CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

MalRootkit droppers(assorted) for archiving/sharing

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2984
Location: Uk
MIRT Premium

PostPosted: Sun Feb 25, 2007 11:35 pm    Post subject: MalRootkit droppers(assorted) for archiving/sharing
Reply with quote

*live malware droppers*

Handle with care freinds Exclamation

Password= infected
2x Haxdor
2x Rustock's
1x Wincom32
1x All-in-one/ trojan injector


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6296
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Mon Feb 26, 2007 12:06 am    Post subject:
Reply with quote

Awesome , thanks .

These will be fun to play with .

Back to top
View users profile Send private message Send email
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2984
Location: Uk
MIRT Premium

PostPosted: Mon Feb 26, 2007 12:15 am    Post subject:
Reply with quote

Embarassed Rename old.old to whatever.exe for wincom32 but bare in mind it also drops a certain worm being trojan peed,peacomm aka *the storms* worm Razz


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2984
Location: Uk
MIRT Premium

PostPosted: Wed Mar 14, 2007 11:11 pm    Post subject:
Reply with quote

Another Haxdoor dropper Smile

CastleCops Link/t182521-MD5_66e2f5a02178e719a04d097eb820798b_ajdnjhfo10_exe.html


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2984
Location: Uk
MIRT Premium

PostPosted: Tue Aug 28, 2007 3:33 pm    Post subject:
Reply with quote

Better late then never Embarassed

Srizbi dropper>>>
http://www.symantec.com/enterprise/security_response/weblog/2007/07/spam_from_the_kernel_fullkerne.html


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
fatdcuk

MIRT Hunter
Premium Member

Joined: Oct 31, 2006
Posts: 2984
Location: Uk
MIRT Premium

PostPosted: Tue Aug 28, 2007 10:18 pm    Post subject:
Reply with quote

Razz and Runtime2.sys Cutwail/Bulknet dropper.

http://ca.com/securityadvisor/virusinfo/virus.aspx?id=62470


_________________
Malware hunter....Got Bot ?
http://www.castlecops.com/f269-Malware_Listserv.html
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer