Attachments
Password is "infected" without quotes
(171.96 KiB) Downloaded 232 times
(171.96 KiB) Downloaded 232 times
A forum for reverse engineering, OS internals and malware analysis
Win32:Virut wrote:Hi,SHA256: e19c8f1ea80d6cf9d3348a07c7428bbcdfc66ea5a192f63e22a8e29cfda5aaf0
I'm looking for MD5: 0efd95e4d3502e20b7120685050abae2
Thanks
00000039 273.98556519 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000040 274.08596802 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000041 274.18600464 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000042 274.28622437 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000043 274.38613892 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000044 274.48648071 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000045 274.59146118 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000046 274.68685913 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000047 274.78668213 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000048 274.90359497 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000049 275.01293945 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000050 275.10397339 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000051 275.20385742 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000052 275.32345581 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000053 275.43780518 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000054 275.52349854 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000055 275.62338257 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
00000056 275.72372437 [532] pid: 532 tid: 1008 Attempt to switch current desktop, target wLockDesktop - request denied
GET /555657550B8836F821F3BF69B40E8541B9BB830D10E570A1C1B HTTP/1.1Decrypts into %temp% folder and then executes by ransom from embedded full screen IE window. Ransom page + all graphics/css in attach.
User-Agent: Our_Agent
Host: hhrbn.ru
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Sun, 18 Nov 2012 01:11:11 GMT
Content-Type: application/octet-stream
Connection: keep-alive
X-Powered-By: PHP/5.3.3-7+squeeze14
Cache-Control: public
Content-Disposition: attachment; filename=32721
Content-Transfer-Encoding: binary
Content-Length: 83722
EP_X0FF wrote:Host: hhrbn.ruNot at home the weekend so can't attack/dissas stuff but found this
rnmbe.su/hhrbn.ru
hxxp://46.37.162.28:80/user/login/ « auth service »
hxxp://hhrbn.ru:80/data.php
hxxp://hhrbn.ru:80/config.php
hxxp://hhrbn.ru:80/gateway.php
hxxp://hhrbn.ru:80/includes/rc4.php
hxxp://hhrbn.ru:80/includes/mysql.php
hxxp://hhrbn.ru:80/includes/functions.php
hxxp://hhrbn.ru:80/config/
hxxp://hhrbn.ru:80/cache/