A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5464  by fatdcuk
 Tue Mar 15, 2011 3:58 am
Nothing fancy just a distinct lack of any route 1 identification by any VT DB ;)

http://www.virustotal.com/file-scan/rep ... 1300160250

Spammed by seeded search terms.
Updates c/o
Code: Select all
http://checkifuneed.com/codecs/QuickTimeCodec.3291.exe
Runs as a service and wants to share even more junk seeded onto the P2P networks.

MalwareBytes detects as Trojan.P2P.Agent oddly enough :)
Attachments
(523.96 KiB) Downloaded 76 times
 #5840  by EP_X0FF
 Wed Apr 06, 2011 5:54 pm
Well Dr.Web clearly says this is trojan* :D

https://www.virustotal.com/file-scan/re ... 1302111883

*(after removing crypter)

There many C++ RTL code inside and GnucDNA components code (d:\GnucDNA\src\GnucleusR3\Release\revengeConsole.pdb)
http://www.gnucleus.com/GnucDNA

Maybe this low detection ration is because this malware is not well known? :)
 #6017  by fatdcuk
 Fri Apr 22, 2011 12:47 pm
Another day and papas found another new bag floated in P2P land :D

http://www.virustotal.com/file-scan/rep ... 1303475625
http://www.virustotal.com/file-scan/rep ... 1303475759
Code: Select all
http://litecodecupdate.com/play/?f=01
There are more files @ that URL..same critter different MD5 blah blah...Installs its tuck shop(shares) in random named directory in %SYSDIR%.
Attachments
(935.18 KiB) Downloaded 61 times
 #6026  by EP_X0FF
 Sat Apr 23, 2011 12:23 pm
That's the same repacked malware, post merged with previous thread :)
 #6027  by Quads
 Sat Apr 23, 2011 10:50 pm
Norton 2012 Download Insight Quarantines the files after being downloaded from the websites.

Quads
 #6028  by EP_X0FF
 Sun Apr 24, 2011 4:35 am
I believe most AV's/FW with HIPS component should block this malware by behavior analysis because installing and running service is suspicious by default.