Malware ist die englischsprachige Bezeichnung für Schadsoftware. Darunter versteht man sämtliche schädliche Software, wie Viren, Trojaner, Würmer, usw.. Im Rahmen der Malware-Analyse versuche ich durch Techniken des Reverse Engineering herauszufinden, was die Schadsoftware tut, von wo sie Befehle bekommt und wohin sie Daten übermittelt. Bei Erpressungs-Trojaner (sogenannter „Ransomware“) ist es mir manchmal sogar möglich, den Entschlüsselungscode aus der Schadsoftware auszulesen.
Von mir analysierte Ransomware / Screen-Locker:
Dateiname | MD5-Hashwert | Code |
1099.exe | 485293f68ea484f446d08ff25331db80 | 338744522; 9786775 |
2503326475.exe | 043ede36f50bf967680bf7a755e1d696 | WARCRAFT |
Bitcoin Adder Flash 2019.exe | 3ae257a80b57d0e05b496a7f37b02ed3 | NIEREA-NIJNB-ZBBWE-NIGKR |
Debug.exe | 6b657c89a3d1309fc3f70c2ab3e16298 | 1470unlock1470 |
f58749b7cb9dd8a84474dd4fcf2a63aadf4cf3c2.exe | 62c6fa3180bb27b6e844e76fce65c3ca | Rebatsa |
flash_player.exe | 947740d3bc01db29b14d1752e20775c7 | 28527548; 35676549 |
Locker.exe | 41ac379eaf0c42231d4fc079b75e01d4 | ve123-locker-pass! |
porno.exe | a1f5b2c60319a5e869daf331ff21f0a1 | DIGGER |
porno_rolik.exe | 618488bced20b2664b9273968c6e0a44 | 121255545 |
porno-rolik2.avi.exe | ef21928078bb4f8c12dcaa2a50b3c348 | REMOTE |
pornoplayer.exe | f95ca401906458427df0b8ef7a0f438c | STARCRAFT |
pornoplayer.exe | fe88a8050f99273b7de3ebaebd03bb33 | SHAME ON THE NIGHT |
pornoplayer.exe | b57c4b512b199d267e764423f0061072 | WE ROCK |
pornoplayer.exe | b1008f6e53ce18a68413348dddc5f593 | SORRY |
winlock.exe | b85ef14f071d8c930204d50732aaffb5 | DTLP |
wpbt0.exe | df9188698b078a38b399a8b6f61f9c34 | 9786775 |
xpiofrbtkzhr.exe | b061a3618f1c00ad0257e3f6b8a0bdc1 | DTLP |
белый.exe | daefb9e7641a4b98b44a09cc874c4fb2 | 147741; 000111 |
Von mir analysierte Schadsoftware:
Dateiname | MD5 | Host | Familie |
afasda.js | cc5831b2416f2833942c9462e63dc040 | 5.101.151.106:500 | njRAT |
attack.ps1 | 2cd64056eb975295e153837800fc261b | top.gaminjo1.pw:4908 | Remcos |
BangBros18 13 08 13 Lexxi Deep Xxx 720p Mp4-Ktr.exe | a8a51b957a834e49c4768bdbc245d71c | 91.218.36.217:80 | N0PE |
Carberp online banking trojan source code leak.exe | 8df3d56dbb2b479a9f4b1c75e4c632da | www.sayco.webege.com:80 | |
Chegeware_v1.exe | 7b8ca8cd740cd2aab99bf68Be3ba74d2 | 89.113.72.55:1605 | njRAT |
comprobante_1_18_uxl5.vbs | 8257b2cb9063afdfa0bde6c460db0e5c | ot583ot583b0gh2.myftp.biz:80 | |
CSGO Vip Hack.exe | d41c0a96a7aff7a85e2cd821110e53d3 | kanat26.duckdns.org:333 | |
devrew.exe | dad99bfe1147ad527a888b16735c6b02 | xetrodep.top | Parasite HTTP RAT |
Extrato_1564-2013.cpl | 6b32f0c6bd7b00cdd9ba4dd280bbdcbe | demandatelecom.com.br:80 | |
FaceBook HACK.exe | 5f69d673e563961ab5167602f93a6af2 | master1111.ddns.net:1177 | njRAT |
fantazy.exe | 4b670fab0e92f01d10ba51ab1f63a5bc | tayler25131.hopto.org:8082 | njRAT |
Fifa 16 Coins Generator.exe | b02aedd86749a7c2371105c242a1a171 | gamerforever.no-ip.biz:1604 | Dark Comet |
File.exe | 444deacc7609665c28e08d1cb3801dc3 | 104.248.133.59:4321 | njRAT |
Fortnite build 15-11r.exe | 063bd486debf4f5f533483fadc4c2baa | hackerman64.hopto.org:1337 | njRAT |
HackOpTool v2.exe | 7768cbad66ff0f0226f32B77ba2b9a79 | virutport.servehttp.com:1 | |
Loader Multi-Hacks.exe | 53937e0fa37ffce3f7be6b2442d35630 | itocharneca.duckdns.org:666 | njRAT |
mecrutoo.exe | 5c0a365f9152162e2662766b0beb1979 | kitchenraja.in:80 | |
New RS Hack.exe | 6bbcb3772a205c7db071c6ea5555329b | darkcomete.ddns.net:1605 | Dark Comet |
PayPal Money Adder.exe | 655b0f0f3b1c0ece79e0745cf5481e32 | salakvallamal.duckdns.org:1604 | NanoCore |
PayPal Money Generator $$.exe | ec1fd7777d192e851d03cc45ca2205df | lookk21.ddns.net:7777 | njRAT |
Server.exe | fceef34273caa6ad1b7efb928893b86b | hakim32.ddns.net:2000 | njRAT |
Spotify Accounts Checker By XSLAYER.exe | 92f293c845e526316a5d53ca05fb29a8 | team-hacker.ddns.net:5656 | |
Skype.exe | 99c83eac5ec48e9311f5bd6d48b84d3d | 786110lala.zapto.org:1111 | njRAT |
START.exe | 76d1b0ffa9dc694c6fdc8e93f86a3350 | j1030440.myjino.ru | |
Startupdate.exe | 0136f46d75a56a2b3dd4d2e327d80cc7 | subgoofy.no-ip.biz:1604 | Dark Comet |
Steam Key 3.0.0.0.exe | 0a4e77ba8c79312c61d13abe84cd746e | mytestserver.myftp.org:7000 | |
ufctp6knt.exe | e7078a7a91ae6b43ea2a9a578b9d93b6 | stinaheins.de:21 | N0PE |
wwe_2K18_installer.exe | a4530d29f342d9ecdd56483272bafece | 194.68.59.34:1440 | |
YOUTUBE VIEW BOT-sig.exe | d28f60eea8c742c14fef9b5d564c6471 | dodoos.ru:443 |