Alice Pos malware

Forum for analysis and discussion about malware.
Post Reply
User avatar
Posts: 145
Joined: Mon May 23, 2016 2:01 am

Alice Pos malware

Post by xors » Fri Dec 23, 2016 3:18 pm

Thanks to Tim for providing the samples. Inside the attachment is my attempt to unpack the packed file (packed with VMProtect). I can't fix the stolen OEP bytes. If anyone can help, please post your findings :)

More information: ... m-malware/
You do not have the required permissions to view the files attached to this post.

User avatar
Global Moderator
Posts: 1660
Joined: Sat Apr 10, 2010 5:54 pm
Location: Seireitei, Soul Society

Re: Alice Pos malware

Post by Xylitol » Fri Dec 23, 2016 6:20 pm

Trend Micro has discovered a new family of ATM malware called Alice
lol, i think MalwareTech gived me that file a while back, but we haven't really looked at it due to vmp.

Posts: 15
Joined: Tue Feb 03, 2015 4:11 pm

Re: Alice Pos malware

Post by robemtnez » Thu Jan 05, 2017 3:05 am

Alice was first used in October 2014. The sample that is not packed with VMProtect is more like a test prototype. The PIN code is hard coded on that one whereas the other samples generate the PIN code using the CRC of the file and the terminal ID (only visible when running the malware on an ATM).

Post Reply