Author Topic: ms1.exe and data.exe  (Read 8263 times)

0 Members and 1 Guest are viewing this topic.

October 26, 2007, 05:03:00 pm
Read 8263 times

sowhat-x

  • Guest
Quote
hxxp://ww.mtwor.com/ms1.exe

MD5 Hash -  E50EE7BB625302DAACA03ECFE07930A7

FSG 2 used on this one,multiple naming conventions from AV companies,
but the most common among them was "Delf.crp" or so...

Quote
hxxp://ww.mtwor.com/ms1/data.exe

MD5 Hash - 7245CE2FB66DC572B8AD2B2AA0695554

PEiD doesn't detect the packer used internally (yet).
EP Section name is ".bedrock" though,and it certainly isn't some sign-faker:
I can assure you this is Bambam speaking here...

VirusTotal's engine reports too many different names to be listed here.
It also (incorrectly) flags the packer as "NPack".





October 26, 2007, 06:58:16 pm
Reply #1

JohnC

  • Special Members
  • Hero Member

  • Offline
  • *

  • 1964
Thanks, these will be in the list soon.