carb0n Posted December 15, 2008 Posted December 15, 2008 There was a file sent from my email that I didn't authorize, me and my staff have been analyzing but haven't come u with a lot of stuff, here is what we got so far:johnnyk analyzed the crypter drops this smss.exe into windows directory hers some reports http://anubis.iseclab.org/?action=result&a...amp;format=html http://research.sunbelt-software.com/ViewM...aspx?id=6585843 http://www.novirusthanks.org/analisis/39b5...18cba37b757e2b4 plus it dorps this crypter.exe and this txt file saying Your files zip,rar,doc,txt,xls,ppt,vbs,htm,html,pas,bas,c,cpp,exe were encrypted . Send mail to unknowncrypter@mail.ru for unencryption key. Your PC has been marked - reporting this activity may lead to the complete deletion of your HDD.cm2guys I ran the file through the lab computer which is a winxp machine NOT updated using internet explorer 6 has avg.tcpmon showed no outside connections now while both the main file and the stub both do alot of querying and copies into the prefetch I don't see much in the way of activity they both ran and then stopped the lab is not a virtual pc it is a live installation on a separate hddfilemon showed that it queried alot for the gdi exploit but was not able to execute.it does modify the host file to hackhound.org 127.0.0.1in the end the file APPEARED to run look for some exploitable shiz and then endI have not seen any effects of this exe on the labIT DOES try and set itself to run as a debugger in the gdl execute debugger registry entrybut other than that I don't see anything else happeningwill continue to monitor tonight So if you guys find anything else, please let me know, thanks.http://rapidshare.de/files/41145344/backdoored.rar.html
GamingMasteR Posted December 16, 2008 Posted December 16, 2008 Your files zip,rar,doc,txt,xls,ppt,vbs,htm,html,pas,bas,c,cpp,exe were encrypted . Send mail to unknowncrypter@mail.ru for unencryption key. Your PC has been marked - reporting this activity may lead to the complete deletion of your HDD.This message reminds me of GPcode !
movzxEax Posted December 16, 2008 Posted December 16, 2008 sounds like a gpcode variantehttp://people.csail.mit.edu/tromer/gpcode/
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now