A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15666  by Waves97
 Tue Sep 18, 2012 3:05 pm
In " Malware Request " is sample of this :)

Image
by niebezpiecznik.pl
 #15667  by 360Tencent
 Tue Sep 18, 2012 4:00 pm
http://labs.alienvault.com/labs/index.p ... r-zeroday/

http://urlquery.net/report.php?id=184218

111.exe(unpacked)

https://www.virustotal.com/file/a6086c1 ... /analysis/

according to the comments below, right decoded 111.exe

Note; Moh2010.swf in the malware request thread is about 9kb( it comes from nod32de.com),the previous version is about 13kb,see pic from http://eromang.zataz.com/2012/09/16/zer ... -over-yet/
Moh2010-0day-20120914-300x215.png
Moh2010-0day-20120914-300x215.png (43.13 KiB) Viewed 740 times
Attachments
pw; infected
(9.87 KiB) Downloaded 77 times
 #15688  by N3mes1s
 Thu Sep 20, 2012 2:09 pm
http://contagiodump.blogspot.it/2012/09 ... -0day.html
Code: Select all
111.exe          baabd0b871095138269cf2c53b517927
111.exe_out 7173d9b331275b8be69a4e698c9ec68f
Decoded SWF  e7ced808b16692f57229a2e21c476be8
exploit.html  4f1dfed17cf7d1a1d9f61e1ad2c03624
Moh2010.swf  eb62e0051ad4ab3f626d148472dfa891
Protect.html  f4537fe00e40b5bc01d9826dc3e0c2e8
https://www.virustotal.com/file/2a2e2ef ... /analysis/
https://www.virustotal.com/file/a6086c1 ... /analysis/
https://www.virustotal.com/file/dd41efa ... /analysis/
https://www.virustotal.com/file/9d66323 ... /analysis/
https://www.virustotal.com/file/70f6a2c ... /analysis/
https://www.virustotal.com/file/a5a04f6 ... /analysis/
https://www.virustotal.com/file/70f6a2c ... 348057714/

Thanks to mila.
Attachments
passwd: infected
(41.58 KiB) Downloaded 77 times