About contagio exchange
CONTAGIO EXCHANGE
Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)
Monday, August 12, 2013
Sunday, August 11, 2013
Saturday, August 10, 2013
Monday, June 25, 2012
023 Crime OSX DNS Changer / OSX.RSPlug.A - web -2007
SHA256: 2bdcdab0a5d41f4b6aa48e2ab55177552c8419c3f8ce140c4850a0616d7a2f3e
SHA1: f620af9a43d6e46e6b028dc8b109ff5d4cced911
MD5: 5291beb71cba2c5779119bff7a10abdb
File size: 16.6 KB ( 17034 bytes )
File name: ultracodec1237.dmg
Thursday, June 7, 2012
023 Crime Downloader Trojan (name?) - web - June 7, 2012
Audio_Recording_MP3
MD5: FDC170166CB958E138E7D401F3C6F896
SHA256: A3253B1732A50146038A68B3B46260F80BEC6C1C
022 Crime Win32/Bakcorox.A - proxy bot - web - June 7, 2012
pcap file
DNS query: day7read.info
DNS response: day7read.info ⇒ 74.207.249.7
Connects to: day7read.info:443 (74.207.249.7)
Sends data to: 8.8.8.8:53
Sends data to: day7read.info:443 (74.207.249.7)
Receives data from : 8.8.8.8:53
Receives data from: day7read.info:443 (74.207.249.7)
Monday, June 4, 2012
021 Crime TDL - web - June 4, 2012
malicious domain

Download (pass infected)
xor key 85
MD5 A16977E9CCBF86168CE20DFC33E0A93C
SHA-256 05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01
https://www.virustotal.com/file/05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01/analysis
newgenerationp.com/d/u
Download (pass infected)
xor key 85
MD5 A16977E9CCBF86168CE20DFC33E0A93C
SHA-256 05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01
https://www.virustotal.com/file/05344813787920a04b207416ea05516b21958b3f6c8ad9fb8f0ce507c41efd01/analysis
Thursday, May 10, 2012
020 Crime Ramnit Rootkit - web -May, 10 2012
Research:
Download (pass infected)
Size: 135680
MD5: 607B2219FBCFBFE8E6AC9D7F3FB8D50E
Thursday, May 3, 2012
019 APT Speech.doc MacOS_X/MS09-027.A Word exploit for MS Word
Someone uploaded. Thank you for sharing.
Document language code is Arabic, which is kind of interesting.
Research: Microsoft An interesting case of Mac OSX malware
Download (pass infected)
File: speech.doc
Size: 158854
MD5: F4CBFE4F2DDF3F599984CF6D01C1B781
Document language code is Arabic, which is kind of interesting.
Research: Microsoft An interesting case of Mac OSX malware
Download (pass infected)File: speech.doc
Size: 158854
MD5: F4CBFE4F2DDF3F599984CF6D01C1B781
Sunday, April 29, 2012
018 Crime "Microsoft Update" phish -> Blackhole exploit kit with Zeus payload - web - April 2012
File: KB971033.exe
Size: 201216
MD5: EC750B75E83749C715D7834E130FCE8E
File: hnszs0.exe
Size: 184832
MD5: 9DB4174373601F74FCE0ECBC77A9577D
Sample credit Bryan Nolen
Download (pass infected)
LIST OF FILES INCLUDED
│ investigation_notes.txt
│
├───dropped_files
│ ├───exe
│ │ hnszs0.exe
│ │ KB971033.exe
│ │
│ ├───java
│ │ jar_cache.zip
│ │
│ ├───pdf
│ │ ap1.pdf
│ │ ap2.pdf
│ │
│ └───swf
│ score.swf
│
├───email
│ MSUPDATE.eml
│
├───extracted_files
│ pid_1412_Explorer_Dumped.EXE
│
├───html
│ exploit.html
│ landing.html
│
└───pcap
dump.pcap
Quick analysis made by Bryan Nolen
Landing page (hxxp://volozhin.gov.by/pub/KB971033/?clien-e=3D1093821896211 and saved as html/landing.html) contains a hidden IFRAME that leads to the exploit page. This landing page also contains a META REFRESH that leads to another suspect binary (hxxp://volozhin.gov.by/pub/KB971033/KB971033.exe saved as dropped_files/exe/KB971033.exe) - detection on this second binary is low ( https://www.virustotal.com/file/0e14f5e6cdab9218135d3a7eed11f0457c9934210859f6075d63bc609469d43b/analysis/1335596875/ )
Exploit page (hxxp://fewfewfewfew.ibiz.cc/main.php?page=95fc4549d83b0486 and saved as html/exploit.html) utilises a trio of exploits designed to attack java, adobe acrobat, or flash.
Analysis of the javascript was perfomed with the assistance of URLQUERY report link (http://urlquery.net/report.php?id=47909).
The attack payloads are saved as
The "final" malicious payload is saved as (dropped_files/exe/hnszs0.exe) and its detection is VERY poor ( https://www.virustotal.com/file/c48df0394939fccb9a3ac0853d0ae696d04e7c5230d3a6468ebce257a0be4ccc/analysis/1335598639/ )
A copy of explorer.exe extracted from the memory image after infection is included, based on observations this is the process it migrated into after infection. It is saved in (extracted_files/pid_1412_Explorer_Dumped.EXE)
PCAP is supplied in the pcap folder. The hosts identified in this malware are:
Landing Page: volozhin.gov.by 212.98.162.62
Exploit Page: fewfewfewfew.ibiz.cc 83.69.233.156
C2: google-analytics-sv1.com 91.230.147.222
(alt C2): localdomain01.com 91.230.147.145
Note: the Alternate C2 was seen in earlier investigations of this malware and changed to the C2 address above when this round of investigation was performed.
