A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4107  by PX5
 Wed Dec 22, 2010 5:26 pm
I wanna run marks original harnig loader in another live enviroment to see if the UA is ver64 or ver63, usually follows the decrypted strings for the UA, may be why not much was seen.
 #4108  by PX5
 Wed Dec 22, 2010 6:32 pm
Marks loader is a bit different than the other I ran, links look about the same but the UA is definitly different, they seem to know I have eSobi installed on this desktop.

EDIT: Desktop is running like death sucking on a lifesaver factory. :lol:

Definitly got some different critters in that load.

accrowd.com/timuo/cptrlg.php?adv=adv523
accrowd.com/timuo/hyfaitavt.php?adv=adv523
accrowd.com/timuo/izgowq.php?adv=adv523
accrowd.com/timuo/iztbjhowu.php?adv=adv523
accrowd.com/timuo/kbwdyfeyta.php?adv=adv523
accrowd.com/timuo/mmaucwe.php?adv=adv523
accrowd.com/timuo/ocwrykrz.php?id=269171479&p=0
accrowd.com/timuo/qhlkrzhf.php?adv=adv523
accrowd.com/timuo/sjnlgn.php?adv=adv523
accrowd.com/timuo/tyfnhc.php?adv=adv523
accrowd.com/timuo/ultamgbih.php?adv=adv523
accrowd.com/timuo/xavdxsz.php?adv=adv523
accrowd.com/timuo/xbvqxsa.php?adv=adv523
accrowd.com/timuo/zptfzubjhp.php?adv=adv523&code1=HNJJ&code2=1171&id=269171479&p=0&b=1

bccorps.com/timuo/hyfaitavt.php?adv=adv523
bccorps.com/timuo/tyfnhc.php?adv=adv523
bccorps.com/timuo/xavdxsz.php?adv=adv523
bccorps.com/timuo/xbvqxsa.php?adv=adv523

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; eSobiSubscriber 2.0.4.16)ver64


Same friends as before it appears, I cant reach the url with the rar either which is Rusty himself. :cry:

204.45.118.202/23/aok
204.45.118.202/23/exc
204.45.118.202/23/iok
204.45.118.202/23/lok
204.45.118.202/23/run
204.45.121.42/jwyydjnmbne.rar

lolz@FakeAV
Attachments
lolz.JPG
lolz.JPG (96.81 KiB) Viewed 581 times
 #4117  by EP_X0FF
 Thu Dec 23, 2010 9:14 am
Malware package identical to those I uploaded before.

It also includes Trojan:Win32/Rimecud, Backdoor Darkness, another Harnig and a few Win32 Autorunner droppers. Poor user of PC who get this package installed.
 #4191  by markusg
 Thu Dec 30, 2010 11:29 am
there is new multible dropper. the only new file is
citistep.info/pnk5/spa12.exe
http://www.virustotal.com/file-scan/rep ... 1293708249

the rest is:

citistep.info/pnk5/am1msgr.exe
citistep.info/pnk5/c2csr.exe
citistep.info/pnk5/i4xcoms.exe
citistep.info/pnk5/ispcd.exe
dropper:
dlsvc32.exe
http://www.virustotal.com/file-scan/rep ... 1293708492
Attachments
(369.59 KiB) Downloaded 48 times
 #4192  by EP_X0FF
 Thu Dec 30, 2010 11:34 am
spa12.exe is TDL4
[main]
version=0.03
aid=30020
sid=0
rnd=1383384898
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://9669b6b96b.com/;hxxps://86b6b96b.com/;hxxps://lkaturl11.com/;hxxps://kangojjm1.com/;hxxps://lkaturl71.com/
wsrv=hxxp://gnorenyawr.com/;hxxp://runderwayr.com/;hxxp://jikdoout0.com/hxxp://swltch0o.com/;hxxp://rammjyuke.com/
psrv=hxxp://crj71ki813ck.com/
version=0.15