Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Posted

Hi, can anyone help me to figure out what this malware is packed with. PeID does not identify it, and VirusTotal gives these results from F-Prot and Authentium:

packers (F-Prot): PE-Armor, Malware_Prot.V

packers (Authentium): PE-Armor, Malware_Prot.V

I've attached the file in a password protected Rar, password is "password".

Any help would be appreciated. Thank you :)

Also, I'm new to these forums, so if I'm breaking any rules, please let me know.

malware.rar

Hi

Have you try this unpack with GUnpacker v0.41

this unpack PE-Armor 0.46, 0.49, 0.75, 0.765

I hope it helps

Greets,

  • Author

Thank you ragdog, GUnpacker appeared to have unpacked the file for me, however I think I still need to fix the IAT.

Both GUnpacker and deroko's oepfinder both tell me that my original entry point is most likely 402FD9, but imprec tells me that's wrong.

When this malware runs, it deletes itself almost immediately, so the only way I have been able to attach imprec to it has been by attaching to paused instance of it in olly.

On the plus side, looking the dumped file in hex mode, I noticed an abundance of "5A" bytes. When I XORd those blocks with 5A I was able to pull out a bunch of static strings that I couldn't get before, so I'm at least making some progress.

Am I even on the right track here? Thanks again, and if I'm asking things I should already know, please point me to the place I need to learn them..

-

This malware probably is the PoisonIvy RAT. I've attached the unpacked file, the password for the archive is "password".

unpacked.rar

  • Author
This malware probably is the PoisonIvy RAT. I've attached the unpacked file, the password for the archive is "password".

Thanks Armaked0n. I sent you a message.

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.