Quantcast
Channel: A blog about rootkits research and the Windows kernel
Viewing all articles
Browse latest Browse all 58

Interesting malware of the month: trends and hashes

$
0
0

Interesting malware that already discussed at last month.

1. ZeroAccess/Sirefef was updated. With feature of cross-platform file-infector and shellcode.

SHA1: 23e1f3a819e4e4af58c4a6d5eb489b90ebd7ae8f
MD5: c6e73a75284507a41da8bef0db342400

2. Stuxnet droppers with Flamer proto-component inside.

SHA1: 46104bf26300a5fb7a4f799d80e141b95465d0cc
MD5: 2fb979eb3e8d8b1571cdd0df33427969

SHA1: 6da3bb3face857638d0af027f52933b037e48c57
MD5: d705ae2f0b0a21e48d42c6ffdf5a171c

3. ZBot droppers with original anti-emu crypter/packer.

SHA1: 01125257e3baf7132345d93e60560cd19ca29914
MD5: 612700f68e7e9c62c3c754cdeff6caa5

MD5: 31cf2ccf68f7a1619557b4419df695a7
SHA1:  f88a9ddf11fa6a897c555ce9116dba931fde22c5

4. Cleaman.G trojan with features of hosts-file modifications and ring-3 "rootkit".

SHA1: 8d502546c344a16c66ff4ee82dda3004343d3ff9
MD5: 1cb27d4ecd25c2030ebb6a1a9b7e3321

5. Pushbot worm via facebook spreading with ring3 "rootkit" feature.

SHA1: 8284814c5c5cb0f37fe200b918b65ef89c259a0a
MD5: 3e50b76c0066c314d224f4fd4cbf14d5

6. Trojan/Win32.OnlineGameHack - Korean games-cheater and AV-killer, targeted to AhnLab-V3 AV killing.

SHA1: 53b1ce48f2b0cf3c7028184676be7b21485bd45a
MD5: ab551ebc28e4cbcdcb44b1175e14038b

7. Simona trojan - Korean multi-AV killer, targeted to Kaspersky, Avast and others with rootkit (FSD-drivers hooking).

SHA1: 9d810d82ed897d32c3874cb093ad82b79a176303
MD5: 3083f4301416130f0e42ace95261645c

Viewing all articles
Browse latest Browse all 58

Trending Articles