Log in

View Full Version : Undetected home work


OHPen
February 6th, 2009, 09:58
Hey guys,

i found that piece of probably mal or spamware. it is packed with a custom wrapper. interesting is that jotti online scan didn't detect anything. maybe its of interest for someone here.

regards,
OHPen

malware password: "malware"

esther
February 6th, 2009, 12:30
hi,
The custom wrapper seems just like RxcNnmtP which Cthulhu posted on another thread and yeah my av doesn't detect either

Kayaker
February 6th, 2009, 12:39
Yeah, same shit, different name.

Take a look at this weeks installment of Dancho Danchev's continuing series on the names of Fake Security Software. "systemguard2009" is one of the many aliases.


A Diverse Portfolio of Fake Security Software - Part Fifteen

http://ddanchev.blogspot.com/2009/02/diverse-portfolio-of-fake-security.html

OHPen
February 6th, 2009, 12:58
hehe, didn't know that packer. seems that this packer is interesting if avs are so far not able to detect it

thx for that link, btw.

regards,
OHPen

OHPen
February 6th, 2009, 13:01
Ah thats, cool i just read the articles from your link and its posted that the malware is from the RBN. Its the first time that i am confronted with the "work" of the RBN people.
that fact alone makes it intersting to take a deeper look for

evaluator
February 6th, 2009, 15:45
>>if avs are so far not able to detect it

inverse!
this packer used with TDSS group malwares, easy detecteble-unpackable.
it not detected as virus, bcoz it is not! it is actually installer-downloader.

evaluator
February 6th, 2009, 16:04
uploaded for you guys, just verify: is your GetSystemDefaultUILanguage
luky!?
@40c290 19 UILangs