About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Saturday, August 10, 2013

Beebone Downloader strings - CRIME (2)

File: Beebone_Downloader_7F5EACBF1CACF19502260AF34ADEB8EF
MD5:  7f5eacbf1cacf19502260af34adeb8ef
Size: 32768





Ascii Strings:
---------------------------------------------------------------------------
!This program cannot be run in DOS mode.
Rich
.text
`.rdata
@.data
.rsrc
SHELL32.DLL
MSVBVM60.DLL
-C000-mvbnkf
I7rO
MDIForm1
MDIForm1
MDIForm1
VB5!6&*
goiep
hbblk
ogssc
mvbnkf
,\]H
jrkftrjki.ocx
jrkftrjki.hwtbxuad
hwtbxuad
zqnm
Form1
MDIForm1
mvbnkf
VBA6.DLL
hwtbxuad2
MSVBVM60.DLL
SHELL32
SHBrowseForFolder
Form
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
1hwtbxuad1
IC:\Windows\System32\jrkftrjki.oca
jrkftrjki
YU'W
-----------------------------snip
V:~:
YT:u
X9Q*
Timer1
Timer2
Timer3
List4
List3
List2
List1
MDIForm
Nuy[
Form1
Form1
Form1
hwtbxuad2
jrkftrjki.hwtbxuad
List4
List3
List2
List1
Timer3
Timer2
Timer1
hwtbxuad1
jrkftrjki.hwtbxuad
ogssc
`j0^d
h;:s
6swG8s
5*s3
MSVBVM60.DLL
SHELL32.DLL
SHBrowseForFolder
MethCallEngine
EVENT_SINK_AddRef
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
1u

Unicode Strings:
---------------------------------------------------------------------------
_extentx
_extenty
_extentx
_extenty
@(p<0
VS_VERSION_INFO
VarFileIifo
Translation
StringFileInfo
040904B0
LegalCopyright
xulixpe
LegalTrademarks
gqbrmek
ProductName
hbblk
FileVersion
3.85
ProductVersion
3.85
InternalName
goiep
OriginalFilename
goiep.exe