A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12840  by kalptarunet
 Sat Apr 21, 2012 1:00 pm
Hello,

I'm looking sample of

Dofoil”, also known as “Bredo”/ “Zurgop”,

AutoRun Value:

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\dxdiag.exe

Sorry not having any info or MD5.

Thanks,
 #12843  by hx1997
 Sat Apr 21, 2012 4:34 pm
kalptarunet wrote:Hello,

I'm looking sample of

Dofoil”, also known as “Bredo”/ “Zurgop”,

AutoRun Value:

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\dxdiag.exe

Sorry not having any info or MD5.

Thanks,
Maybe this one?
C1E5DAE72A51A7B7219346C4A360D867 - Win32/TrojanDownloader.Zurgop.AB trojan

Password "infected"
Attachments
(27.28 KiB) Downloaded 85 times
 #14363  by dumb110
 Fri Jun 29, 2012 10:48 am
SHA256: 9b200cd9c38f78e589dbe259b34fbb3da0a292b1fa2710927823d7dc14800aee

sample please..
 #14374  by rkhunter
 Sat Jun 30, 2012 7:23 am
dumb110 wrote:SHA256: 9b200cd9c38f78e589dbe259b34fbb3da0a292b1fa2710927823d7dc14800aee

sample please..
MD5: c6b3a65256f0948d65ce38d6435a9db8
SHA1: 1654bed972c0b5d75f9431f5fe39a7a9cfc61133
Attachments
pass:infected
(37.55 KiB) Downloaded 89 times
 #19552  by EP_X0FF
 Wed Jun 05, 2013 6:06 am
Dofoil using simplified version of PowerLoader style inject. Sample courtesy of noxnox. Dropper and payload attached.
Set breaks on NtCreateSection/SetWindowLongA to see more.

https://www.virustotal.com/en/file/83ed ... /analysis/
Attachments
pass: infected
(574.28 KiB) Downloaded 84 times
 #23179  by thisisu
 Sat Jun 21, 2014 8:37 pm
Win32/Dofoil.T

MD5 8176a3ec0aec664fb4170fdf9c9ee261
SHA1 034cee51257195b9b29e68d5ec714671de9ccc0d
SHA256 3d773d150fa014625c9c8718068d91b6a32b05431601754808e91ec1932512a8
https://www.virustotal.com/en/file/3d77 ... /analysis/
Code: Select all
HKU\Owner\...\Policies\Explorer\Run: [Ukcmedia] => C:\Users\Owner\AppData\Roaming\udbsfdsv\sgfautuj.exe [128008 2010-11-21] ()
Attachments
pass: infected
(72.38 KiB) Downloaded 68 times