Mal...where?

Fighting the Global War on Malicious Code

Interesting Rootkit

Found an interesting piece of malware on a victim's laptop -- the rootkit killed GMER when I first tried to run it, but renaming the executable was enough to trick it. The file's (random) name is "brazhmqltx.exe", found in C:\Windows\system32.

Size: 275,968 bytes (276KB)
MD5: 909b3f5072ec3228b9d596d3bb5cb22e
SHA1: da799a12ae69a2d00e026e54291d54ccac4504fc
Packers: PecBundle, PECompact

Detection is almost nonexistent as of right now on VirusTotal:

AntiVir7.3.0.2101.18.2007no virus found
Authentium4.93.801.17.2007no virus found
Avast4.7.936.001.17.2007no virus found
AVG38601.18.2007no virus found
BitDefender7.201.18.2007no virus found
CAT-QuickHeal9.0001.17.2007(Suspicious) - DNAScan
ClamAVdevel-2006042601.18.2007no virus found
DrWeb4.3301.18.2007no virus found
eSafe7.0.14.001.18.2007no virus found
eTrust-InoculateIT23.73.11601.18.2007no virus found
eTrust-Vet30.3.333401.18.2007no virus found
Ewido4.001.17.2007no virus found
Fortinet2.82.0.001.18.2007no virus found
F-Prot3.16f01.17.2007no virus found
F-Prot44.2.1.2901.17.2007no virus found
IkarusT3.1.0.2701.09.2007no virus found
Kaspersky4.0.2.2401.18.2007no virus found
McAfee494101.17.2007no virus found
Microsoft1.190401.18.2007no virus found
NOD32v2198801.18.2007no virus found
Norman5.80.0201.18.2007no virus found
Panda9.0.0.401.17.2007Adware/NaviPromo
Prevx1V201.18.2007no virus found
Sophos4.13.001.17.2007no virus found
Sunbelt2.2.907.001.12.2007VIPRE.Suspicious
TheHacker6.0.3.14901.18.2007no virus found
UNA1.8301.17.2007no virus found
VBA323.11.201.18.2007no virus found
VirusBuster4.3.19:901.18.2007no virus found

I'm going to attempt a bit more analysis this afternoon -- I'm curious as to just what this is. (The computer seemed clean otherwise).

~ Nexus7

Labels: ,

posted by David @ 7:59 AM,

0 Comments:

Post a Comment

<< Home


Web This Blog

About me

    I'm David From Atlanta, Georgia, United States -- I'm a Computer Science undergrad at Emory University seeking to go into Network Security after grad school. More than that, I am a follower of Christ and a Christian, living the Journey and learning from others who are doing the same. My family and home rest in Fredericksburg, VA.
    My profile

Archives

Previous Posts

Helpful Sites

Favorite Forums

Favorite Blogs

Powered By

Powered by Blogger>