Wow SteveSOSP3. You dont even see whats being said here... iStealer? Does that not sound an alarm?
Lets take your post first.
Quote:
Originally Posted by SteveSOSP3
Bruteforcers tend to fail.
|
If you know they tend to fail, then why not download the file and see if it passes a scan, or to see if its a keylogger??!?!
Code:
C:\Documents and Settings\Louis\Desktop\vb keylogger\Best FTP\obj\Release\Silence FTP keylogger.pdb
Wow. This could had been bad since you just passed it over like it was nothing.
Malicious TROJAN Detected
What's been found: Creates a startup registry entry.
Code:
* The following files were created in the system:
# Filename(s) File Size File Hash
1 c:\system.jpeg 38,075 bytes MD5: 0x4B013465BB9A16031CC47193ECC981ED
SHA-1: 0xFF8472399648A430EE1830FF44AB22BBF1F2A76E
2 c:\temp98.dat 44 bytes MD5: 0x3E5CEB07F51A70D9D431714F04C0272F
SHA-1: 0x045C85BA38952325E126C70962CC0F9D9077BC67
3 [file and pathname of the sample #1] 26,624 bytes MD5: 0x3312232B749C46DD653000F1961D2DE5
SHA-1: 0x50C2F60140C8266AEB95A8058BD813AC0E051D29
4 %Windir%\temp88.dat 80 bytes MD5: 0x425074B203FD4517752415AFBBA1804E
SHA-1: 0x31A75095C82E4A8DD267BBB1EA95A04A578E1BB5
Code:
* The following port was open in the system:
Port Protocol Process
1081 TCP [file and pathname of the sample #1]
* The following Host Names were requested from a host database:
o wpad.mrc.pctools.com.
o ftp.drivehq.com
* The following GET request was made:
o wpad.dat
Lets Disassemble his trojan:
Hmm.. seems we have Mr.Trojanner's (Timmy from FkN) FTP info. Lets see what he has in there.