Nytro Posted July 16, 2014 Report Posted July 16, 2014 Soraya: The Worst of Both WorldsA FortiGuard Labs Technical AnalysisIntroductionSoraya is the first of its kind, a hybrid piece of malware combining popular form grabbing techniques seenin Zeus and memory parsing techniques seen in Dexter and JackPOS.In this report, we join Junior AV Analyst Hong Kei Chan in describing Soraya’s installation then analyzing thetwo defining elements of Soraya – form grabbing and memory parsing. We will also review the command-and-control (C&C) communication protocol in detail by exploring the features found in Soraya’s controlpanel.InstallationMany of the samples received by FortiGuard Labs have been packed with custom packing algorithms,where a 24KB UPX-compressed image is mapped back to the original base address and then executed.Soraya does not import any functions, so it utilizes a common technique where the base address ofkernel32.dll is retrieved from the Process Environment Block (PEB) structure before resolving theaddress of the target API using values that have been hashed from the API names.The addresses of the following APIs are retrieved using this custom algorithm:Fortinet | High Performance Network Security, Enterprise and Data-Center Firewall Solution Brief : Two-Factor AuthenticationLoadLibraryGetProcAddressVirtualProtectZwCreateSectionZwMapViewofSectionRtlMoveMemoryCreateRemoteThreadGetModuleHandleWCreateToolHelp32SnapshotProcess32FirstProcess32NextOpenProcessisWow64ProcessExitProcessAfter getting the handle of its target processes, it uses ZwCreateSection, ZwMapViewofSection,RtlMoveMemory, and CreateRemoteThread to inject itself into a number of system processesincluding explorer.exe to begin its malicious functions.Download: http://www.fortinet.com/sites/default/files/whitepapers/soraya_WP.pdf Quote
ELCACIQUE Posted October 23, 2014 Report Posted October 23, 2014 do you have any tutorial about Soraya? Quote
malsploit Posted October 23, 2014 Report Posted October 23, 2014 Mi s-a parut o porcarie. Am analizat un sample si e banal.MalwareTech: Hacking Soraya Panel - Free Bot? Free Bots! Quote