A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #6884  by EP_X0FF
 Mon Jun 20, 2011 10:59 am
EzzO wrote:Hello, I'm looking for this sample.
Please, help.
Thanks.
Virus:Win32/Slugin.A
Attachments
pass: malware
(867.9 KiB) Downloaded 163 times
 #6885  by EzzO
 Mon Jun 20, 2011 11:08 am
EP_X0FF wrote:
EzzO wrote:Hello, I'm looking for this sample.
Please, help.
Thanks.
Virus:Win32/Slugin.A
many thanks, but this is another modification. I need exactly that modification which with this md5: 3a7436f156e1ef28a4b313c4e58a2454
Many thanks.
 #6886  by EP_X0FF
 Mon Jun 20, 2011 11:16 am
This is PE infector where Virus:Win32/Slugin.A!dll is the DLL component of Virus:Win32/Slugin.A. It contains the infection routine for the virus.
Chances to get exactly this infected installer exe from VT report are low.
 #6901  by PX5
 Wed Jun 22, 2011 7:12 am
Agree with EP, finding actual infector is 10,000 to 1 chance but can use attached exe, found by your hash, to infect system if like, atleast if itll stop the continual request for same stuff. ;)
Attachments
(63.18 KiB) Downloaded 102 times