Minotaur Malware Analysis Blog

Malware

Tutorial on Buffer Overflows and MetaSploit

by on Jul.26, 2012, under Learning, Malware

Here is a 1 hour youtube video explaining step-by-step the process of finding and exploiting buffer overflow vulnerabilities, how to exploit them, and finally how to write a metasploit module for it. Click Here.

Leave a Comment more...

Rootkit Course on Youtube

by on Jul.26, 2012, under Learning, Malware

I came across a great video series on rootkits today. The course is from opensecuritytraining.info and the link to the course details including download of the course materials is here.

The videos are here:

Leave a Comment more...

Fling.com showing up in backchannel analysis

by on May.28, 2012, under Malware

 

 

A recent sample [edit] was found using fling.com during backchannel communications. After searching for similar samples, several samples have been found to be exhibiting this behavior. The spreadsheet of these samples can be found here and all hashes can be looked up on minotauranalysis.com for the full report details. Nearly 70 samples have matched and this activity has been observed since december of last year.

 

MD5 Date
09134d24b14f1fcb6f3964ea94ff51d9 12/20/11 8:54
0e88ff5ef24b5c24528b07d11bb1a04a 12/20/11 11:00
2cea90c67c7b518b16394eafb2159ecf 12/30/11 11:08
8048d065f8e12d6cda926974d6e6a459 12/31/11 9:09
c89330f8982e356a8fe7c6ed4bbbbc35 1/1/12 17:03
4779ad6cbee6c8750112510d7def2a09 1/1/12 20:05
72ae9e9bed3f0cd2cdb4160c4f2959d7 1/5/12 6:01
259e2ccb8d3bfa1da9021974f9108d04 1/8/12 1:35
ae422757ea60786826c8da21f9436d8d 1/9/12 14:57
fd7608cb6a6f04fb6931faa3aa0aaa3d 1/13/12 1:22
c27e7449779c75aa2ce56cf09851fbbb 1/13/12 3:50
7e7462bb89cb6cf0dbe3dd024b2e79e9 1/13/12 5:15
aae40711b078afaa31cfe088bb291045 1/15/12 7:16
861d3caba86d3552ca73f55edce2deea 1/19/12 11:30
2b59d6d208893f92f14554ae2a05a6b0 1/19/12 22:09
5d9bbd66af580031a78ecfffe8620adc 1/22/12 0:58
8414a2a7675294ab209c76e251bdc3d3 1/22/12 16:08
398f51ece840741958ac955756d1899e 1/30/12 5:48
dfa41ed72f7a8d4a373ccffbe6361e5d 1/31/12 1:12
ce14ae14aca5c20c7c2120944d709c4b 1/31/12 11:25
765e7c536aaca5b29228227b7e4c0c54 2/1/12 5:20
9883987c12b185635e879ee7a779f13e 2/3/12 3:08
1c0c0fa53e8b939a291a50e26a37564e 2/7/12 1:38
f1d115d8b127322c1508d3c8c3ee1c7c 2/7/12 5:20
49430556598255cd3a19830d30f38380 2/8/12 5:11
08f3778cc7a755e0091b2def73b5da56 2/10/12 12:53
78f68bea2d037bcdfe8aa4330433469d 2/10/12 15:00
5bf6981fc79f42865ff6fde5bb3d7b5c 2/10/12 21:57
d6ec11231cb035674c0d1f98fcf84db2 2/11/12 9:13
f5dd565288e19c6125f15ed05a46f43f 2/12/12 5:13
03067c03b5d82282546ff7b7f090cceb 2/14/12 4:17
6fcb0243df7c93c70e7eb22a1e54ec88 2/14/12 4:21
25def968c95c7e29638c839036932c2a 2/14/12 4:24
77ff7a59f4880eb41d43d7853b9698d1 2/22/12 23:38
d3c8fc6a10b29b1e88fd941d68cec622 2/28/12 3:21
d623b4f803018a4a8c14ff8758297f4e 2/29/12 5:09
c9add47cd8008e9706e2fd2b3ab9613f 3/3/12 11:10
ba74b47729ad7a83038613894bc809fd 3/4/12 6:33
63fe01015f4ceb19c9b64ad0bccc723b 3/6/12 7:11
cf226658e441d6f3ea1de104b389bfdf 3/9/12 2:55
9674c4fe3167c97db765424d59420bfa 3/10/12 7:17
35034e3855eca713b657311e1218e008 3/31/12 0:09
0d3864ad40a03d360c6d8cd3d576683e 4/5/12 3:11
ae051cfdb9edf6fc5fb2338989cf8c83 4/7/12 13:10
0cef31032aacef7dd36914774754b2f8 4/10/12 3:06
48aee4f235d2bd4c91af55bb416888c8 4/12/12 3:12
7f40f0858f7973eb92070b6a06c55ce1 4/16/12 19:08
4456d87c8537b8f3a48b7e89f28079b2 4/17/12 2:25
33184d0750809ba937276755dd929a06 4/19/12 13:05
805bfda33f106a2b78af306f5cd01a14 4/26/12 18:32
fde386f0018d598b726a00bdec63f7d2 4/30/12 5:21
2efe003b8969fa946f194333152f334c 5/3/12 5:19
32105ea0c50fce1288ffabac627347eb 5/4/12 5:16
0f46910399be9f698a2f268e30e1c013 5/5/12 7:58
52f6676242ad7776f212e652521cc6a3 5/7/12 5:20
1ea9c0ea0563f7681e6f6519f070f079 5/8/12 12:48
d7adb0d77d68f63f2e5f7b9ef7f6c910 5/9/12 3:32
d5f55b06604876cffd57800521b01e7f 5/9/12 3:36
73798e48b4a1cdbb172bfd55c1f75f85 5/10/12 5:05
d2b5b038bf3a6b74836a804ed5b71021 5/10/12 9:28
d2b5b038bf3a6b74836a804ed5b71021 5/10/12 9:28
d2b5b038bf3a6b74836a804ed5b71021 5/10/12 9:28
d2b5b038bf3a6b74836a804ed5b71021 5/10/12 9:28
40646f36fe5551b18f86e945a11d2f36 5/11/12 5:07
84faae1c3336fb44b116d4f47bef141f 5/11/12 17:24
91badc3df93645b303a381abcb0ca94d 5/12/12 13:16
2a1f784dfdad6744936f610c2a852320 5/22/12 7:25
384c85018a3e3d072e02ace8fdb8b50c 5/25/12 11:52
00bed5b0e24bde1138f571d586809174 5/28/12 11:15
c71d6136d7549559ebddf65a48dd6a06 5/28/12 11:24
3a1f9e592937513387c9c1880f795757 5/28/12 17:30

