Alice Pos malware

Forum for analysis and discussion about malware.

Alice Pos malware

Postby xors » Fri Dec 23, 2016 3:18 pm

Thanks to Tim for providing the samples. Inside the attachment is my attempt to unpack the packed file (packed with VMProtect). I can't fix the stolen OEP bytes. If anyone can help, please post your findings :)

More information: ... m-malware/
You do not have the required permissions to view the files attached to this post.
User avatar
Posts: 137
Joined: Mon May 23, 2016 2:01 am
Location: Greece
Reputation point: 63

Re: Alice Pos malware

Postby Xylitol » Fri Dec 23, 2016 6:20 pm

Trend Micro has discovered a new family of ATM malware called Alice

lol, i think MalwareTech gived me that file a while back, but we haven't really looked at it due to vmp.
User avatar
Global Moderator
Posts: 1649
Joined: Sat Apr 10, 2010 5:54 pm
Location: Seireitei, Soul Society
Reputation point: 505

Re: Alice Pos malware

Postby robemtnez » Thu Jan 05, 2017 3:05 am

Alice was first used in October 2014. The sample that is not packed with VMProtect is more like a test prototype. The PIN code is hard coded on that one whereas the other samples generate the PIN code using the CRC of the file and the terminal ID (only visible when running the malware on an ATM).
Posts: 15
Joined: Tue Feb 03, 2015 4:11 pm
Reputation point: 9

Return to Malware

Who is online

Users browsing this forum: No registered users and 14 guests