A forum for reverse engineering, OS internals and malware analysis 

Search found 17 matches

 Go to advanced search

Re: Trojan Zeus (alias ZBot)

 by NarfBang ¦  Wed Mar 28, 2012 1:42 pm ¦  Forum: Malware ¦  Topic: Win32/Zeus (alias Zbot) ¦  Replies: 281 ¦  Views: 365237

Interesting piece on NBC the other night.

http://www.msnbc.msn.com/id/21134540/vp ... 6#46815636

Re: Trojan Ransom / FakePoliceAlert

 by NarfBang ¦  Thu Feb 16, 2012 7:08 pm ¦  Forum: Malware ¦  Topic: French Ransom (Trojan:Win32/Ransom.FL) ¦  Replies: 49 ¦  Views: 48067

SHA256:
ce9c7f46cad1e40cb9e411736b5bc66412f61ee2aa6d638e4413ea4efdfde648
File name:
file-3554303_
Detection ratio:
2 / 43
https://www.virustotal.com/file/ce9c7f4 ... /analysis/

Cheers!

Re: ntoskrnl.exe issue

 by NarfBang ¦  Fri Feb 03, 2012 4:15 pm ¦  Forum: General Discussion ¦  Topic: ntoskrnl.exe issue ¦  Replies: 4 ¦  Views: 4760

I get that same error on one of my machines.
Would be interested to find out why.

Re: Microsoft Neutralizes Kelihos Botnet

 by NarfBang ¦  Tue Jan 31, 2012 4:33 pm ¦  Forum: Malware ¦  Topic: Microsoft Neutralizes Kelihos Botnet ¦  Replies: 12 ¦  Views: 9904

Looks like not dead. Should have delete bots. Nobody notice anyway.
http://threatpost.com/en_us/blogs/kelih ... ces-013112

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by NarfBang ¦  Mon Dec 12, 2011 9:43 pm ¦  Forum: Malware ¦  Topic: Rootkit TDL 3 (alias TDSS, Alureon.CT, Olmarik) ¦  Replies: 395 ¦  Views: 286429

Fresh TDSS

Enjoy!

Re: Rootkit ZeroAccess (alias Max++, Sirefef)

 by NarfBang ¦  Thu Dec 08, 2011 7:45 pm ¦  Forum: Malware ¦  Topic: Rootkit ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 374 ¦  Views: 327485

What's the difference between the .aml & .h ?
Pardon my naivete.

Re: Rootkit ZeroAccess (alias Max++, Sirefef)

 by NarfBang ¦  Thu Dec 08, 2011 7:13 pm ¦  Forum: Malware ¦  Topic: Rootkit ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 374 ¦  Views: 327485

BAAA HAAAA! I went back to the URL and tooled around in the folder directory and found these 6 other files. Some ID as ZeroAccess, others not so much. All seven files (including corrupted one) are in the 7z. I am newb and not so good at IDing things correctly. Mods please move files that don't belon...

Re: Rootkit ZeroAccess (alias Max++, Sirefef)

 by NarfBang ¦  Thu Dec 08, 2011 6:43 pm ¦  Forum: Malware ¦  Topic: Rootkit ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 374 ¦  Views: 327485

Me thinks this be ZeroAccess. Low detection rate if it is.

Virustotal results
http://www.virustotal.com/file-scan/rep ... 1323368655

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by NarfBang ¦  Wed Nov 23, 2011 2:55 pm ¦  Forum: Malware ¦  Topic: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco) ¦  Replies: 149 ¦  Views: 166018

Спасибо EP_X0FF!

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by NarfBang ¦  Tue Nov 22, 2011 4:06 pm ¦  Forum: Malware ¦  Topic: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco) ¦  Replies: 149 ¦  Views: 166018

Hey all,
Does anyone have a family tree of TDSS and its progeny?
I'm interested in the timelines and history of how this family is evolving.
Cheers if ya want to move this post to a different thread.