UPDATE: It appears that the malware is using http://promos.fling.com/geo/txt/city.php for GeoIP capabilities. A request to that URL will return the city name of the infected computer’s IP address, and allow the malware authors to tailor ads and popups appropriately.

Leave a Comment : more...

Anti-Malware DNS System Outage

by on May.09, 2012, under Malware

We are aware that the anti-malware DNS comparison engine is offline. We are working on a new version, and if you have any DNS vendors you would like to add to our list, please email info@novcon.net. We hope to restore this service shortly.

Leave a Comment :, more...

Backchannel Tracking

by on Jul.03, 2011, under Analytics, Malware, Minotaur

Minotaur has added several new features of the last couple weeks. Most of these features have to do with backchannels. Backchannels are network communications that malware uses to “call home”. These communications can be anything from retrieving new commands and configurations to simple lookups of public information from public sources. Minotaur keeps track of all communications that take place during the execution of malware in the sandbox. It then correlates all of these communications with each other and produces a list of the top destinations of this traffic. Minotaur also produces a map of all communications that take place during the execution of the sample. Below is an example of such a map.

These capabilities are very much still a work in progress. We hope to soon provide much more information about each IP address and each communication. In the meantime we are building a database of all known back channels that Minotaur observes. The first fruits of this database can be seen in the link below.

BackChannels

Leave a Comment more...

If a picture is worth a thousand words, then…

by on Jun.22, 2011, under Analytics, Malware, Minotaur

…what’s 15,000 pictures worth?

Yup, minotaur now saves a video of each (relevant) sample processed via it’s cuckoo VMs.

What does it look like? WHy not check out a few samples with videos:

Fake AV
Hupigon

And for some old school mayhem:
Joke.Program

The system is automatically recording new samples as they come in as well as back-filling samples as it has time.

Leave a Comment more...

KIS 2012 vs NIS 2012 Beta (Video)

by on Jun.20, 2011, under Malware

Languy99 has published a video comparison of malware detection capabilities or Kaspersky 2012 vs. Norton 2012 Beta

 

Leave a Comment more...


Week-in-Malware Review

by on Apr.12, 2011, under Malware

  • Today is the record for Patch Tuesdays, with 17 bulletins and 64 vulnerabilities
Leave a Comment more...

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!