A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28885  by EP_X0FF
 Wed Jul 13, 2016 4:09 pm
No problem. It is xor with key length 256 used on executable which is inverted in file.

Take actual exe.

It's Locky.
Attachments
pass: malware
(102.57 KiB) Downloaded 107 times
 #28903  by xors
 Mon Jul 18, 2016 9:27 am
From [url]hxxp://212.27.63.102/09uhv65hg?NMOmkGYI=XpVoEFE[/url]
Attachments
password:infected
(289.22 KiB) Downloaded 96 times
 #28913  by mkroll
 Wed Jul 20, 2016 3:05 pm
Locky spam now already delivers the Locky sample inside the script instead of downloading it.
Still uses the new UHEPRNG algorithm from https://github.com/skratchdot/random-se ... r/index.js to decrypt the sample (first seen here: https://www.virustotal.com/en/file/be2b ... /analysis/).
Nothing new about the Locky itself. Of course it needs the "321" parameter as usual for this channel.

Javascript dropper: https://www.virustotal.com/en/file/e751 ... /analysis/
Locky (with config): https://www.virustotal.com/en/file/56be ... /analysis/
Attachments
Spammed Locky *dropper* javascript + dropped Locky
(411.02 KiB) Downloaded 92 times
 #28934  by xors
 Mon Jul 25, 2016 12:30 pm
From hxxp://213.205.40.169/7h8gbiuomp?wwugJzY=maQhnrviLU
Attachments
password:infected
(290.78 KiB) Downloaded 70 times
 #28935  by xors
 Mon Jul 25, 2016 12:40 pm
One more
From hxxp://212.40.179.63/7h8gbiuomp
Attachments
password:infected
(292.25 KiB) Downloaded 83 times
 #28971  by tim
 Tue Aug 02, 2016 12:56 pm
Found this config from a recent spam campaign, first time i have seen a campaign id of 13 and also a DGA seed value this high.
Code: Select all
{
   "campaignId": 13,
   "seed": 29033,
   "delay": 0,
   "fakeSvchost": false,
   "persist": false,
   "ignoreRuLang": true,
   "ips": [
      "91.230.211.139",
      "37.139.30.95",
      "91.219.29.48"
   ],
   "urlPath": "/upload/_dispatch.php"
}  
 #28976  by xors
 Thu Aug 04, 2016 10:52 am
From hxxp://91.223.89.200/13fo8lnl
Attachments
password:infected
(195.75 KiB) Downloaded 72 times
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10
  • 15