About

Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, September 30, 2020

IOC for Guildma Malware


SHA256 values of Guildma dropper (malware):

  • cbcb8717dd2bf61581ad3847422ab41d077f45ab5804c60052d4ce1da437f5c5
  • 6daf43959466c5cb0a9bef548c5e4c5c985d0746633cdff2e9e69578313e6a84
  • 98c2d92c4dc26b41b8c38f8fe3723a6874b13a2577d52ccda9e35147c9f27e0f
  • b9252c513ee1883bc7f85ce1de4b2aed31c9d423cc1b03fb3bf28d0324632c56


Post made by 

Saturday, March 7, 2020

Analysis of latest Trickbot malware sample - served in excel attachment

Twitter link:

The malware sample of trickbot was already submitted in the anyrun online sandbox for malware analysis.




We collected this malware sample and performed a manual analysis. The file details are:


Searched this hash in the VirusTotal for detection hits:


File name: Unpaid_invoice_1462.xls

File size: 109.5 KB
SHA256: 9e777e1e2e80909b5054c1eca935edc7046feb7d4546f40d392549e2f481d08e
MD5: 1f38f17810621dbff93a4e8cbd2ea1bf

This excel embedded with a macro that connects to a suspicious URL. We executed the malware in our VM, it prompts to enable the macro. After enabling, it to try to connect the following Link:

URL: pnxkntdl(.)xyz/KJSDBViad7

Currently, it didn’t download any other payloads.



Post made by

Wednesday, April 27, 2016

Dark Seoul Implant with zero detection:

Famous Malware researcher Snorre Fagerland tweeted that dark seoul implant having zero detection in Virustotal.

https://twitter.com/SnorreFagerland/status/725211677277310977

Here is the VT link:
https://www.virustotal.com/en/file/061044ffbebeebab449a13ee74799fd9c58b9b383149cbde7a7f6db77c54f72e/analysis/

At this time of writing, 0/56 in VT. i.e. No antivirus vendor flagged this implant.

Wednesday, August 6, 2014

Analysis of malicious VBscript:


Yesterday, AntiVir detects a vbscript as :VBS/Dldr.Agent.sver

I try had a hand with that and try to find what it is actually doing:

Malicious script

Formatted script using malzilla

If you look at the script, it set the site name as nosensetoblock and temp folder location as tfolder. It loads a cmd file in temp location as follows:

 var genesis is equal to "%TEMP%\\keybtc.cmd", autorotatedomain="images";

 Use the Try catch method for auto reply (refer the image).

 Its good detect these kind of scripts :).

Post made by
newWorld

Tuesday, August 5, 2014

Trojan: Wonton

VT Information about a malicious sample:

MD5e564d95cff4e3c7c14b8a149de41935a
SHA-1f9c256c5b2ae937a9b04d73ac88aaa782b8770dc
SHA-25657bab53ddf5ba525343218c78de26064d0e6b9a3cd739ebbe0ba2358ea2b7394
ssdeep12288:jN5mEjuyhoWgXk6Eqyli7B0d6hHBZ0FAb12:jNIEjuyhoWgXk6W07B0d6hHBqFAZ2
imphash a49926a7e80581b917867c2bd8cfdf8f
Size416.5 KB (426496 bytes)
TypeWin32 EXE
MagicPE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrIDWin32 Executable MS Visual C++ (generic) (64.5%) Win32 Dynamic Link Library (generic) (13.6%) Win32 Executable (generic) (9.3%) Clipper DOS Executable (4.1%) Generic Win/DOS Executable (4.1%)


 This malware through an error message when you execute:
But if you observe the changes in the system through process explorer and process monitoring tools, you will find some process with random character as process name which points to the %Application data%. This is obviously wired. And give one hundred percent confirmation to the user that we are executed a malware. If you use inctrl, it will log all the changes made in the files, folders and registries.                                              


Leading Antivirus such as Sophos detecting these set of malwares with the name :                                        

Troj/Wonton-FE



And Eset-Nod32 detect the same malwares with the name:

a variant of Win32/Agent.VNC



sophos write up
The above snap says what sophos says about the behavior of the samples. Sophos is pretty good AV.

Stay protected. Enjoy the cyber world.

Post made by 

Tuesday, June 17, 2014

Malware brief introduction:


Malware is a malicious software program (Mal+Ware=Malicious+software). Computer viruses, Trojan, Rootkits, Bootkits, Adware, Spyware, Backdoor, Crimeware, etc. comes under the category of malware. Malware is intended to infect the system, run the unauthorized programs in the system, utilize the system resources and even steal the credentials.

In dos virus era, computer viruses are used only for destruction purposes. And the earlier malware author did it for a fun and show their talent in the understanding of computers and its program's functionality. But the current trend is totally different. Yes, the current malware author not focusing on just destruction of the programs by infecting, their total focus on stealing the valuable credentials such as banking user name and password, email password, etc. Billions of Dollars were stolen using malware programs by malware authors.

Another important purpose of the malware is used as state of art and in other words as targeted attacks against a country or state, organisation by other arch-rival countries or organisation. It is known as APT (Advance persistent Threats). Threat actor may be underground cyber hacking groups or arch-rival Governments or state sponsored threat actors and its target is as we earlier told a country or state, big organisation (Billions of Dollars worth in terms of revenue).

Common people use the term virus (computer virus) for all the malicious programs, but computer virus is one of the malicious program or one of the categories in the malware. Virus files usually infect the system files and application files. So, it finally results in the malfunction of the computer programs. Only option is through disinfection method used by antivirus program or need to format the whole system and installing the operating system once again. Formatting the  system and installing the OS again, is time consuming work. Also, people will lost the important data stored in the system. If data may be songs and movies, but in greater extent, it was important official documents and it worth more than a movie or songs. In this case, using antivirus program is must. Since it have shield functionality to stop the known malware families or viruses to infect the system. Even infected program can be cleaned or disinfected by antivirus program, since they have cleaning routines for most of the virus families.

Antivirus or anti-malware engines will detect those malicious programs and remove it. Antivirus engine scan for signature in the all computer programs present in the system and notify the user. Signature is nothing but malicious code or routine and it only triggering the malicious event to happen. If such routines present in the file, then it will be detected by the antivirus engine. We can see more about on the same category in upcoming posts.

Saturday, December 21, 2013

The U.S National Security Agency (NSA) is reported to have installed computer malware in 50,000 computer networks around the globe. Reports in theWashington Post, based on documents provided by Edward Snowden, revealed that by the end of 2008 the NSA had 20,000 computers infected, and the number has increased to about 50,000 infiltrated computer networks today.
According to HLS News Wire the infections, considered, “Digital Sleeper Agents,” remain inactive within ...
see the rest of the information here:





http://i-hls.com/wp-content/uploads/2013/12/6812144_s-feature.jpg                                                                                            

Post by newWorld

ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch

ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch Category: Vulnerability Research | Windows Security |...