Posts

Showing posts with the label win32

Trojan Win32 Tobfy M Affiliate

Image
Trojan Win32 Tobfy M Affiliate Came across a Tobfy sample today, things was interesting so here is a post. I will skip the reversing part: im a bit bored to take 50 screenshots and go step by step about whats do the M version of Tobfy. (this winlock is very primitive and relatively easy to understand) So, lets go directly to the C&C part. French landing when loaded (buggy IP retrieving, and geoloc): � dns: 1 �� ip: 91.226.212.174 - adresse: HKKPOGMPG.POLEXT-FREEHOST.RU � dns: 1 �� ip: 91.226.212.174 - adresse: AREKOV.COM Login: Registration: News: Statistics: Checks: Links/EXE (39090a097cfbe4ab766317e5f3d74b53): Rules: Affiliate stats: (Ignore the admin account, its also made by me) Affiliate Checks: Some samples took from the server: http://www.kernelmode.info/forum/viewtopic.php?f=16&t=2214&start=10#p19581 Im a bit unaware about Tobfy but that the first time i see this one on affiliate system. download file now

Trojan Win32 Spy Ranbyus

Image
Trojan Win32 Spy Ranbyus  Received a mail with an interesting exe https://www.virustotal.com/file/17a3ee51492b9b2ba155f54be61f2c305b090cee8d604d1df616ca3ba881b372/analysis/1359049655/ Thanks creep. This bot is used by one group of Russian carders and is not for sale, they call it triton IDA Map file imported to Olly, without IDA i got huge problem to understand the exe: Injects: Decoded strings (some, not everything): &pp=1 reg add " &files=1 nabagent.exe putty.exe [MOUSE R %dx%d] POST SeShutdownPrivilege UniStream.exe cbsmain.exe HKLM jawt.dll &net=1 disk%u.xml &scrn=1 &cmd=1 UZ.DB3 GET iexplore.exe ThunderRT6FormDC com.bifit.harver.core.DocumentBrowserFrame drweb.exe nabwatcher.exe WINNT bc_loader.exe avfwsvc.exe [VK_END] .iBank* aswupdsv.exe %s mp%xa%04d.$$$ /servlets/ibc bclient.exe EnableLUA secring client7.exe Western Union� Translink� Tiny Client-Bank /bsi.dll Content-type: multipart/form-data, boundary=%s Edit java.exe sign.key .PhysicalDrive0 inbank-st...

Trojan Win32 Reveton

Image
Trojan Win32 Reveton [root@heretyghyuiiiojk www]# What a cool hostname. "v" is GeoLiteCity.dat mixed with some php. images.rar is a payload downloaded by Reveton (cf here) The sql database have 4 tables: `balances`, `content`, `geoip_isp`, `stat_ips` Just the basic, landing for Italian ransom. And traces of german landing Code comments and variables name are in english By looking the code source of pages ive see that "shared.php" is used as panel with GET req only DB content: Codes: There is also a feature to erase vouchers. download file now