A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #14870  by EP_X0FF
 Wed Jul 25, 2012 2:49 pm
zaafar wrote:Thanks for the reply.
what about its successors, (MAXSS/Pihar) are they dead too?
No, but they are insignificant and not interesting.
 #14929  by EP_X0FF
 Mon Jul 30, 2012 1:58 pm
Needo wrote:
EP_X0FF wrote:Try to do your analysis after few years. Hint: it is dead.
What do you mean TDL4 is dead, and why?
Call 1-800-TDSS, they explain you everything as well as where in this forum located "Search" button.
 #14931  by Needo
 Mon Jul 30, 2012 2:34 pm
EP_X0FF wrote:
Needo wrote:
EP_X0FF wrote:Try to do your analysis after few years. Hint: it is dead.
What do you mean TDL4 is dead, and why?
Call 1-800-TDSS, they explain you everything as well as where in this forum located "Search" button.
looks like i do have missed the funeral but I searched google and the kernelmode.info form.....and i couldn't find any "how did it happened" topics/posts/article
it would be great if you would link to the post/topic/article explaining the death of tdl4.
 #14969  by Needo
 Thu Aug 02, 2012 5:38 am
TeamRocketOps wrote:@Needo

I believe the information you are looking for is "Operation Ghost Click". Here is a link to the FBI page:

http://www.fbi.gov/news/stories/2011/no ... re_110911/

Yes, FBI did a raid on that DNS-Changer malware but i thought, dns-changer is just a binary downloaded by TDL4 malware.
Dns-changer just uses TDL4 rootkit to spread and hide itself in a compromised pc. So shutting down of dns changer shouldn't affect the TDL4.

https://www.bit9.com/blog/2012/07/06/dn ... on-monday/
 #15086  by Flamef
 Fri Aug 10, 2012 12:13 am
Hi all,
i just saw this post by luck here http://www.prevx.com/blog/172/TDL-rootk ... efore.html
I don't know if they tell the truth,i think Prevx's trustworthiness is rather doubted.Anyway if what they state is true :
This swap tells Windows to load itself in WinPE mode, thus disabling the driver signing checks and allowing unsigned drivers from being loaded in kernel mode
Have we seen something similar if not the same?Let me remind you :
Here - http://www.securelist.com/en/blog/11266 ... _to_64_bit
Here - http://www.securelist.com/en/blog/473/A ... _for_MacOS
Here - http://p4r4n0id.com/?p=526 Greeting P4ran0id :D
  • 1
  • 56
  • 57
  • 58
  • 59
  • 60