Full memory dumps from my sandbox VM avaliable on request.
I have a strong suspicion this is a Zeus varient.
-Bryan Nolen <bryan _at_ arc .dot. net .dot. au>
@bryannolen
Size: 201216
MD5: EC750B75E83749C715D7834E130FCE8E
File: hnszs0.exe
Size: 184832
MD5: 9DB4174373601F74FCE0ECBC77A9577D
Sample credit Bryan Nolen
LIST OF FILES INCLUDED
│ investigation_notes.txt
│
├───dropped_files
│ ├───exe
│ │ hnszs0.exe
│ │ KB971033.exe
│ │
│ ├───java
│ │ jar_cache.zip
│ │
│ │ ap1.pdf
│ │ ap2.pdf
│ │
│ └───swf
│ score.swf
│
│ MSUPDATE.eml
│
├───extracted_files
│ pid_1412_Explorer_Dumped.EXE
│
├───html
│ exploit.html
│ landing.html
│
└───pcap
dump.pcap
Quick analysis made by Bryan Nolen
Landing page (hxxp://volozhin.gov.by/pub/KB971033/?clien-e=3D1093821896211 and saved as html/landing.html) contains a hidden IFRAME that leads to the exploit page. This landing page also contains a META REFRESH that leads to another suspect binary (hxxp://volozhin.gov.by/pub/KB971033/KB971033.exe saved as dropped_files/exe/KB971033.exe) - detection on this second binary is low ( https://www.virustotal.com/file/0e14f5e6cdab9218135d3a7eed11f0457c9934210859f6075d63bc609469d43b/analysis/1335596875/ )
Exploit page (hxxp://fewfewfewfew.ibiz.cc/main.php?page=95fc4549d83b0486 and saved as html/exploit.html) utilises a trio of exploits designed to attack java, adobe acrobat, or flash.
Analysis of the javascript was perfomed with the assistance of URLQUERY report link (http://urlquery.net/report.php?id=47909).
The attack payloads are saved as
- dropped_files/pdf/ap1.pdf
- dropped_files/pdf/ap2.pdf
- dropped_files/swf/score.swf
- dropped_files/java/jar_cache.zip
The "final" malicious payload is saved as (dropped_files/exe/hnszs0.exe) and its detection is VERY poor ( https://www.virustotal.com/file/c48df0394939fccb9a3ac0853d0ae696d04e7c5230d3a6468ebce257a0be4ccc/analysis/1335598639/ )
A copy of explorer.exe extracted from the memory image after infection is included, based on observations this is the process it migrated into after infection. It is saved in (extracted_files/pid_1412_Explorer_Dumped.EXE)
PCAP is supplied in the pcap folder. The hosts identified in this malware are:
Landing Page: volozhin.gov.by 212.98.162.62
Exploit Page: fewfewfewfew.ibiz.cc 83.69.233.156
C2: google-analytics-sv1.com 91.230.147.222
(alt C2): localdomain01.com 91.230.147.145
Note: the Alternate C2 was seen in earlier investigations of this malware and changed to the C2 address above when this round of investigation was performed.
Full memory dumps from my sandbox VM avaliable on request.
I have a strong suspicion this is a Zeus varient.
-Bryan Nolen <bryan _at_ arc .dot. net .dot. au>
@bryannolen
SITE TYPE
LEGITIMATE, COMPROMISED
212.98.162.62
volozhin.gov.by Belarus AS12406 Business network j.v. Business Network JV
BLACKHOLE
83.69.233.156
fewfewfewfew.ibiz.cc Russian Federation AS28762 AWAX Telecom Ltd AWAX Telecom Ltd.
PAYLOAD - ZEUS
C2
91.230.147.222
google-analytics-sv1.com Russian Federation AS57189 PE Spiridonova Vera Ana OOO Aldevir Invest
LEGITIMATE, COMPROMISED
212.98.162.62
volozhin.gov.by Belarus AS12406 Business network j.v. Business Network JV
BLACKHOLE
83.69.233.156
fewfewfewfew.ibiz.cc Russian Federation AS28762 AWAX Telecom Ltd AWAX Telecom Ltd.
PAYLOAD - ZEUS
C2
91.230.147.222
google-analytics-sv1.com Russian Federation AS57189 PE Spiridonova Vera Ana OOO Aldevir Invest
C2
91.230.147.145
91.230.147.145
localdomain01.com Russian Federation AS57189 PE Spiridonova Vera Ana OOO Aldevir Invest
Wednesday, April 4, 2012
014 - Crime - Sinowal Mebroot Torpig -rootkit-trojan - Web - Feb-Mar 2012
MD5: 13CE4CD747E450A129D900E842315328
MD5: C2BB7A8316EF7A106E6A3B3BB8D5532A
MD5: CBE853D5D7EC089EF0302789284D6C44
MD5: E16261185C13FB16213288A3860C1B8D
Download 014_Crime_Sinowal-Mebroot-Torpig.zip (Email me if you need the pass)
MD5: C2BB7A8316EF7A106E6A3B3BB8D5532A
MD5: CBE853D5D7EC089EF0302789284D6C44
MD5: E16261185C13FB16213288A3860C1B8D
Subscribe to:
Posts (Atom)