A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15339  by SomeUnusedName
 Fri Aug 24, 2012 1:01 pm
Check the update, FireEye missed that the IP was a sinkhole for Gauss as well as Flame and therefore concluded they are connected, which at least from that evidence is wrong.
 #17357  by Shabnam Aslani
 Mon Dec 24, 2012 7:10 am
Hello everyone :geek:
I read the posts and it was so exciting to see no one mentained the interconnection between GAUSS madules:)
Absolutely they do not work seperatly... You should find the connection and sequence of executing of modules...I mean the real way that they work together.
The first module to execute is WMI or WinShell...you should inject this module to lsass.exe process and then it wil drop two other files named wmiqry32.dll and wmihlp32.dll...Then it will inject the wmiqry32.dll to svchost.exe with the -k netsvc command and you should patch the execution to load other modules. If you had any problem plz inform me.
thx