About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Saturday, August 10, 2013

Beebone Downloader strings - CRIME

File: Beebone_Downloader_8C1AF0A0D20FF98D33C31C24D8967E4F
MD5:  8c1af0a0d20ff98d33c31c24d8967e4f
Size: 32768





Ascii Strings:
---------------------------------------------------------------------------
!This program cannot be run in DOS mode.
Rich
.text
`.rdata
@.data
.rsrc
SHELL32.DLL
MSVBVM60.DLL
-C000-sbvkvc
I7rO
MDIForm1
MDIForm1
MDIForm1
VB5!6&*
erxoo
yyoyg
znieb
sbvkvc
,\]H
yomgtbtph.ocx
yomgtbtph.orfkeigq
orfkeigq
oncz
Form1
MDIForm1
sbvkvc
VBA6.DLL
orfkeigq2
MSVBVM60.DLL
SHELL32
SHBrowseForFolder
Form
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
1orfkeigq1
IC:\Windows\System32\yomgtbtph.oca
yomgtbtph
br$4oE.
|bTx
!s25S
----------------------------------------------------snip
1i`i
:&9P#l
!PX8
Timer1
Timer2
Timer3
List4
List3
List2
List1
MDIForm
Nuy[
Form1
Form1
Form1
orfkeigq2
yomgtbtph.orfkeigq
List4
List3
List2
List1
Timer3
Timer2
Timer1
orfkeigq1
yomgtbtph.orfkeigq
znieb
`j0^d
h;:s
6swG8s
5*s3
MSVBVM60.DLL
SHELL32.DLL
SHBrowseForFolder
MethCallEngine
EVENT_SINK_AddRef
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
1u

Unicode Strings:
---------------------------------------------------------------------------
_extentx
_extenty
_extentx
_extenty
@(p<0
VS_VERSION_INFO
VarFileIifo
Translation
StringFileInfo
040904B0
LegalCopyright
javlykg
LegalTrademarks
ptwawce
ProductName
yyoyg
FileVersion
3.85
ProductVersion
3.85
InternalName
erxoo
OriginalFilename
erxoo.exe