Welcome,
Guest
. Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Home
Help
Search
Login
Register
Malware Domain List
»
Malware Related
»
Malware Analysis
»
zeus/prg/zbot/ntos/wnspoem config file decryptor
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: zeus/prg/zbot/ntos/wnspoem config file decryptor (Read 13204 times)
0 Members and 1 Guest are viewing this topic.
January 01, 2009, 12:25:07 pm
Read 13204 times
SysAdMini
Administrator
Hero Member
Offline
3335
zeus/prg/zbot/ntos/wnspoem config file decryptor
http://blog.threatexpert.com/2008/12/zeus-config-decryptor.html
Logged
Ruining the bad guy's day
January 18, 2009, 05:54:49 pm
Reply #1
SysAdMini
Administrator
Hero Member
Offline
3335
Re: zeus/prg/zbot/ntos/wnspoem config file decryptor
This decryptor tool doesn't work for the latest version of zeus.
The config file of new zeus versions is encrypted by a key which
is compiled into the binary.
That means you need an unpacked copy of the corresponding
binary in order to decrypt the config.
example :
Code:
[Select]
hxxp://58.65.236.41/cfg.bin
hxxp://58.65.236.41/z.exe
/EDIT
See also the translation of a Spanish article
http://translate.google.com/translate?prev=hp&hl=en&u=http%3A%2F%2Fblog.s21sec.com%2F2009%2F01%2Fnuevas-muestras-de-zeus.html&sl=auto&tl=en
Logged
Ruining the bad guy's day
January 03, 2010, 06:35:24 pm
Reply #2
SysAdMini
Administrator
Hero Member
Offline
3335
Re: zeus/prg/zbot/ntos/wnspoem config file decryptor
Decrypting the Zeus Config File
http://traversecode.blogspot.com/2009/12/decrypting-zeus-config-file.html
Logged
Ruining the bad guy's day
May 03, 2010, 07:30:00 am
Reply #3
SysAdMini
Administrator
Hero Member
Offline
3335
Re: zeus/prg/zbot/ntos/wnspoem config file decryptor
Config Decryptor for ZeuS 2.0
http://blog.threatexpert.com/2010/05/config-decryptor-for-zeus-20.html
Logged
Ruining the bad guy's day
Print
Pages: [
1
]
Go Up
« previous
next »
Malware Domain List
»
Malware Related
»
Malware Analysis
»
zeus/prg/zbot/ntos/wnspoem config file decryptor