Presented at a conference in May 2012
It is just pictures and not very useful without the narration. Email me if you need commentary for any of the slides
Download pdf
![]() |
| Angus McIntyre |
![]() |
| bbtoystore.com |
News about Xpaj file infector brought this new donation of a sample, which i am posting now. I will add the network capture and sandbox report to augment the detailed analysis reports released by Bitdefender Xpaj - the bootkit edition and Symantec W32.Xpaj.B is a File Infector with a Vengeance
Red dots indicate the sample download links - same password on all by the scheme. Email me if you need it. With many thanks to Hendrik for his work and contributions.| Dr.Web image |
1. A few hours after I posted the Flashback.K, someone anonymously uploaded Flashback.O sample (thank you very much!), which I am posting below. Like in the first case, it is a payload binary from a victim, not the downloader, which makes it impossible to install. If you succeed or have a binary that installs, please share. I personally have not tried to run them yet, did not have a vm.| Examples of referrers blacklisted by Blackhole exploit kit |
Greetings,| fputlsat.dll |
| Lately things just don't seem the same Actin' funny, but I don't know why 'Scuse me....... while I kiss the sky Jimi Hendrix "Purple Haze" |