Clicky

Pages

Showing posts with label rootkit. Show all posts
Showing posts with label rootkit. Show all posts

Tuesday, March 20, 2018

Rootkit Umbreon / Umreon - x86, ARM samples



Pokémon-themed Umbreon Linux Rootkit Hits x86, ARM Systems
Research: Trend Micro

There are two packages
one is 'found in the wild' full and a set of hashes from Trend Micro (all but one file are already in the full package)


Download Email me if you need the password  

 

Friday, December 7, 2012

Aug 2012 - Hikit APT rootkit sample



End of the year presents:
This is a sample of Hikit rootkit 
Aug 2012
Related News and Analysis:
The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 1) - Mandiant



Thursday, May 3, 2012

Xpaj -MBR rootkit sample - sample


News about Xpaj file infector brought this new donation of a sample, which i am posting now. I will add the network capture and sandbox report to augment the detailed analysis reports released by Bitdefender Xpaj - the bootkit edition and Symantec W32.Xpaj.B is a File Infector with a Vengeance
The file is meant to look like a crack of sorts for Big Air Stoked game



I accidentally overwrote this post with a blank one, many thanks to Lotta for sending the cached page and helping recreate it. It was not a long and detailed post but I wouldn't have time to redo it.


Wednesday, April 18, 2012

DarkMegi rootkit - sample (distributed via Blackhole)

Update April 20, 2012 Kimberly wrote an excellent analysis of this sample. Please go to
Stopmalvertising to read

This is a "DarkMegie" rootkit sample, kindly donated by Hendrik Adrian. Just like described in the McAfee article "Darkmegi: This is Not the Rootkit You’re Looking For" by Craig Schmugar, it is anything but quiet and stealthy. In fact, it makes so many system changes that it is hard to cover it all in a quick post.
Indeed, it drops the rootkit components in drivers with the incredible padding to 25MB and generates a lot of traffic. Unfortunately, I did not have time yet to sort out the mess and purpose of all files that this malware creates so I am just posting it here along with sandbox results for you to analyze. If you write a detailed analysis, please share,  I will link to.

Wednesday, February 1, 2012

TDL4 - Purple Haze (Pihar) Variant - sample and analysis


Lately things just don't seem the same
Actin' funny, but I don't know why
'Scuse me....... while I kiss the sky
 Jimi Hendrix "Purple Haze"
I recently ran into an interesting piece of malware that was downloaded on a victim's computer. I thought it was TDL/TDSS or maybe a new version of it as it had same components as TDL4 bootkit with a functionality of a mass scale PPC (pay-per-click) fraud. TDL had this functionality too and it is most likely spread by the same Russian-speaking gangs using the Blackhole exploit kit. It did not have the same type of config file that you may find in TDL4 (and first I could not find it at all). I call it "Purple Haze" thanks to the strings found in the code.

I shared it with Alexander Matrosov from ESET. He and Eugene Rodionov  analyzed it and posted an article on the ESET blog: "TDL4 reloaded: Purple Haze all in my brain" (edited by David Harley)
Eset also updated the removal tool for this variant - direct download link: OlmarikTDL4 remover

Friday, October 7, 2011

Rustock samples and analysis links. Rustock.C, E, I, J and other variants

 

 I thought that Russian Matryoshka aka Rustock the Nested Doll would be a good subject after the previous post about Trojan.Matryoshka (Taidoor) analyzed by Jared Myers from CyberESI. Russian rootkit Rustock is as notorious as TDSS or Stuxnet and is very sophisticated. Many researchers made detailed analysis of Rustock and this is why it is a great subject of study. The botnet is down but the malware is here for you to play and try to reverse on your own or following one of the analysis papers posted below.

Monday, September 19, 2011

Mebromi BIOS rootkit affecting Award BIOS (aka "BMW" virus)


On September 13, 2011, Marco Giuliani from Webroot posted a detailed analysis of Mebromi - BIOS rootkit affecting Chinese computers with AWARD BIOS, which was earlier discovered by Qihoo 360. As noted by cfans from bbs.kafan.cn and kerne1_madman from hi.baidu.com/kerne1_madman, the infection starts with a binary with MD5 1AA4C64363B68622C9426CE96C4186F2 that downloads the actual dropper MD5 BB5511A6586BA04335712E6C65E83671. While looking for the samples, I found one domain referenced on CleanMX on 2011-08-31 that was used for distribution of the downloader with binary called qvodffs.exe MD5 1AA4C64363B68622C9426CE96C4186F2  hxxp://av.88ss.info/qvodffs.exe.  In other cases it was called 123.exe (noted by Prevx  -seen on Aug 29, 2011 )

Thursday, July 7, 2011

Rootkit TDL-4 (TDSS, Alureon.DX, Olmarik, TDL) 32-bit and 64-bit Sample + Analysis links - Update July 7


Old version 3 -  See August 27, 2010  TDL3 dropper (x86 compatible with x64 systems).

General File Information - April 2011

 This is an updated version of TDL4, which made a lot of news recently thanks to being named the ‘indestructible’ botnet. This is the last / current version and it is dated April 2011 (the previous version is from January 2011)

All the credits and many thanks for the files and comments go to @EP_X0FF @InsaneKaos @markusg @USForce from KernelMode.info. I am posting the files and their comments here because of the the large number of inquiries for the updated version.

