A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #17246  by Quads
 Tue Dec 18, 2012 1:10 am
Another what looks like a SMS code oe phone number

Image

Quads
 #17697  by EP_X0FF
 Sun Jan 13, 2013 8:35 am
Fresh MBRlock.

SHA1: 7c8791be7b1530055f1a54a36b74489783b09820

https://www.virustotal.com/file/34ad70c ... /analysis/

Unlock code: 45746777
However I think code auto generated for each new build (rebuilds few times per day seems) so posting unblock codes makes no real sense.

Dropper created 23 May 2011, MBR code with randomized unlock code + tel number appends to dropper as overlay. Assume there is somewhere builder for it, allowing to customize code/tel (not meaning infamous work from vazonez).
Attachments
pass: malware
(90.06 KiB) Downloaded 120 times
 #17921  by EP_X0FF
 Tue Jan 29, 2013 8:35 am
Fresh MBRlock.

Landing hxxp://threedimensionaltrojans.biz/ (domain quickly regenerating)
hxxp://threedimensionaltrojans.biz/download/ <= numerous copy.

SHA-1 a2acae2c2693c14a2d814c216cdad60e659d8787

Too boring to unpack.
Attachments
pass: malware
(53.96 KiB) Downloaded 103 times
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10