"value":"A few weeks ago CERT Polska released a short blog post introducing a new malware family now known as Bolek. PhishMe and Dr.Web have since added some additional insight into the family. Browsing through a memory dump of the malware, a Webinjects section sticks out. Webinjects usually imply banking malware, so it seems Bolek picks up where its predecessor, Carberp, leaves off. This post takes a closer look at its command and control (C2) mechanism and what it takes to elicit a configuration file from its C2 servers."
"comment":"323084 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: 000a09c86232724445353a8d2e2e9c46eef042669a24b3421d8428105856cc12",
"comment":"323084 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: 000a09c86232724445353a8d2e2e9c46eef042669a24b3421d8428105856cc12",
"deleted":false,
"disable_correlation":false,
"timestamp":"1465739648",
"to_ids":true,
"type":"md5",
"uuid":"575d6980-f344-428b-8cfd-405502de0b81",
"value":"a3de5ad2f5de15f66ca32ac23869fe24"
},
{
"category":"External analysis",
"comment":"323084 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: 000a09c86232724445353a8d2e2e9c46eef042669a24b3421d8428105856cc12",
"comment":"At the time of this research, the C2 servers were down (one of them was a sinkhole already), so a second sample was also used. - Xchecked via VT: cdbd348df2c1d80c9fea63a6d958095b4188c462d17380131d3508d770d3a875",
"comment":"At the time of this research, the C2 servers were down (one of them was a sinkhole already), so a second sample was also used. - Xchecked via VT: cdbd348df2c1d80c9fea63a6d958095b4188c462d17380131d3508d770d3a875",
"deleted":false,
"disable_correlation":false,
"timestamp":"1465739649",
"to_ids":true,
"type":"md5",
"uuid":"575d6981-3da0-415e-8c6e-4f9702de0b81",
"value":"6f24daf8ef6245563afdd095e27408b5"
},
{
"category":"External analysis",
"comment":"At the time of this research, the C2 servers were down (one of them was a sinkhole already), so a second sample was also used. - Xchecked via VT: cdbd348df2c1d80c9fea63a6d958095b4188c462d17380131d3508d770d3a875",
"comment":"278028 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: a0d92950267539d7054843cdbca8976caf7ed4e755d9f9d97622feb6104a4885",
"comment":"278028 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: a0d92950267539d7054843cdbca8976caf7ed4e755d9f9d97622feb6104a4885",
"deleted":false,
"disable_correlation":false,
"timestamp":"1465739650",
"to_ids":true,
"type":"md5",
"uuid":"575d6982-c768-41c1-99a9-41c302de0b81",
"value":"3b10ebf43e537f93c4c7ed0c11a2b7db"
},
{
"category":"External analysis",
"comment":"278028 bytes of binary data. Contains a PE file starting at offset 524. - Xchecked via VT: a0d92950267539d7054843cdbca8976caf7ed4e755d9f9d97622feb6104a4885",