A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #8474  by EP_X0FF
 Thu Sep 08, 2011 1:25 pm
WawaSeb wrote:Hello,

Is it possible to find the BIOS-FLASHING somewhere (Mebromi) : http://blogs.norman.com/2011/malware-de ... ing-trojan ?

Best regards,
This is Trojan:WinNT/Bioskit.A

I need to ask for permission to share this sample, or you can get it from somebody else.

edit:
Here are the hashes for components.

http://www.virustotal.com/file-scan/rep ... 1315469744
http://www.virustotal.com/file-scan/rep ... 1315454105
http://www.virustotal.com/file-scan/rep ... 1315469775
 #8475  by sww
 Thu Sep 08, 2011 1:43 pm
Will post a detailed article (as always) in a near future. God damit, i'm too slow... :evil:
 #8492  by Evilcry
 Fri Sep 09, 2011 6:25 am
Hi,

Mebromi or Mybios/Bioskit is crap, basically only a Cut&Paste from IceLord Rootkit, nothing special :)

No VM Escape.

Regards,
Evilcry
 #8493  by frank_boldewin
 Fri Sep 09, 2011 7:22 am
i wasn't impressed by this stuff either. nothing new in bios.sys icelord hasn't shown us some years ago.
further the norman analysis misses to go into detail how exactly the hook.rom works which gets flashed.
 #8495  by cjbi
 Fri Sep 09, 2011 10:50 am
Not interested.
This is just variant of Rootkit IceLord.
Name should be IceLord.B.
 #8500  by obse
 Fri Sep 09, 2011 7:02 pm
Btw first MBR-kit(mebroot) ITW was also released after few years of published PoC (Eeye bootroot)
and everybody said exactly the same: "nothing interesting, i'm already seen that..."
but that was a big pain in ... (you known where ;) for AV vendors, and for some of them till today