers: https://www.virustotal.com/en/file/4e32 ... /analysis/ https://www.virustotal.com/en/file/2aa3 ... /analysis/ https://www.virustotal.com/en/file/6c9d ... /analysis/ https://www.virustotal.com/en/file/4739 ... /analysis/ https://www.virustotal.com/en/file/f4ea ... /analysis/ Main driver component can be found here: http://www.kernelmode.info/forum/viewto ... =20&t=4119 Regards Attachments ModPos_droppers_2012.zip PW: infected (288.58 KiB) Downloaded 98 times Malware Reversing http://www.malware-reversing.com Username R136a1 Rank Forum Admin Posts 272 Joined Wed Jul 13, 2011 4:30 pm Location Netherlands
Re: ModPOS (Backdoor.Straxbot, TrojanDropper:Win32/Rortiem.A #27346 by p1nk Thu Dec 03, 2015 3:28 am I compressed all the PoS samples listed in the Discover report and uploaded them to: http://malshare.com/users/~p1nk/pos_bulk.zip password: infected Username p1nk Posts 44 Joined Thu Oct 29, 2015 1:09 am
Re: ModPOS (Backdoor.Straxbot, TrojanDropper:Win32/Rortiem.A #27456 by Phant0m Wed Dec 23, 2015 11:56 am Did anyone got fallback url from samples ? maybe to try hacking panel Username Phant0m Posts 8 Joined Thu Oct 15, 2015 9:56 pm