Hacktreides Posted February 7, 2017 Share Posted February 7, 2017 Hello, I find this malware in the wild, anyone know his family, and his packer type? There is a lot of junk code and a lot of selfextraded code, if someone have a quick way to unpack it. https://www.virustotal.com/en/file/86e6be6c7e474b2115aef450724ee1a6464b43888d45bdf48d0a404c7dd03b88/analysis/ Thank iphone_video.exe Link to comment Share on other sites More sharing options...
kao Posted February 7, 2017 Share Posted February 7, 2017 It's a custom protector and quite a good one. First layer removed, see attached RAR. Second layer does few anti-VM tricks and tries to inject code into explorer. Dump_00216AF8_00010000.rar Link to comment Share on other sites More sharing options...
Hacktreides Posted February 7, 2017 Author Share Posted February 7, 2017 You find same as me Any idea of his malware family? It seem to be a rat. Thank you Link to comment Share on other sites More sharing options...
Xyl2k Posted February 8, 2017 Share Posted February 8, 2017 Sound like Smokebot but it's not what i know, a evolution or fork maybe.. microsoft seem to agree about Smokebot (TrojanDownloader:Win32/Dofoil.AC) c2: https://www.virustotal.com/en/domain/2ancisco.net/information/ 2 Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now