A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #9394  by Muteb
 Mon Oct 24, 2011 10:54 pm
Hi everyone,

I am seeking for help to find agony and SkypeTrojon rootkits sample. Those samples are open source so i can use commands line to tell them what to do. Please i am doing i research paper and looking for those. I search the net but could not get anything. any one can help.

Thanks
 #9402  by Meriadoc
 Tue Oct 25, 2011 12:25 pm
Here you go Muteb:

Tofsee md5: bdd2d7f5599349a0d60a5ea5cd767550
agony+source

edit: on second look I think you are looking for skypetrojan? Megapanzer?
Attachments
pass=malware
(253.97 KiB) Downloaded 68 times
Last edited by Meriadoc on Tue Oct 25, 2011 1:48 pm, edited 1 time in total.
 #9403  by Meriadoc
 Tue Oct 25, 2011 12:53 pm
Muteb:

SkypeTrojan source

Megapanzer
This trojan horse is a Megapanzer variant in its ealiest days branched in 2006. First Megapanzers purpose was to connect back to its client through all kind of firewalls and proxy servers and offering an attacker a simple command shell. The feature eavesdropping Skype conversations was added a little later and after proving its feasibility it became the new main focus.
It injects function calls into the Skype process to intercept all audio data coming and going to the Skype process. It extracts the PCM audio data, converts it to MP3 and sends it to the attacker after encrypting it.
zdnet
Attachments
pass=malware
(187.36 KiB) Downloaded 66 times