Original dropper:
SHA1: e83ca87a39a5f15ca5942fd57d78e790861c2937
MD5: 15e692cf34a70fb364591622bff1e43a
Extracted bootkit dropper:
SHA1: 5ecefefe4bbfc040927e827ab81c10caf5d10f90
MD5: f72e3d86b8f4f97d103ff1b7f87213f2
In brief:
- Infects MBR
- Contains rootkit
- Multi-AV killing, system-tools killing features
- Some anti-debug features
- Anti-drvmon features (greeting to EP_X0FF and Fyyre)
Dropper + decrypted payload (mbr+rootkit+dll) in attach.
SHA1: e83ca87a39a5f15ca5942fd57d78e790861c2937
MD5: 15e692cf34a70fb364591622bff1e43a
Extracted bootkit dropper:
SHA1: 5ecefefe4bbfc040927e827ab81c10caf5d10f90
MD5: f72e3d86b8f4f97d103ff1b7f87213f2
In brief:
- Infects MBR
- Contains rootkit
- Multi-AV killing, system-tools killing features
- Some anti-debug features
- Anti-drvmon features (greeting to EP_X0FF and Fyyre)
Dropper + decrypted payload (mbr+rootkit+dll) in attach.
Attachments
pass:infected
(17.42 KiB) Downloaded 132 times
(17.42 KiB) Downloaded 132 times
pass:infected
(43.85 KiB) Downloaded 149 times
(43.85 KiB) Downloaded 149 times
pass:infected
(51.9 KiB) Downloaded 143 times
(51.9 KiB) Downloaded 143 times