KernelMode.info:
Version TDL4 (April 2011 edition)
1) Bypassed Microsoft patch (STATUS_INVALID_IMAGE_HASH error overwritten) to be able again to infect x64 OS
2) Bypasssed Microsoft patch to kdcom.dll (this version of TDL4 checks kdcom resource directory size on the x64 version of it, whether it is == 0x110 || 0xFA)
2) Improved disk minport filtering hook
Version history:
  1. 0.01 firstly detected ITW in the end of July 2010
  2. 0.02 August 2010, version with x64 support
  3. 0.03 September 2010, small changes, new C&C library
  4. In April 2011 Microsoft released KB2506014 targeting 0.03 version, exactly boot loader and kd dll - and it was able to successfully prevent TDL4 from working. However, the rootkit support strike back within two weeks releasing their update, which could bypass the MS patch. The rootkit version wasn't changed.
Related articles:
List of samples included

File: TDL4.exe
Size: 146944
MD5:  4A052246C5551E83D2D55F80E72F03EB
http://www.virustotal.com/file-scan/report.html?id=b75fd580c29736abd11327eef949e449f6d466a05fb6fd343d3957684c8036e5-1305275113

File: dll (2).exe
Size: 140288
MD5:  D69B02C1ACD87B5A5C33B19693E24020
http://www.virustotal.com/file-scan/report.html?id=fe165840b709adb5b7765ea329c317f64d05a402873c8d8cea84873cbe192bf4-1304405700

File: DLL.exe
Size: 140288
MD5:  A1DE5B3607845F5C6597528BE02EBDA5
http://www.virustotal.com/file-scan/report.html?id=1aa5708519389ddcf96fa6206cf274844414c58bff6e3f8338188364449f4509-1304402425



Download TDL4 - April 2011 edition files listed above as a password protected archive (contact me if you need the password)


Thursday, February 24, 2011

ZeroAccess / Max++ / Smiscer Crimeware Rootkit sample for Step-by-Step Reverse Engineering by Giuseppe Bonfa - << (Update 2011 version available)

Post Update Feb 24, 2011

 The new version is available here, thanks to Guiseppe :)

Download MaxRootkit_2011_1.exe as a password protected archive (contact me if you need the password)

  File name: 392ddf0d2ee5049da11afa4668e9c98f

Virustotal
Submission date 2011-02-14 14:41:24 (UTC)
Result:25 /43 (58.1%)
Antivirus     Version     Last Update     Result
AhnLab-V3     2011.02.14.02     2011.02.14     Trojan/Win32.Gen
AntiVir     7.11.3.78     2011.02.14     TR/Dropper.Gen
Avast     4.8.1351.0     2011.02.14     Win32:FakeAlert-FC
Avast5     5.0.677.0     2011.02.14     Win32:FakeAlert-FC
AVG     10.0.0.1190     2011.02.14     Dropper.Generic3.AJH
BitDefender     7.2     2011.02.14     Trojan.Generic.5349632
CAT-QuickHeal     11.00     2011.02.14     Worm.Sirefef.a
DrWeb     5.0.2.03300     2011.02.14     Trojan.DownLoader2.2219
Emsisoft     5.1.0.2     2011.02.14     Worm.Win32.Sirefef!IK
F-Secure     9.0.16160.0     2011.02.14     Trojan.Generic.5349632
Fortinet     4.2.254.0     2011.02.14     W32/Dx.VUZ!tr
GData     21     2011.02.14     Trojan.Generic.5349632
Ikarus     T3.1.1.97.0     2011.02.14     Worm.Win32.Sirefef
McAfee     5.400.0.1158     2011.02.14     Generic.dx!vuz
McAfee-GW-Edition     2010.1C     2011.02.14     Heuristic.BehavesLike.Win32.Suspicious.H
Microsoft     1.6502     2011.02.14     Worm:Win32/Sirefef.gen!A
NOD32     5872     2011.02.14     a variant of Win32/Sirefef.C
Panda     10.0.3.5     2011.02.13     Trj/CI.A
PCTools     7.0.3.5     2011.02.13     Trojan.Gen
Rising     23.45.00.00     2011.02.14     [Suspicious]
Symantec     20101.3.0.103     2011.02.14     Trojan.Gen
TheHacker     6.7.0.1.130     2011.02.13     Trojan/Sirefef.c
TrendMicro     9.200.0.1012     2011.02.14     TROJ_GEN.R3EC1BD
TrendMicro-HouseCall     9.200.0.1012     2011.02.14     TROJ_GEN.R3EC1BD
VIPRE     8416     2011.02.14     Trojan.Win32.Generic!BT
MD5   : 392ddf0d2ee5049da11afa4668e9c98f


 

Infosec resources published  an excellent and very detailed 4 part tutorial by Giuseppe Bonfa
Step-by-Step Reverse Engineering Malware: ZeroAccess / Max++ / Smiscer Crimeware Rootkit

Part 1: Introduction and De-Obfuscating and Reversing the User-Mode Agent Dropper
Part 2: Reverse Engineering the Kernel-Mode Device Driver Stealth Rootkit
Part 3: Reverse Engineering the Kernel-Mode Device Driver Process Injection Rootkit
Part 4: Tracing the Crimeware Origins by Reversing the Injected Code

The full tutorial is at Infosec resources

To follow the tutorial, you need a hex editor of your choice (e.g. Hex Workshop) , debugger (Ollydbg) plus the malware ZeroAccess rootkit (see download section below)

 

Nov 18, 2010 Whitehat cracks notorious rootkit wide open - The Register

 

Download MaxRootkit_2011_1.exe as a password protected archive (contact me if you need the password)

 If you are interested in other Reverse Engineering tutorials, you can find many at  

read more...

.