About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Saturday, August 10, 2013

Alina POS v.5.3 strings -CRIME

robohash
File: Alina-POS_
4C754150639AA3A86CA4D6B6342820BE
MD5:  4c754150639aa3a86ca4d6b6342820be
Size: 48128

Ascii Strings:




---------------------------------------------------------------------------
!This program cannot be run in DOS mode.
2VRiche
.text
`.rdata
@.data
.rsrc
@.reloc
---------------------------------snip
VVVVV
Taskmgr.exe
services.exe
dasHost.exe
csrss.exe
cmd.exe
rundll32.exe
ctfmon.exe
scvhost.exe
svchost.exe
explorer.exe
defender
.exe
string too long
invalid string position
Software\Microsoft\Windows\CurrentVersion\Run
errorretrieving
Alina v
[%s:%d <%x>]
{[!29!]}{[!1!]}
dwm.exe
win-firewall.exe
adobeflash.exe
desktop.exe
jucheck.exe
jusched.exe
java.exe
{[!2!]}{[!20!]}{[!21!]}%s
{[!3!]}%s{[!4!]}
AKW.exe
QML.exe
spoolsv.exe
taskmgr.exe
wscntfy.exe
alg.exe
winlogon.exe
lsass.exe
dllhost.exe
pidgin.exe
skype.exe
thunderbird.exe
devenv.exe
steam.exe
wininit.exe
smss.exe
iexplore.exe
firefox.exe
chrome.exe
{[!6!]}%x{[!7!]}0x%x ( {[!8!]}%x).{[!9!]}%d.{[!45!]} = %d):
esp@0x%x:
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
0x%8x
{[!11!]}{[!4!]}
{[!12!]}{[!10!]}http://%s:%d{[!4!]}
{[!13!]}{[!4!]}
{[!15!]}{[!4!]}
{[!14!]}{[!4!]}
Accept: application/octet-stream
Content-Type: application/octet-stream
Connection: close
POST
HTTP/1.1
%%%02x
vector<T> too long
map/set<T> too long
invalid map/set<T> iterator
{[!46!]}%d{[!1!]}
{[!16!]}{[!46!]}%s (%d)
card
cards
A/adobe/version_check.php
91.229.76.97
{[!22!]}%s{[!5!]}
dlex=
{[!23!]}{[!22!]}, {[!24!]}{[!4!]}%d{[!25!]}
update=
chk=
{[!17!]}{[!19!]}
log=0
{[!17!]}{[!18!]}
log=1
cardinterval=
updateinterval=
diag
update
{[!16!]}{[!20!]}{[!26!]}%s
{[!29!]}{[!32!]}%s
\\.\pipe\alina
{[!28!]}%d.%d, {[!29!]}%d.%d.{[!1!]}
{[!27!]}{[!30!]}{[!4!]}%s.{[!2!]}
{[!30!]}{[!31!]}{[!4!]}
{[!4!]}{[!10!]}{[!44!]}{[!43!]}{[!21!]}
{[!4!]}{[!45!]}{[!21!]}
{[!37!]}{[!35!]}{[!4!]}{[!38!]}0x%x,{[!39!]}0x%x.
{[!43!]}{[!4!]}
{[!22!]}{[!18!]}{[!33!]}{[!4!]}{[!34!]}= %d, {[!35!]}= 0x%x.{[!36!]}
{[!40!]}{[!4!]}{[!36!]}
{[!41!]}{[!4!]}{[!42!]}= 0x%x, {[!34!]}= 0x%x.{[!36!]}
{[!22!]}{[!5!]}%s -> %s [%d]{[!35!]}= 0x%x (== 0x%x)
{[!37!]}{[!35!]}{[!4!]}{[!38!]}0x%x,{[!39!]}0x%x.{[!36!]}
Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.152 Safari/537.22
http://
.exe
RSDSN
C:\Users\dice\Desktop\SRC_adobe\src\grab\Release\Alina.pdb
Process32Next
OpenProcess
GetCurrentProcessId
CloseHandle
Process32First
CreateToolhelp32Snapshot
GetModuleFileNameA
GetComputerNameA
GetVolumeInformationA
CreateProcessA
CopyFileA
Sleep
TerminateProcess
DeleteFileA
CreateFileA
GetLastError
GetCurrentProcess
