About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Monday, August 12, 2013

Taleret strings - APT (2)

File: Taleret_5328CFCB46EF18ECF7BA0D21A7ADC02C
MD5:  5328cfcb46ef18ecf7ba0d21a7adc02c
Size: 126976




Taleret strings - APT (1)

File: Taleret_FED166A667AB9CBB1EF6331B8E9D7894
MD5:  fed166a667ab9cbb1ef6331b8e9d7894
Size: 36864

Ascii Strings:


Sunday, August 11, 2013

Alina POS v.5.6 strings - CRIME

File: Alinav5.6-POS_5A22ED78B6454E34217D07C4AF37B23B
MD5:  5a22ed78b6454e34217d07c4af37b23b
Size: 167936




Saturday, August 10, 2013

Alina POS v.5.3 strings -CRIME

robohash
File: Alina-POS_
4C754150639AA3A86CA4D6B6342820BE
MD5:  4c754150639aa3a86ca4d6b6342820be
Size: 48128

Ascii Strings:


BunituB-Proxy strings - CRIME (3)

robohash

File: BunituB-Proxy_BC22DE23FB07EE9E3C02DD1D2B3E52B3
MD5:  bc22de23fb07ee9e3c02dd1d2b3e52b3
Size: 73728




BunituB-Proxy strings - CRIME (2)

robohash
File: BunituB-Proxy_B64D221166E494AC00251594304BE072
MD5:  b64d221166e494ac00251594304be072
Size: 15872




BunituB-Proxy strings - CRIME

File: BunituB-Proxy_A725B21C1F9D24ADA97564F3F152CF50
MD5:  a725b21c1f9d24ada97564f3f152cf50
Size: 16896



Blazebot strings - CRIME

File: Blazebot_DBAF6F1D0EAAB5DC0C88B9CEEC9EA95E.exe_
MD5:  dbaf6f1d0eaab5dc0c88b9ceec9ea95e
Size: 251957



Bladabindi strings - CRIME

File: fe3e87a746bbf71268a35dfc43a6396d1ef3a92e33b99e1350317183edb66da6
MD5:  82f0aeb7ce7c448b763055a10726ed7b
Size: 28672



Bitcoinminer strings - CRIME

File: Bitcoinminer_F865C199024105A2FFDF5FA98F391D74_syu.exe_
MD5:  f865c199024105a2ffdf5fa98f391d74
Size: 589798



Beebone Downloader strings - CRIME (2)

File: Beebone_Downloader_7F5EACBF1CACF19502260AF34ADEB8EF
MD5:  7f5eacbf1cacf19502260af34adeb8ef
Size: 32768



Beebone Downloader strings - CRIME

File: Beebone_Downloader_8C1AF0A0D20FF98D33C31C24D8967E4F
MD5:  8c1af0a0d20ff98d33c31c24d8967e4f
Size: 32768



Avatar Rootkit NETbotnet strings - CRIME

File: Avatar_Rootkit_NETbotnet_32d6644c5ea66e390070d3dc3401e54b_unpacked
MD5:  32d6644c5ea66e390070d3dc3401e54b
Size: 129024



Ardamax Keylogger strings - CRIME

File: ArdamaxKeylogger_E33AF9E602CBB7AC3634C2608150DD18
MD5:  e33af9e602cbb7ac3634c2608150dd18
Size: 802724



ArcomRat strings - CRIME

File: Arcomrat_4015DD5B27EB612CA5DC320033E284C5
MD5:  4015dd5b27eb612ca5dc320033e284c5
Size: 1024960



Andromeda Bot strings - CRIME

File: Andromeda_85F908A5BD0ADA2D72D138E038AECC7D_DHL-LABEL-ID-2456-8344-5362-5466.exe_
MD5:  85f908a5bd0ada2d72d138e038aecc7d
Size: 57344



Pandora DDoS bot strings - CRIME

This summary is not available. Please click here to view the post.

Monday, June 25, 2012

023 Crime OSX DNS Changer / OSX.RSPlug.A - web -2007


SHA256: 2bdcdab0a5d41f4b6aa48e2ab55177552c8419c3f8ce140c4850a0616d7a2f3e
SHA1: f620af9a43d6e46e6b028dc8b109ff5d4cced911
MD5: 5291beb71cba2c5779119bff7a10abdb
File size: 16.6 KB ( 17034 bytes )
File name: ultracodec1237.dmg



 Download (pass infected)


 

Thursday, June 7, 2012

023 Crime Downloader Trojan (name?) - web - June 7, 2012

Audio_Recording_MP3
MD5: FDC170166CB958E138E7D401F3C6F896
SHA256: A3253B1732A50146038A68B3B46260F80BEC6C1C

 Download (pass infected)

pcap file




022 Crime Win32/Bakcorox.A - proxy bot - web - June 7, 2012

 Download (pass infected)


pcap file



DNS query:  day7read.info
DNS response:  day7read.info ⇒ 74.207.249.7
Connects to:  day7read.info:443 (74.207.249.7)
Sends data to:  8.8.8.8:53
Sends data to:  day7read.info:443 (74.207.249.7)
Receives data from :  8.8.8.8:53
Receives data from:  day7read.info:443 (74.207.249.7)
 

