A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #10754  by rkhunter
 Tue Jan 03, 2012 6:47 am
MDL wrote in Twitter that it discovered new Sinowal activity after some weeks of silence. Domain names are probably being generated again.
 #10840  by rkhunter
 Thu Jan 05, 2012 4:22 pm
There are Sinowal's more and more. Was caught over 15 droppers at last two days.
 #10842  by Aleksandra
 Thu Jan 05, 2012 4:50 pm
rkhunter wrote:There are Sinowal's more and more. Was caught over 15 droppers at last two days.
Please attach your samples.
 #10843  by rkhunter
 Thu Jan 05, 2012 4:54 pm
Aleksandra wrote:
rkhunter wrote:There are Sinowal's more and more. Was caught over 15 droppers at last two days.
Please attach your samples.
Attachments
pass:malware
(435 KiB) Downloaded 108 times
 #10882  by AaLl86
 Fri Jan 06, 2012 9:21 pm
Hi all!
First of all, I wish an happy new year to everyone here.
Second, and more important thing is this: http://www.aall86.altervista.org/files/ ... alysis.pdf
Take a glance of it, it's an analysis of last Sinowal I found, and tell me what do you think about...
Unfortunately I lost that damn payload in some VM I use for analysis. Let me know if someone has the exact payload of my analysis please...

Regards,
Andrea
 #11823  by Aleksandra
 Sun Feb 26, 2012 1:36 pm
MD5: 3e16d15c969ff2be96757b25ac981ea3
SHA1: 0652dbd14d4a8ab54031d50bfa64b833b6719715
9/42

MD5: 21e645cf1fb09ce41698280eae2e2ebd
SHA1: f75097f133652c076e5fc49f72493ea7d2aa6768
9/42
Attachments
pass: virus
(303.72 KiB) Downloaded 88 times
pass: virus
(46.69 KiB) Downloaded 77 times
  • 1
  • 2
  • 3
  • 4
  • 5
  • 12