Clicky

Pages

Showing posts with label Vir-Opachki. Show all posts
Showing posts with label Vir-Opachki. Show all posts

Sunday, March 7, 2010

March 2010 Opachki Trojan update and sample

I already posted a few links for Opachki trojan in November 2009.  Here is an update.


 
Download dropper.exe and dropped rundll32.dll as a password protected archive. Please contact me if you need the password

Details:
2ded7ee112cea2db509ba95dc09fded6  dropper.exe
032e8fced2fbed146c30a47d4989804b  rundll32.dll

March 2010 Virustotal scan results of the available sample. Please note this sample dates to October 2009. Newer versions and samples will have lower detection rate and may get slightly different names.

 File dropper.exe received on 2010.03.07 16:46:50 (UTC)
www.virustotal.com/analisis/787d0eae3fb29883b8dba9c3bcc00793baa4a54fbad0921d1aee7f5e6ad86907-1267980410
Result: 37/42 (88.1%)
a-squared    4.5.0.50    2010.03.07    Packed.Win32.Krap!IK
AhnLab-V3    5.0.0.2    2010.03.07    Win-Trojan/Krap.31232.K
AntiVir    8.2.1.180    2010.03.05    TR/Crypt.ZPACK.Gen
Antiy-AVL    2.0.3.7    2010.03.05    Packed/Win32.Krap.gen
Authentium    5.2.0.5    2010.03.06    W32/Trojan2.KMYU
Avast    4.8.1351.0    2010.03.07    Win32:MalOb-R
Avast5    5.0.332.0    2010.03.07    Win32:MalOb-R
AVG    9.0.0.787    2010.03.07    Win32/Cryptor
BitDefender    7.2    2010.03.07    Trojan.Generic.2594388
CAT-QuickHeal    10.00    2010.03.06    Trojan.Krap.ah
Comodo    4091    2010.02.28    TrojWare.Win32.Trojan.Agent.Gen
DrWeb    5.0.1.12222    2010.03.07    Trojan.Packed.683
eSafe    7.0.17.0    2010.03.04    Win32.Horse
F-Prot    4.5.1.85    2010.03.06    W32/Trojan2.KMYU
F-Secure    9.0.15370.0    2010.03.07    Packed:W32/Tikmis.gen!A
Fortinet    4.0.14.0    2010.03.07    W32/Krap.AH
GData    19    2010.03.07    Trojan.Generic.2594388
Ikarus    T3.1.1.80.0    2010.03.07    Packed.Win32.Krap
Jiangmin    13.0.900    2010.03.07    Packed.Krap.zvc
K7AntiVirus    7.10.990    2010.03.04    Trojan.Win32.Malware.4
Kaspersky    7.0.0.125    2010.03.07    Packed.Win32.Krap.ah
McAfee    5912    2010.03.06    Opachki.a
McAfee+Artemis    5912    2010.03.06    Opachki.a
McAfee-GW-Edition    6.8.5    2010.03.07    Trojan.Crypt.ZPACK.Gen
Microsoft    1.5502    2010.03.07    Trojan:Win32/Opachki.A
NOD32    4922    2010.03.07    Win32/TrojanDropper.Agent.OLQ
Norman    6.04.08    2010.03.07    W32/Crypt.dam
nProtect    2009.1.8.0    2010.03.07    Trojan/W32.Krap.31232.L
Panda    10.0.2.2    2010.03.07    Trj/Zlob.KH
PCTools    7.0.3.5    2010.03.04    Trojan.Generic
Prevx    3.0    2010.03.07    High Risk Cloaked Malware
Sophos    4.51.0    2010.03.07    Mal/FakeAV-BX
Sunbelt    5780    2010.03.07    Trojan.Win32.Generic!VS
Symantec    20091.2.0.41    2010.03.07    Trojan Horse
TrendMicro    9.120.0.1004    2010.03.07    TROJ_OPACHKI.I
VBA32    3.12.12.2    2010.03.05    BScope.Win32.AntiAV2010
VirusBuster    5.0.27.0    2010.03.06    Trojan.Opachki.EK
Additional information
File size: 31232 bytes
MD5...: 2ded7ee112cea2db509ba95dc09fded6

Monday, November 2, 2009

Win32/Opachki.A - Trojan that removes Zeus (but it is not benign)

Links updated: Jan 18, 2023

Download. Email me if you need the password
1) 
6762a2e15913e66b06a0953387bd87b0f9ce22b5939fe1efd46c7120df214d7c
2) 
MD5 00f2fd5e2c125965c188754f04da576c
SHA-1 63d53f6e1b3f9fb23c88b19f7c6326da45753a5d
SHA-256 a602a3dd91b5aa0e0e68d20efe787e01c9548cb1b11b5032541c2e7d4edb5710



Win32/Opachki.A --Virustotal-all antivirus names for it. The real tragedy is in those  http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf


nsrbgxod.bak created by Opachki http://www.threatexpert.com/report.aspx?md5=87a2583de6f6fbb5104e0433e89b1bcf and nsrbgxod.bak created by Zeus/ZBot http://www.threatexpert.com/report.aspx?md5=00f2fd5e2c125965c188754f04da576c (link lost)



Different hash


SecureWorks Opachki Trojan Analysis http://www.secureworks.com/research/threats/opachki

Threatexpert

Submission details:

Filename(s)

1 %Temp%\nsrbgxod.bak

0 bytes


MD5: D41D8CD98F00B204E9800998ECF8427E
SHA-1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
2 %UserProfile%\protect.dll
%Programs%Startup\ChkDisk.dll
%System%\autochk.dll


[file and pathname of the sample #1]


24,064 bytes

MD5: 0x87A2583DE6F6FBB5104E0433E89B1BCF

SHA-1: 6048D36DB2207A1CEA877742C9403A816D711C6D

Mal/UnkPack-Fam
[Sophos]

TrojanDropper:Win32/Opachki.A

[Microsoft]

Trojan-Dropper.Win32.Opachki

[Ikarus]

3 %Programs%\Startup\ChkDisk.lnk



655 bytes



MD5: 0x6F61156F14AEED438770D31391E67EC9

SHA-1: 0x277B806CEC1AEDE9F9B934B7DD655D0BBB542597

Read more -  Update March 2010