A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20561  by N3mes1s
 Thu Aug 22, 2013 12:10 pm
First fakeAv browser page:

http://urlquery.net/report.php?id=4676419

after
GET /index.php?c=RaEQL35Qhmg8kIEAyKydUWLt2abuVSeZkMW823tcOdHLi+sHzn+IhzfWz0ESjU4fq3YMhr4Xf4T8yLo0G1yosbiJyssK1LCmIKe4X6XXotKxBA== HTTP/1.1
Host: 212.7.195.124
Proxy-Connection: keep-alive
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.36
Referer: hxxp://212.7.195.124/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf4bfpf/naQjDQHx5/+ByoM=
Accept-Encoding: gzip,deflate,sdch
Accept-Language: it-IT,it;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: uid=100
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 22 Aug 2013 09:44:32 GMT
Content-Type: application/octet-stream
Content-Length: 512000
Connection: keep-alive
X-Powered-By: PHP/5.3.26
Content-Disposition: attachment;filename="security_cleaner.exe"
System Care Antivirus

Image

SHA256: 6e68c2de51da4f2a5bcc99e83218a7251066393b293d1225a4ad48552c3d30f7
SHA1: a9eb52dd4842fa08ec96d284a1989432b65ff2cb
MD5: 9a189b4f7b7fe113f4798bb80f920667
File size: 500.0 KB ( 512000 bytes )
File name: fakeavdropped.exe
File type: Win32 EXE
Detection ratio: 6 / 46
Analysis date: 2013-08-22 11:49:15 UTC

https://www.virustotal.com/en/file/6e68 ... 377172155/
Attachments
passwd: infected
(416.18 KiB) Downloaded 103 times
 #20573  by ISergey256
 Fri Aug 23, 2013 8:24 am
Antivirus Security Pro
https://www.virustotal.com/en/file/9005 ... /analysis/
Image

To run in virtual machine - create file "C:\sd.dbg"
Code: Select all
if ( dword_44E050(L"C:\\sd2.dbg") != -1 ) 
    dword_44E1A8(0);
  if ( dword_44E050(L"C:\\sd.dbg") == -1 )
  {
    v15 = *(_DWORD *)"VMWARE";
    v16 = *(_WORD *)"RE";
    v17 = aVmware_0[6];
    v11 = *(_DWORD *)"VIRTUAL HD";
    v12 = *(_DWORD *)"UAL HD";
    v13 = *(_WORD *)"HD";
    v14 = aVirtualHd[10];
    v5 = dword_47223C[0];
	.................
Attachments
pass: infected
(493.3 KiB) Downloaded 100 times
 #20601  by EP_X0FF
 Mon Aug 26, 2013 3:23 am
bitstechs wrote:PC Defender 360 and My Safe PC 2014 not working on my virtual machine. Anyone else have any luck?
How many times this must be told? They almost all VM aware. Use real machine or patched VM.
  • 1
  • 8
  • 9
  • 10
  • 11
  • 12
  • 15