Tuesday 11 December 2012

Web Crab formgrabber

And to finish my hackforum tour for the day...
Advert:

9Kb with UPX:

Looking for process:

Open process:

WriteProcess:


And CreateRemoteThread. (the first time i run the malware made Firefox crashed, second time it worked)
So let's debug Firefox...


when i try to log in on virustotal:

POST req are intercepted:

Data are enc and send to the panel (here it's localhost/development/panel.php)

If you look for the sample...
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=2234

5 comments:

  1. In my opinion it's not even worth to reverse hackforums malawares,most of them are copy /paste and made from ripped sources.

    and they doesn't work as they are advertised.

    Why waste time Xyli bro in such low shit.

    thanks

    ReplyDelete
  2. looks like is a rip of this http://pastebin.com/MPeEhGLy

    coder made another formgrabber before and code was 1:1 match lol

    even this public pastbin code is ripped and broken but this formgrabber "coder" obviously cant see that

    ReplyDelete
    Replies
    1. Even the coder himself have said he's using injection code ripped from Zeus.

      Delete
  3. What else can we expect from HF skid's,kid's,script kiddy and more importantly Copy/paster's and rippers.

    ReplyDelete
  4. i'm interested in the rip of this

    ReplyDelete