Post
Topic
Board Bitcoin Discussion
Re: MtGox_client.exe
by
jhfire
on 21/06/2011, 01:04:48 UTC
Lol, I am quite experienced in the malware field.
Looks like some skids learned to use the leaked Zeus code and a crypter... I'll check this out in NET Reflector  and see if I can't reverse engineer this skiddy.

HAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAH AAAAAAAAAAAAAAAAAAAAAAHAHAHHAHAHAHHAHAHAHAHAHAHHAAHAHAHAHHAHAHAHAHAHAHAHAHHAHAH AHAHA

MAAHHDFSDGHouar589yh4uigre9uiter

That is what I think about your statement. First little kid, the file is written in C++ and uses port 80 to communicate to the site. I thought it was a stealer until I tracked the IP down to the site. I found the control panel, sql injected to find the username and password. It is a HTTP RAT and the control panel has 9k RATS.

This is not Zeus kid and this is not a fucking crypter. It has crypted ST/RT and made a directory in C:\ under the name of win.bin or some shit like that. I already decompiled this virus and got everything out of it. I took down his site and now the game is over. You're to late, please take your kid shit somewhere else.

P.S. I like it how you think by saying "Zeus" and "Lol, I am quite experienced in the malware field." makes you some kind of god.

Edit: I made a thread about it and it got taken down by mobs.