Skip to main content

Posts

Showing posts with the label blackpos

Dump Memory Grabber BlackPOS Win32 Pocardler A

Dump Memory Grabber BlackPOS Win32 Pocardler A Having a look on another POS malware named by AV guys BlackPOS: MD5: cbd268e260bf40c25f1bff8b85e04e01 The original exe is packed with UPX and have a size of (292 Kb) After unpacking the exe size is 754 Kb and the Time/Date Stamp: 512A2914 (24-02-2013 - 14:52:04)  First seen in VirusTotal... right now This malware retrieve the path of %USERPROFILE%: At this step we can trick it like ProjectHook to display a leet GUI:  Just take the jump: Now if we dont take it, it copy the actual file to %USERPROFILE% with the name svhst.exe execute the original exe with argument /silentinstall Ive choose to NOP the line to continue without infecting my vm, and whats he do next ? The same crap but this time with argument /firewall" Re-NOPed the line and... yeah, you guessed it, still WinExec with "Netsh firewall set opmode disable" Netsh = network shell, this command will disable the Windows firewall. Then he delete the file dum.exe (???) He ...