Sunday, July 29, 2012

Flamer /SkyWiper Samples

August 13, 2012 - added an article by CERT Polska

If you didn't get enough of Flamer /SkyWiper yet, here are the samples donated by a reader. They are also available on various forums and Virustotal. Whether they are new or old, part of the "Olympic Games" or not, they are a fine example of a targeted attack.  Enjoy



Update: Aug 13 More human than human – Flame’s code injection techniques Polish CERT


 Download all the files listed below (email me if you need the password)  - i fixed the password, redownload if you need to

Download additional June 2, 2012 files

File information

For the file functions see

  1. advnetcfg.ocx      MD5:  BB5441AF1E1741FCA600E9C433CB1550   Virustotal
  2. advnetcfg2.ocx    MD5:  8ED3846D189C51C6A0D69BDC4E66C1A5  Virustotal
  3. boot32drv.sys     MD5:  C81D037B723ADC43E3EE17B1EEE9D6CC Virustotal
  4. ccalc32.sys         MD5:  5AD73D2E4E33BB84155EE4B35FBEFC2B Virustotal 
  5. msglu32.ocx       MD5:  D53B39FB50841FF163F6E9CFD8B52C2E Virustotal
  6. mssecmgr.ocx     MD5:  BDC9E04388BDA8527B398A8C34667E18 Virustotal
  7. nteps32.ocx        MD5:  C9E00C9D94D1A790D5923B050B0BD741 Virustotal
  8. soapr32.ocx        MD5:  96E04ABB00EA5F18BA021C34E486746 Virustotal
  9. soapr32.ocx        MD5:  296e04abb00ea5f18ba021c34e486746 Virustotal
  10. name?                MD5:  37c97c908706969b2e3addf70b68dc13 Virustotal
  11. 00006411.dl       MD5:  b604c68cd46f8839979da49bb2818c36  Virustotal
  12. 00004784.dl       MD5:  ec992e35e794947a17804451f2a8857e Virustotal
  13.  name?               MD5:  c09306141c326ce96d39532c9388d764 Virustotal
  Additional (June 2, 2012)
  1. mssecmgr2.dll    MD5    0A17040C18A6646D485BDE9CE899789F Virustotal
  2. comspol32.ocx   MD5    20732C97EF66DD97389E219FC0182CB5 Virustotal
  3. soapr32.ocx       MD5    296E04ABB00EA5F18BA021C34E486746 Virustotal
  4. noname.dll         MD5    581F2EF2E3BA164281B562E435882EB5 Virustotal
  5. mscrypt.dat        MD5    5B03ED3894D88ADE1C72BA4A700A193F Virustotal
  6. boot32.ocx         MD5    646FE96ABF038834F8FEAEED8FFBD334 Virustotal
  7. noname.dll         MD5    75DE82289AC8C816E27F3215A4613698 Virustotal
  8. nteps32.ocx        MD5    BB4BF0681A582245BD379E4ACE30274B Virustotal
  9. noname.dll         MD5    BDDBC6974EB8279613B833804EDA12F9 Virustotal
  10. mscrypt.dat        MD5    C4D1CA8DD6ADA3EB1C5EB507516F7C84 Virustotal
  11. ??                      MD5    ee4b589a7b5d56ada10d9a15f81dada9 Virustotal
  12. advnetcfg.ocx     MD5    F0A654F7C485AE195CCF81A72FE083A2 Virustotal
  13.  ??                     MD5    F47BD1AF6F6FBC2559D6AB5069D394EB Virustotal
Alphabetical list of all files here

  1. Hi Mila, good to see you back after so long :)
    I've found some samples (6 or so) on the site, but not as many as listed here.
    Thanks for sharing!

  2. Mila,welcome back!

  3. #8 in the first list is only 31 characters


  7. So, I'm new to this malware analysis thing. Taking a few classes to learn it better. Any recommendations on best way to go about analyzing flame and others on this site? I hear this one is a nasty one, been reading about it a lot online.

    1. Hi, try more links or books

    2. I've got that book and would recommend it to you. The labs are a brilliant feature.

      @Mila Good to see your back.

    3. I've got that book and would recommmend it to you. The labs are a brilliant feature.

      @Mila it's good to see your back posting again.

  8. no problem, thank you all for the feedback!

