Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code

Go down

Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code Empty Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code

Post  andry Wed Dec 22, 2010 4:01 am

Trojan-GameThief.Win32.Magania, according to Kaspersky naming convention, monitors the user activities trying to obtain valuable information from the affected user, especially about gaming login accounts. This long tutorial analyze this malware but is also a general document which explains how to analyze a modern nested-dolls malware.

In this paper we will analyse more deeply the structure of this malware, especially the polymorphic part that represents a typical sample of hostile code. Starting from the first load into IDA we can see that Megania's PE structure and Import Table destroyed, this is how looks from WinGraph:

Download PDF
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum