A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #19663  by MountFranklin
 Mon Jun 17, 2013 12:44 am
Thanks thisisu for leading me to this post.

Also thanks to Kafeine for the dll samples.

Would greatly appreciate if anyone can share for a "working" dropper file or an active dropper site, I would be very interested to let one of my dedicated sandbox to be infected and analyse its behaviour.

Thank you very much in advance.

Regards,
Frank
 #19726  by Horgh
 Sat Jun 22, 2013 5:28 pm
Sinowal dropper + a dump (ugly one, but it works) + dll dropped.
Downloaded by a zbot sample.
pwd : infected
(194.49 KiB) Downloaded 127 times
  • 1
  • 8
  • 9
  • 10
  • 11
  • 12