Monday, June 4, 2012

021 Crime TDL - web - June 4, 2012

malicious domain
newgenerationp.com/d/u


 
Download (pass infected)

xor key 85 
MD5  A16977E9CCBF86168CE20DFC33E0A93C
SHA-256 05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01


https://www.virustotal.com/file/05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01/analysis

Thursday, May 10, 2012

020 Crime Ramnit Rootkit - web -May, 10 2012

Sample credit - Artem Baranov and Hendrik Adrian

Research:

 
Download (pass infected)


Size: 135680
MD5:  607B2219FBCFBFE8E6AC9D7F3FB8D50E

Thursday, May 3, 2012

019 APT Speech.doc MacOS_X/MS09-027.A Word exploit for MS Word

Someone uploaded. Thank you for sharing.
Document language code is Arabic, which is kind of interesting.

Research: Microsoft An interesting case of Mac OSX malware


 Download (pass infected)

File: speech.doc
Size: 158854
MD5:  F4CBFE4F2DDF3F599984CF6D01C1B781


Sunday, April 29, 2012

018 Crime "Microsoft Update" phish -> Blackhole exploit kit with Zeus payload - web - April 2012

File: KB971033.exe
Size: 201216
MD5:  EC750B75E83749C715D7834E130FCE8E

File: hnszs0.exe
Size: 184832
MD5:  9DB4174373601F74FCE0ECBC77A9577D

Sample credit Bryan Nolen

Download (pass infected)


LIST OF FILES INCLUDED
│   investigation_notes.txt

├───dropped_files
│   ├───exe
│   │       hnszs0.exe
│   │       KB971033.exe
│   │
│   ├───java
│   │       jar_cache.zip
│   │
│   ├───pdf
│   │       ap1.pdf
│   │       ap2.pdf
│   │
│   └───swf
│           score.swf

├───email
│       MSUPDATE.eml

├───extracted_files
│       pid_1412_Explorer_Dumped.EXE

├───html
│       exploit.html
│       landing.html

└───pcap
        dump.pcap



Quick analysis made by Bryan Nolen

Landing page (hxxp://volozhin.gov.by/pub/KB971033/?clien-e=3D1093821896211 and saved as html/landing.html) contains a hidden IFRAME that leads to the exploit page. This landing page also contains a META REFRESH that leads to another suspect binary (hxxp://volozhin.gov.by/pub/KB971033/KB971033.exe saved as dropped_files/exe/KB971033.exe) - detection on this second binary is low ( https://www.virustotal.com/file/0e14f5e6cdab9218135d3a7eed11f0457c9934210859f6075d63bc609469d43b/analysis/1335596875/ )

Exploit page (hxxp://fewfewfewfew.ibiz.cc/main.php?page=95fc4549d83b0486 and saved as html/exploit.html) utilises a trio of exploits designed to attack java, adobe acrobat, or flash.

Analysis of the javascript was perfomed with the assistance of URLQUERY report link (http://urlquery.net/report.php?id=47909).

The attack payloads are saved as
  • dropped_files/pdf/ap1.pdf 
  • dropped_files/pdf/ap2.pdf 
  • dropped_files/swf/score.swf 
  • dropped_files/java/jar_cache.zip

The "final" malicious payload is saved as (dropped_files/exe/hnszs0.exe) and its detection is VERY poor ( https://www.virustotal.com/file/c48df0394939fccb9a3ac0853d0ae696d04e7c5230d3a6468ebce257a0be4ccc/analysis/1335598639/ )

A copy of explorer.exe extracted from the memory image after infection is included, based on observations this is the process it migrated into after infection. It is saved in (extracted_files/pid_1412_Explorer_Dumped.EXE)

PCAP is supplied in the pcap folder. The hosts identified in this malware are:

Landing Page:    volozhin.gov.by         212.98.162.62
Exploit Page:    fewfewfewfew.ibiz.cc         83.69.233.156
C2:        google-analytics-sv1.com     91.230.147.222
(alt C2):    localdomain01.com         91.230.147.145

Note: the Alternate C2 was seen in earlier investigations of this malware and changed to the C2 address above when this round of investigation was performed.

Full memory dumps from my sandbox VM avaliable on request.

I have a strong suspicion this is a Zeus varient.


-Bryan Nolen <bryan _at_ arc .dot. net .dot. au>
@bryannolen

SITE TYPE
LEGITIMATE, COMPROMISED   
212.98.162.62
volozhin.gov.by
    Belarus    AS12406 Business network j.v.    Business Network JV
                       
BLACKHOLE    
83.69.233.156
fewfewfewfew.ibiz.cc 
   Russian Federation    AS28762 AWAX Telecom Ltd    AWAX Telecom Ltd.

PAYLOAD - ZEUS   
C2
91.230.147.222
google-analytics-sv1.com
Russian Federation    AS57189 PE Spiridonova Vera Ana    OOO Aldevir Invest
 
C2
91.230.147.145
localdomain01.com Russian Federation    AS57189 PE Spiridonova Vera Ana    OOO Aldevir Invest





Wednesday, April 4, 2012