This trojan comes as a spam email. Here are sample spam emails:
Like some CryptoLocker samples, this trojan uses a very similar decryption method. It uses VirtualAlloc to allocate memory space where it will decrypt the embedded PE Image, and then calls VirtualProtect so that it can overwrite itself with the newly decrypted PE Image and then passes the control to it.
Here's...
Monday, November 18, 2013
Sunday, November 17, 2013
CryptoLocker - a Ransomware
Posted on Sunday, November 17, 2013 by Unknown
| No comments
What is a Ransomware?
A ransomware is a malicious program that encrypts all of document, picture and movie files in a computer. And to be able to decrypt them, the user must pay the malware author for some amount of money.
CryptoLocker
This ransomware, once executed, will search for document files that it targets and encrypt them using an RSA algorithm. And the user may pay...
Thursday, November 14, 2013
DETAILED ANALYSIS OF Trojan.Win32.Duqu: The Key Logger Module
Posted on Thursday, November 14, 2013 by Unknown
| No comments

INTRODUCTION
Duqu malware is a collection of malware components that together provide services to attackers. It may arrive as a Microsoft Word (.doc) that exploits Win32k TrueType font parsing engine and allows execution.
This document will be solely focused on the key logger component of Duqu.
SUMMARY
The file in study is the info stealer/key logger component “a...
Subscribe to:
Posts (Atom)