Jump to content


- - - - -

Maleware selfchecking Zeus Bot


  • Please log in to reply
2 replies to this topic

#1 ltheonel

ltheonel

    Newbie

  • (Junior+)
  • 9 posts

Posted 12 August 2011 - 05:25 PM

Since noboy is interested, thread can be deleted please.

Attached Files

  • Attached File  zbot.zip   229.13K   17 downloads

Edited by ltheonel, 28 August 2011 - 05:20 AM.
Attached sample to post...


#2 ltheonel

ltheonel

    Newbie

  • (Junior+)
  • 9 posts

Posted 12 August 2011 - 05:27 PM

View Postltheonel, on 12 August 2011 - 05:25 PM, said:

ATTENTION: THIS IS A MALEWARE SAMPLE AND EXECUTION/ANALYSING IS ON OWN RISK!!!!!!!!!

Hello, i got this Zeus bot sample this should connect to your local lan, there seems to be some selfchecking done inside it, that i dont understand.
I obscured it with a simple crypter to analyse behavior but failed.
If you have some interest tips for me just post, doing research now maybe a week :(

You can break befor execution of resumethread and manipulate the entry of new created process thats where the maleware got deobfuscated in first layer.

this is bot samlpe:
crypted.bot:http://www.mediafire.com/?qryeecrg3j3se3c
uncrypted.bot:http://www.mediafire.com/?idcx6gy3xmntd3j

ATTENTION: THIS IS A MALEWARE SAMPLE AND EXECUTION/ANALYSING IS ON OWN RISC!!!!!!!!!


#3 Teddy Rogers

Teddy Rogers

    Site Administrator

  • (Administrator)
  • 9,627 posts
  • Gender:Male
  • Location:Australia

Posted 01 September 2011 - 12:15 PM

Is it looking for specific processes before injection?

What is the password to the archive?

Ted.

Posted Image
I would love to change the world, but they won't give me the source code...





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users