About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Monday, August 12, 2013

Citadel 1.3.5.1 strings - CRIME (1)

File: Citadel1.3.5.1_439333E63DD1DCA5C23653BDBD740CFC
MD5:  439333e63dd1dca5c23653bdbd740cfc
Size: 245568






Ascii Strings:
---------------------------------------------------------------------------
!This program cannot be run in DOS mode.
Rich
UPX0
UPX1
.rsrc
3.09
UPX!
SVB^|-------------------------snip
FlushFiPBuffer
s",Re
TM<i
ToWi.
dDha(Is
l Pag3l{
RtlUnw
mTim
kurren
m_I[:ck
Qu,yP
YnF-SI
kedM
E,oo
aaLB^
CZse
Addr
7RLi
puP`f
.X/Ttup-<Te6*lE3\:e
wdEx pm`
djbu4
25f.5
9Nam
EnwE
mve+
&Dlg>
}sny?
ipbo
f5Rr
_2ID9
Ava,abBs
{]KA
Oq]$8d1d
um}+
`\QwSh.Z
+V`F
c_{z
Q8i-=
Djog
~gSc
148Nd
@.M\R
srcN
XPTPSW
|||"
sss`fff
999M
urr=
MML'
OIHH|fcc
onn(
onn8
onnK
onnY
onnf
onnr
onn}
)===
bbcE
Bvxv{|~~
ljm{kopvopoxbdc
~~|g
-nnn
555P
*jkl
&&&Z
@@@~
777]ddd
W###
,,,R
]]^y
\www
;<<+
EAAAr...
tuvT
d!!!h
lKKL
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>PA
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
USER32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
StartTraceA
PrintDlgA
SetFocus
eU-1#{
(e-nrtG
' 6B
_|{]{
*W"g
-----------------snip

Unicode Strings:
---------------------------------------------------------------------------
VS_VERSION_INFO
StringFileInfo
042604b0
CompanyName
DocuSign Software LLC
FileDescription
BDE UI Launcher
FileVersion
5.2.4.7
InternalName
bdeui
LegalCopyright
Copyright (C) 2005-2013 - DocuSign Software LLC
OriginalFilename
bdeui
ProductName
BDE UI Launcher
ProductVersion
5.2.4.7
VarFileInfo
Translation