A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #9047  by EP_X0FF
 Sun Oct 09, 2011 8:13 am
Not really. R2D2 in attach.

for me its more interesting Reaper dronez malware.
Attachments
pass: malware
(164.73 KiB) Downloaded 59 times
 #9277  by sugar
 Wed Oct 19, 2011 11:25 am
EP_X0FF, no is old version with x86 driver, new version have x64 driver too.
It is well known that 64 bit kernel modules must carry a valid digital signature that can be checked by the operating system, or loading the driver fails. The driver that comes with the rootkit contains a 1024 bit RSA certificate (fingerprint e5445e4a 9c7d24c8 43f0c669 e2a8d3a1 78cf7fa8), issued by Goose Cert on April 11, 2010. However, the certificate must be installed and the trustworthiness must be confirmed in order to make the driver load.