A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #27523  by ikolor
 Sun Jan 03, 2016 5:13 pm
Maybe not .If you have different malware code please update and show as.This sample has different MD-5.
 #27526  by MalwareTech
 Mon Jan 04, 2016 2:38 am
ikolor wrote:Maybe not .If you have different malware code please update and show as.This sample has different MD-5.
That's the problem with hashes, they're only good for identifying an individual sample. Kelihos has many identical samples where all that's changed is the domain or internal name. Also they are regularly recrypting the samples to keep them FUD, so you'll find a million identical samples all with different hashes.
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10