Underc0de

[In]Seguridad Informática => Análisis y desarrollo de malwares => Mensaje iniciado por: Roda en Diciembre 20, 2014, 03:22:12 AM

Título: Virus Total Crypter byRoda
Publicado por: Roda en Diciembre 20, 2014, 03:22:12 AM
Para todo el foro les traigo...


(http://i.imgur.com/AMmqSbQ.gif)


(http://i.imgur.com/YBhzXUZ.gif) (http://i.imgur.com/nOyDVp4.gif) (http://i.imgur.com/RoovZYf.gif) (http://i.imgur.com/0gFBj0U.gif) (http://i.imgur.com/5Rh0SxX.gif)

Gracias Cruz

(http://i.imgur.com/2P96o6g.gif)

Algunos Rats que funcionan perfectamente

(http://i.imgur.com/EpdE0FG.png)

Vamos con los reportes...

Date and Time: 12/20/2014 05:54:34 UTC\n

File Name: Roda.exe
File Size: 28 KB
SHA1: abe07d6376392b665cc0cb18778a58ce65e8b828
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=21okzdaw_qwjugLkk


Date and Time: 12/20/2014 05:55:37 UTC\n

File Name: BolaMetalEncriptada.exe
File Size: 49.51 KB
SHA1: d89e1bc27b3700c13310ec1c44b6da9996aa932a
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=bno9gpoo_LxLnscKf


Trojans encrypted locally

Date and Time: 12/20/2014 05:57:27 UTC\n

File Name: Bozok.exe
File Size: 60.68 KB
SHA1: c6250107b4ede48bf53fe626c90c60bdfd46ca00
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=j78ppg64_DkifVLgF


Date and Time: 12/20/2014 05:59:07 UTC\n

File Name: NjWormVBS.exe
File Size: 49.18 KB
SHA1: b2497bc6b2865dee9d2f232c79a7b2183a607c1e
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=qbpmw852_YCkkawKt


Date and Time: 12/20/2014 06:00:42 UTC\n

File Name: Cybergate 1.7.5.exe
File Size: 298.68 KB
SHA1: 9bf99a1f01453f3f5de0e7624b920148657ab7ee
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=35dz6vqp_WzAdLycf


Date and Time: 12/20/2014 06:01:45 UTC\n

File Name: DarkComet.exe
File Size: 279.68 KB
SHA1: 889b7885858c0e4ae5343e4ec1896b3e63ac1c73
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=eo0d3arz_zbOrAFeG


Date and Time: 12/20/2014 06:02:31 UTC\n

File Name: Xtreme 3.7.exe
File Size: 49.18 KB
SHA1: 4b01fdbf0505a9dc8bd54809228c780d79847d0a
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=mopq0kn5_xgYHeYzX


Date and Time: 12/20/2014 06:03:39 UTC\n

File Name: SpyNet 2.7.exe
File Size: 496.68 KB
SHA1: 5cdb5c0d9a9d2119e8c6b90c44cb196011b65aad
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=tmyp10r7_lMpOUZOE


(http://i.imgur.com/jcSYMvB.gif)


Descarga

http://www22.zippyshare.com/v/55513099/file.html (http://www22.zippyshare.com/v/55513099/file.html)

Pass

MP


Agradecimientos y creditos: Tifons, Blau, MCN, Sudito y a todos los que diariamente colaboran


Crypter realizado 90% Source


(http://rs734.pbsrc.com/albums/ww344/luban5/virus-total-free.jpg~c200)


Cualquier duda o consulta estoy a vuestra disposicion


Sera hasta la proxima compañeros
Título: Re:Virus Total Crypter byRoda
Publicado por: blackdrake en Diciembre 20, 2014, 06:47:20 AM
Como siempre un aportazo y bien verde.

Muchas Gracias Roda ^^
Título: Re:Virus Total Crypter byRoda
Publicado por: hToWnKiLLeR en Abril 18, 2015, 10:54:09 PM
sí, estaba a punto de probar pero la contraseña es incorrecta en el archivo tiene un Istealer con quien yo quería probar esto: /

tested virus total :

https://www.virustotal.com/tr/file/44b173657133405f2f8ccc080ef2f134bd26e08bb8b12ee463c7bf606d34d316/analysis/

is 1/56 waht is dead 1??? Virus
Título: Re:Virus Total Crypter byRoda
Publicado por: Roda en Abril 19, 2015, 04:13:01 AM
ah bien...
Virus Total
que copado---
deci que es viejo y ya debe estar quemado
tendria que saber usted que ahi no se escanea