Author Topic: crazy malware author - 48 layers of obfuscation  (Read 5399 times)

0 Members and 1 Guest are viewing this topic.

October 08, 2008, 10:47:19 pm
Read 5399 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

October 09, 2008, 12:01:37 am
Reply #1

Tigger`

  • Newbie

  • Offline
  • *

  • 6
They are always trying to make it harder to detect things.  :)

October 09, 2008, 09:52:05 am
Reply #2

Orac

  • Special Members
  • Hero Member

  • Offline
  • *

  • 723
    • malwareremoval.com
Thats just crazy, if your going to go that far at least use 48 layers of different obfuscation techinques, not the same one recycled. Yet another skiddie with way too much time on their hands !!
Malware analysised using clarified analyzer to record and document how malware behaves in a networking environment

October 09, 2008, 07:39:20 pm
Reply #3

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
LOL! ...... ya gotta love these skiddies
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

October 09, 2008, 08:04:00 pm
Reply #4

julevine

  • Special Access
  • Jr. Member

  • Offline
  • *

  • 14
if someone finds a sample Can you post a rar file with the code so i can study it

thanks

October 09, 2008, 09:39:32 pm
Reply #5

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
if someone finds a sample Can you post a rar file with the code so i can study it

thanks

I had contacted the author of the article (Marco Cova) and got a quick response.
Here is the sample. PW is "mdl".

Comment from Marco
Quote
I've attached the phishing kit that contains the sample. The code I was referring to on the blog is contained in the loginsubmit.php file. The file amen.php also looks similar.



Ruining the bad guy's day