And to finish my hackforum tour for the day...
Advert:
9Kb with UPX:
Looking for process:
Open process:
WriteProcess:
And CreateRemoteThread. (the first time i run the malware made Firefox crashed, second time it worked)
So let's debug Firefox...
when i try to log in on virustotal:
POST req are intercepted:
Data are enc and send to the panel (here it's localhost/development/panel.php)
If you look for the sample...
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=2234
Showing posts with label formgrabber. Show all posts
Showing posts with label formgrabber. Show all posts
Tuesday, 11 December 2012
Monday, 6 August 2012
MP-FormGrabber
A Form-grabber malware who claim to grab anything, and with no dependencies.
It work with lastest version of Firefox, Chrome, Internet Explorer and Opera.
Advert:
Copy the file/Execute the copy:
Registry persistence:
Drop a dll from ressource:
Looking for browser process:
Inject:
Firefox injected:
(Congratulation, your browser is owned)
An interesting part of strings found inside the dll:
Doing an attempt to sign in on the VirusTotal.com service:
(Here, the injected dll compare if it's a POST request)
Malware call home procedure:
Before calling the gate it verify if the host is already decrypted, if no it decrypt the host.
(The coder of MP-Formgrabber have added a method to avoid leaks with hexed bins but look's like he have never heard of code-cave)
Retake an hardcoded strings from resource:
Host decyphered:
Encode grabbed datas and call the gate:
"gate.php" server side
The malware panel, login:
Logs:
Rules settings to parse logs:
Grabbed infos parsed:
This form-grabber was fun to reverse, anyway dont take this as a game, malware can always ruin your life in two clicks.
If you are looking for an exe of MP-FormGrabber and additional access to my panel for research purpose, feel free to contact me.
It work with lastest version of Firefox, Chrome, Internet Explorer and Opera.
Advert:
Copy the file/Execute the copy:
Registry persistence:
Drop a dll from ressource:
Looking for browser process:
Inject:
Firefox injected:
(Congratulation, your browser is owned)
An interesting part of strings found inside the dll:
Doing an attempt to sign in on the VirusTotal.com service:
(Here, the injected dll compare if it's a POST request)
Malware call home procedure:
Before calling the gate it verify if the host is already decrypted, if no it decrypt the host.
(The coder of MP-Formgrabber have added a method to avoid leaks with hexed bins but look's like he have never heard of code-cave)
Retake an hardcoded strings from resource:
Host decyphered:
Encode grabbed datas and call the gate:
"gate.php" server side
The malware panel, login:
Logs:
Rules settings to parse logs:
Grabbed infos parsed:
This form-grabber was fun to reverse, anyway dont take this as a game, malware can always ruin your life in two clicks.
If you are looking for an exe of MP-FormGrabber and additional access to my panel for research purpose, feel free to contact me.
Subscribe to:
Posts (Atom)
























