A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12354  by rkhunter
 Mon Mar 26, 2012 4:26 pm
I know that many U.S. companies/providers resell hosting to eastern Europe companies, so this is not unusual.
 #12394  by Maxstar
 Thu Mar 29, 2012 1:58 pm
I think this is a also a Zbot / Zeus sample!

https://www.virustotal.com/file/8a30fbe ... /analysis/
MD5: c215cba7566628f984f8649f1218963a
Detection ratio: 3 / 42
Attachments
pass: infected
(195.37 KiB) Downloaded 55 times
Last edited by EP_X0FF on Fri Mar 30, 2012 8:55 am, edited 1 time in total. Reason: password added
 #12398  by rkhunter
 Fri Mar 30, 2012 7:29 am
New modifications of ZBot were observed at last two days: PWS:Win32/Zbot.AES, PWS:Win32/Zbot.AET.
Droppers in attach.
Attachments
pass:infected
(372.31 KiB) Downloaded 61 times
pass:infected
(306.28 KiB) Downloaded 60 times
 #12399  by rkhunter
 Fri Mar 30, 2012 7:32 am
Maxstar wrote:I think this is a also a Zbot / Zeus sample!
If I not mistaken, archive without password actually. Reupload, please.
 #12400  by Maxstar
 Fri Mar 30, 2012 7:58 am
rkhunter wrote:
Maxstar wrote:I think this is a also a Zbot / Zeus sample!
If I not mistaken, archive without password actually. Reupload, please.
I can't edit my post anymore, but I will send a PM to one of the moderators.
I also uploaded this sample by Emsisoft and MBAM and they don't want password protected archives so I have uploaded here the wrong archive. sorry. :oops:
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10
  • 29