kishfellow's blog
Rootkit.Win32.Agent.akga - AKGA rootkit
Submitted by kishfellow on Fri, 2010-03-05 18:54. MalwareA friend of mine was infected with this Rootkit, I thank him for contributing the sample.
He saved the sys file from a backup, and uploaded it for us at Rapidshare.
http://rapidshare.com/files/359540439/xeortd.rar
A thread discussing behavioral details, and removal instructions for the rootkit
Courtesy of Spybot S&D - http://forums.spybot.info/showthread.php?&t=55711
I tried viewing the SYS file with Wordpad (not a disassembler) and found APIs like IoDeleteDevice and APIs which are hidden.
Facebook Phisher
Submitted by kishfellow on Wed, 2009-07-15 07:06. Exploits | MalwareFacebook phisher - Check it out while it's hot !
RAR Archive Password: "infected" (without quotes)
Cheers :)
Kish
Firepack toolkit - Source code
Submitted by kishfellow on Fri, 2009-06-05 19:04. Exploits | MalwareSource code of an exploit pack - Firepack
RAR Archive Password: "infected" (without quotes)
P.S: Don't know if this has been posted earlier ... ;)
Cheers :)
Kish
MyDoom & Beagle Worms - Source code
Submitted by kishfellow on Fri, 2008-11-07 09:33. Exploits | MalwareSource code of a coule of worms that gave people a good run for their money
RAR Archive Password: "infected" (without quotes)
P.S: Don't know if this has been posted earlier ... ;)
Cheers :)
Kish
Realmbot - Source code
Submitted by kishfellow on Thu, 2008-11-06 09:29. Exploits | MalwareFound this bot's source code lying in my drive, this is from 2006.
P.S: Iam still alive... up and running ...
Cheers :)
Kish
Injecto - Source code
Submitted by kishfellow on Sat, 2008-06-28 07:32. MalwareFound this Injecto source to be lying on my hard disk, thought I'll post it here ...
Cheers :)
Kish
Cabir (Caribe.a) - Source code
Submitted by kishfellow on Thu, 2008-06-26 11:31. Exploits | MalwareHi people, After a long time, one decent post perhaps ;)
This worm is a mobile malware, also the alias of the infamous Cabir.a
The author has originally named it Caribe.a, and this worm looks like some C/C++ code.
Ref: http://www.viruslist.com/en/viruslist.html?id=1689517
The source code as usual, is uploaded for you ;)
Cheers :)
Kish
pBot - PHP Remote File Include Bug - Web based / PHP bot
Submitted by kishfellow on Mon, 2008-03-10 00:40. Exploits | MalwareSpeaking about PHP RFI vulns, this is a classic example.
This is a web-based bot that uses PHP as it's base, and is similar to BlackEnergy DDoS bot in terms of operating out of the web.
OC Download pBot Source code (rename extension to .rar)
Here's the Rapidshare Mirror
Cheers :)
Kish
Possible Terrorist Website ?
Submitted by kishfellow on Tue, 2008-02-05 21:53. ExploitsJust found out this blog, and I have a strong intuition that this belongs to a terrorist group (mujahideen / taliban / al-qaeda) ??
Check it out if your just as curious
Few more sites found ...
http://naseeha.wordpress.com/
http://moderatesrefuted.wordpress.com/
http://truthline.wordpress.com/
http://alkarnee.wordpress.com/
and a terrorist magazine: http://202.75.33.137/uploads/teaqny_magazine1.zip
Update: Will try to add random terrorist encryption tools download if I get my hands on them in a while ...
Cheers :)
Kish
An idea that never materialized
Submitted by kishfellow on Wed, 2008-01-30 22:52.Warning: This happens to be an OFF Topic Post, sort of a rant.
It's too bad that we didn't see the potential to develop something similar here in Offensive computing, even upon a bare idea and some small support from one guy who said it's a nice idea to have a standard for testing AVs
Today this is here on ...
http://www.securityfocus.com/news/11502
Just felt like, aww, that's something I thought, and it never materialzed ;)
Cheers :)
Kish
