Go Back  
Reply
 
Thread Tools
Old 02-03-2012   #21
RickDangerous
Member
 
RickDangerous's Avatar
 
Join Date: Nov 2011
Posts: 82
Likes: 118
Liked 22 Times in 15 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
I just finished (!!!) bruteforcing a pup. Nothing found ofcourse, but why did it stop? I thought it was supposed to go through all 2^32 combinations?
RickDangerous is offline   Reply With Quote
Old 02-03-2012   #22
eliteforces
Member
null
 
Join Date: Nov 2010
Posts: 36
Likes: 3
Liked 9 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Be careful.

Antivirus Result Update
AhnLab-V3 - 20120203
AntiVir - 20120203
Antiy-AVL - 20120203
Avast - 20120203
AVG - 20120203
BitDefender - 20120203
ByteHero - 20120128
CAT-QuickHeal - 20120203
ClamAV Trojan.Bredolab-993 20120203
Commtouch - 20120203
Comodo - 20120203
DrWeb - 20120203
Emsisoft - 20120203
eSafe - 20120202
eTrust-Vet - 20120203
F-Prot - 20120201
F-Secure - 20120203
Fortinet - 20120203
GData - 20120203
Ikarus - 20120203
Jiangmin - 20120203
K7AntiVirus - 20120203
Kaspersky - 20120203
McAfee - 20120203
McAfee-GW-Edition - 20120203
Microsoft - 20120203
NOD32 - 20120203
Norman W32/Bredolab.B!genr 20120203
nProtect - 20120203
Panda - 20120203
PCTools - 20120201
Prevx - 20120203
Rising - 20120118
Sophos - 20120203
SUPERAntiSpyware - 20120203
Symantec - 20120203
TheHacker - 20120203
TrendMicro - 20120203
TrendMicro-HouseCall - 20120203
VBA32 - 20120203
VIPRE - 20120203
ViRobot - 20120203
VirusBuster - 20120203

Trojan.Bredolab is a Trojan horse that downloads and executes files from the Internet. It may arrive on the computer through email or a drive-by download. The Trojan also attempts to avoid detection by employing several evasion techniques.


Infection
Bredolab has been observed using the following two primary methods of distribution:
Drive-by download
Email


A drive-by-download may occur when a user visits a website that has been rigged to contain an exploit. The exploit causes malware to be downloaded on to the user's computer without his or her consent.

The email distribution method employs social engineering tricks to convince the user to open the attachment in the email. All of the emails are crafted in such a way as to appear as legitimate as possible in order to deceive the user. It is also common for the threat to reuse themes but with slight variations on the body of the message and the attachment names. For example, these themes have already been observed:

Western Union free money
UPS delivery failures
Shop.corsair.com shipping confirmations
Facebook password changes


Functionality
The primary function of this threat is to download more malware on to the compromised computer. It is likely that the authors of the threat are associated with affiliate schemes that are attempting to generate money through the distribution of malware. The threat may also be used to help construct a bot network that can be sold or hired for monetary gain.


Self-protection
It also employs the following techniques in order to avoid detection:
Server-side polymorphism - the threat constantly changes its method of packing and its appearance in order to avoid detection
Anti-debugging tricks - the threat performs checks to determine whether it is executing within a debugging environment
Encoded communication - all communication between the threat and the remote server uses encryption

Last edited by eliteforces; 02-03-2012 at 01:09 PM.
eliteforces is offline   Reply With Quote
Likes: (1)
Old 02-03-2012   #23
RickDangerous
Member
 
RickDangerous's Avatar
 
Join Date: Nov 2011
Posts: 82
Likes: 118
Liked 22 Times in 15 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Thanks for the heads up, eliteforces. I always run untrusted programs in VMware
RickDangerous is offline   Reply With Quote
Old 02-03-2012   #24
denero1
Member
 
denero1's Avatar
 
Join Date: Jun 2009
Posts: 601
Likes: 511
Liked 144 Times in 84 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
i woulda thought

Originally Posted by eliteforces View Post
Be careful.
so the 15 post and 2012 join date didnt give him away >.>

beware the newbie with the miracle fix lol
denero1 is offline   Reply With Quote
Old 02-03-2012   #25
RickDangerous
Member
 
RickDangerous's Avatar
 
Join Date: Nov 2011
Posts: 82
Likes: 118
Liked 22 Times in 15 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
The author has released a new version if anyone is interested:
http://www.mediafire.com/?nrd42kofpwt8dk7
Edit: link fixed

Last edited by RickDangerous; 02-03-2012 at 01:38 PM.
RickDangerous is offline   Reply With Quote
Old 02-03-2012   #26
Nateblitz16
Member
 
Nateblitz16's Avatar
 
Join Date: Jan 2012
Posts: 192
Likes: 132
Liked 64 Times in 43 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
Originally Posted by denero1 View Post
so the 15 post and 2012 join date didnt give him away >.>

beware the newbie with the miracle fix lol
shut up woody lol >.>

Last edited by Nateblitz16; 02-03-2012 at 02:10 PM.
Nateblitz16 is offline   Reply With Quote
Likes: (1)
Old 02-03-2012   #27
enosrasun
Member
 
enosrasun's Avatar
 
Join Date: Nov 2009
Posts: 190
Likes: 27
Liked 88 Times in 57 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
I think this app work,I have scan some files from 4.00 unpacked pup and on some of them stop an show another window but blank
enosrasun is offline   Reply With Quote
Old 02-03-2012   #28
reptor
Apprentice
 
Join Date: Jan 2011
Posts: 6
Likes: 2
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
I'm getting the same outcome. A small blank window pops up.
reptor is offline   Reply With Quote
Old 02-03-2012   #29
Toufik
Apprentice
 
Toufik's Avatar
 
Join Date: Jan 2012
Posts: 18
Likes: 6
Liked 3 Times in 2 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
OMG I HAVE KEYS !!!!



... --'
Toufik is offline   Reply With Quote
Old 02-03-2012   #30
mrc1978
 
mrc1978's Avatar
 
Join Date: Jan 2011
Location: Bradford(West Yorks), Born and Bred
Posts: 1,957
Likes: 392
Liked 955 Times in 617 Posts
Mentioned: 243 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Toufik View Post
OMG I HAVE KEYS !!!!



... --'
I have a penis, so its all good
mrc1978 is online now   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 02:07 AM.