Posted August 12, 201114 yr Since noboy is interested, thread can be deleted please.zbot.zip Edited August 28, 201114 yr by ltheonel Attached sample to post...
August 12, 201114 yr Author ATTENTION: THIS IS A MALEWARE SAMPLE AND EXECUTION/ANALYSING IS ON OWN RISK!!!!!!!!! Hello, i got this Zeus bot sample this should connect to your local lan, there seems to be some selfchecking done inside it, that i dont understand. I obscured it with a simple crypter to analyse behavior but failed. If you have some interest tips for me just post, doing research now maybe a week You can break befor execution of resumethread and manipulate the entry of new created process thats where the maleware got deobfuscated in first layer. this is bot samlpe: crypted.bot:http://www.mediafire.com/?qryeecrg3j3se3c uncrypted.bot:http://www.mediafire.com/?idcx6gy3xmntd3j ATTENTION: THIS IS A MALEWARE SAMPLE AND EXECUTION/ANALYSING IS ON OWN RISC!!!!!!!!!
September 1, 201113 yr Is it looking for specific processes before injection?What is the password to the archive?Ted.
Create an account or sign in to comment