A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #6324  by Xylitol
 Sat May 14, 2011 5:39 pm
Tiny storyboard about this spyeye sample who conduct to ms removal tool download
Image

--------------
Fake.HDD Windows XP Recovery + insulated rk stuff

Image
Attachments
See archive comment for password
(161.47 KiB) Downloaded 70 times
See archive comment for password
(776.66 KiB) Downloaded 66 times
See archive comment for password
(370.93 KiB) Downloaded 59 times
 #6428  by Xylitol
 Thu May 19, 2011 8:26 pm
fake.hdd winxp recovery again and braviax again

Image
Attachments
See archive comment for password
(187.31 KiB) Downloaded 67 times
See archive comment for password
(574.26 KiB) Downloaded 58 times
 #6560  by EP_X0FF
 Fri May 27, 2011 3:05 pm
Windows XP Recovery

(also mentioned by Xylitol here)

GUI

Image

"Give me money" dialog

Image

Probably also installs ZeroAccess, but dropper currently unavailable (has option "adw: download rootkit" and comes from site, which yesterday hosted ZAccess sample).

Muldrop, crypted then packed by UPX, payload it drops also crypted and packed by UPX. Uses IE injection. Dropper has AntiVM on board (VMWare, Virtual Box, Virtual PC).

In attach original dropper and extracted payload.

http://www.virustotal.com/file-scan/rep ... 1306508426
Attachments
pass: malware
(707.82 KiB) Downloaded 86 times
 #6607  by Xylitol
 Wed Jun 01, 2011 11:05 am
Image

Image

QS81-OPGD-786F
OH6G-H76G-985A
JA7J-JHA7-QPL9
Code: Select all
Text strings referenced in kniga_is:, item 640
 Address=0052FF3A
 Disassembly=MOV EDX,5300E0
 Text string=UNICODE "http://zipfilez.ru/payarch/smscheck/log.php?v=%MAINVER%&cid=%CID%&s=%SCHEME%&wid=%WID%&fid=%FID%&fq="
25/42 >> 59.5%
http://www.virustotal.com/file-scan/rep ... 1306925764
Attachments
pwd: xylibox
(1.13 MiB) Downloaded 62 times
 #6727  by EP_X0FF
 Wed Jun 08, 2011 3:54 pm
WinRAR 2011

from hxxp://allinstrret.ru/ (any downloaded exe is the same)

Image

Written on CodeGear RAD Studio v15.0.3890.34076 (CBuilder) and crypted.

Yet another SMS Hoax.
Attachments
pass: malware
(3.79 MiB) Downloaded 63 times
 #6837  by EP_X0FF
 Thu Jun 16, 2011 11:35 am
Windows XP Repair

Muldrop VT http://www.virustotal.com/file-scan/rep ... 1308221793

GUI

Image

Has antivm and anti-debugging on board (likely part of crypter code).

Perfect example of Matryoshka (crypter+UPX->crypter+UPX)

All original + unpacked in attach (all stages + some additional payload dll extracted from end layer code)
Attachments
pass: malware
(1.15 MiB) Downloaded 65 times
  • 1
  • 2
  • 3
  • 4
  • 5
  • 12