A Form-grabber malware who claim to grab anything, and with no dependencies.
It work with lastest version of Firefox, Chrome, Internet Explorer and Opera.
Advert:
Copy the file/Execute the copy:
Registry persistence:
Drop a dll from ressource:
Looking for browser process:
Inject:
Firefox injected:
(Congratulation, your browser is owned)
An interesting part of strings found inside the dll:
Doing an attempt to sign in on the VirusTotal.com service:
(Here, the injected dll compare if it's a POST request)
Malware call home procedure:
Before calling the gate it verify if the host is already decrypted, if no it decrypt the host.
(The coder of MP-Formgrabber have added a method to avoid leaks with hexed bins but look's like he have never heard of code-cave)
Retake an hardcoded strings from resource:
Host decyphered:
Encode grabbed datas and call the gate:
"gate.php" server side
The malware panel, login:
Logs:
Rules settings to parse logs:
Grabbed infos parsed:
This form-grabber was fun to reverse, anyway dont take this as a game, malware can always ruin your life in two clicks.
If you are looking for an exe of MP-FormGrabber and additional access to my panel for research purpose, feel free to contact me.
Showing posts with label Opera. Show all posts
Showing posts with label Opera. Show all posts
Monday, 6 August 2012
Thursday, 10 March 2011
HoaxSMS Fake installers (Opera / WinRAR 2011)
Opera Hoax: 9557c35b1d02fb27cb5646d945c66103
Opera can be downloaded for free here: http://www.opera.com/
-------------------------------------
WinRAR 2011: 64c67472ce9b61910278e2d9cdb66278
-------------------------------------
WinRAR 2011: 7dd1f1909edf70276dfc77326480b431
Winrar can be downloaded for free here: http://www.rarlab.com/
----
Hoax SMS in the past:
Subscribe to:
Posts (Atom)















