Cthulhu
January 27th, 2009, 13:14
I found this trojan that seems to be an IRC Bot according to virustotal.com
I've never seen this packer before.
PWD: malware
I've never seen this packer before.
PWD: malware
View Full Version : Malware packed with unknown packer
.xeh:00415767 F3 A4 rep movsb
.xeh:00415769 61 popa
.xeh:0041576A 83 C2 28 add edx, 28h
.xeh:0041576D 41 inc ecx
.xeh:0041576E 81 F9 03 00+ cmp ecx, 3
.xeh:00415774 72 D2 jb short loc_415748
.xeh:00415774
.xeh:00415776 B8 B2 59 40+ mov eax, 4059B2h
.xeh:0041577B FF D0 call eax ; sub_4059B2
.xeh:0041577B
.xeh:0041577D C3 retn
[Originally Posted by anom;78993]The password is "malware", in case anyone's wondering. |
[Originally Posted by evaluator;79002]hey! packer is dumb, but seems this is VNSPOEM, which i did unpacked already here.. |