Slide 67
Slide 67 text
Title: Malware_downloader
status: Experimental
Meta
Description: ”Malicious downloader that downloads additional payload”
Author: Laura and Yagnesh
hash: AE4CA70697DF5506BC610172CFC288E7
SSDEEP: 48:a2SWLML7kulJknJmD+jtx7MBqc9xDsYjWHlJR:6Rj/kJs+jtx7MIc9xD1jWHj
strings:
$s0 = *wininet.dll*
$s1 = *CreateService*
$s2 = *InternetOpen*
$s3 = *InternetOpenURL*
$s4 = www.malwareanalysisbook.com
$s5 = Malservice
condition:
4 of ($s0, $s1, $s2 ,$s3, $s4 and $s5)
Example:
Mechanics of Malware’s Darkside