GetModuleHandleA
ReadProcessMemory
CreateThread
AddVectoredExceptionHandler
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
DeleteCriticalSection
SetThreadPriority
VirtualQueryEx
GetTickCount
GetProcessId
IsWow64Process
TerminateThread
CreateNamedPipeA
CallNamedPipeA
WaitNamedPipeA
DisconnectNamedPipe
WriteFile
ReadFile
ConnectNamedPipe
GetFileSize
KERNEL32.dll
RegSetValueExA
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
SHGetFolderPathA
SHELL32.dll
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z
MSVCP100.dll
strstr
??0exception@std@@QAE@ABQBD@Z
?what@exception@std@@UBEPBDXZ
??1exception@std@@UAE@XZ
??3@YAXPAX@Z
memcpy
memmove
memset
??2@YAPAXI@Z
_CxxThrowException
??0exception@std@@QAE@ABV01@@Z
__CxxFrameHandler3
sprintf
vsprintf_s
exit
free
realloc
malloc
atoi
??_V@YAXPAX@Z
rand
strncpy
_stricmp
memchr
MSVCR100.dll
_amsg_exit
__getmainargs
_cexit
_exit
_XcptFilter
_ismbblead
_acmdln
_initterm
_initterm_e
_configthreadlocale
__setusermatherr
_commode
_fmode
__set_app_type
?terminate@@YAXXZ
?_type_info_dtor_internal_method@type_info@@QAEXXZ
_crt_debugger_hook
_unlock
__dllonexit
_lock
_onexit
_except_handler4_common
_invoke_watson
_controlfp_s
InternetReadFile
InternetCloseHandle
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
InternetConnectA
InternetOpenA
WININET.dll
URLDownloadToFileA
urlmon.dll
InterlockedExchange
InterlockedCompareExchange
HeapSetInformation
GetStartupInfoW
EncodePointer
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
DecodePointer
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXX
PADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
051P1Y1
4V4h4
4"50666
7#7)7
81979
:f;l;
50Z0u0&151
757H7
8F8X8x8
98:L:S:
<&<4<E<{<
> >V>g>
?'?g?o?v?
0%0-0b0j0u0
1B1h1n1u1
2%2C2b2x2
3"3,3G3O3Z3r3
6"7Q8
:&;6;
<f=x=
2O5T5_5
5V:e:M<W<
>V>f>}>
?(?@?L?f?k?v?
1j2p2
9%9[9z9
;2;9;^;
;!<6<N<V<^<
=F>V>
>V?h?
101<1f1$2=2
3&484Y4_4F5X5
6,616<6Q6V6a6
7?7U7v7
9%9K9U9m9z9
;V<m<
>9>K>R>Z>x>
>1?7?A?P?V?^?f?
[0c0k0
151A1O1V1d1s1
1F2X2
2A3[3
314@4H4t4
4?5J5R5k5
6(6@6S6z6
7f8u8
8&939D9l9
9Z:d:x:
:D;Y;a;i;
</<?<
>f>n>
?'?I?Q?\?z?
0I0u0
1'121M1^1f1q1
3J3V3
4$4*404@4F4L4R4X4a4k4r4x4}4
5*54595>5`5e5n5s5
6$6O6W6`6f6n6z6
7+767K7
8!8'8-838:8A8H8O8V8]8d8l8t8|8
9R9X9b9i9t9z9
9":':H:M:l:
;=;Q;W;
;;<@<
="=(=.=4=:=@=F=L=b=
>P?}?
20k0
1D1}1
122R2
2x:|:
:0;4;D;H;L;T;l;p;
=$=H=\=d=p=
><>\>d>l>t>|>
?$?D?L?T?\?h?
0,080@0X0`0l0
1,1L1T1\1d1p1
2$202P2X2`2l2
383D3d3p3
44484T4X4x4
0 0$0(0,0H0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1P1T1X1\1`1d1h1l1p1t1x1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2

Unicode Strings:
---------------------------------------------------------------------------
jjjjjjj
jjjjjjj
jjjj