A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #24354  by leeno
 Sat Nov 15, 2014 5:49 pm
I am trying to execute Ransom:Win64/Reveton.B Dll .I am unable to run this 64 Bit sample . it would be great if some one help in executing this sample .
I will appreciate if you can provide detail steps to run this sample .
I am attaching the sample pass is infected

Thanks

leeno
You do not have the required permissions to view the files attached to this post.
 #24422  by TETYYSs
 Mon Nov 24, 2014 12:52 pm
Midnight-Star234 wrote:How are you supposed to open these files? :?
The ZIP file is an archive file, you'll need software like 7-zip or similar to open these.
 #24425  by frame4-mdpro
 Mon Nov 24, 2014 2:56 pm
I don't want to be too scathing, but I have virtually no confidence in somebody asking how to handle archive files, let alone malware :x
 #24429  by EP_X0FF
 Tue Nov 25, 2014 10:01 am
frame4-mdpro wrote:I don't want to be too scathing, but I have virtually no confidence in somebody asking how to handle archive files, let alone malware :x
Quite speculative but probably he is asking how to run them, because Reveton is in dll. However this mean he doesn't read whole thread before posting his question, because how to launch reveton was discussed earlier here, even with examples.
 #24453  by Midnight-Star234
 Fri Nov 28, 2014 6:10 am
EP_X0FF wrote:
frame4-mdpro wrote:I don't want to be too scathing, but I have virtually no confidence in somebody asking how to handle archive files, let alone malware :x
Quite speculative but probably he is asking how to run them, because Reveton is in dll. However this mean he doesn't read whole thread before posting his question, because how to launch reveton was discussed earlier here, even with examples.
Yeah I should have read the entire thread I got them running actually well to a page saying Internet Explorer couldn't display this page but I got it working after screwing around a little bit I gotta read before I post I'm such an idiot
 #25365  by Cody Johnston
 Sun Mar 01, 2015 5:30 pm
harikrish093 wrote:Hey Check out this variant of Reveton.I try find which algorithm it uses for encryption but cant if any one find pls tell Here i posted VT link

https://www.virustotal.com/en/file/823b ... /analysis/
A few things:

1. Not everyone here has access to download files from VirusTotal, so if you want people to look at something, attach the actual sample.
2. Reveton is not known to encrypt files, so there is nothing to discover.
3. This sample is over a month old..
  • 1
  • 12
  • 13
  • 14
  • 15
  • 16