Archived Blog
Part I - The Initial Executable
The executable was packed with tElock, which is a free compressor/protector made by TMG. After unpacking it, we found that the malware was coded in Visual Basic and hence would allow us to use a decompiler such as VB Decompiler by GPcH Soft. Once opened in the decompiler, you see the following:
Figure 1:

The results reminded us of a sample we had looked at previously which had procedure names in Portuguese and references to MSN Messenger. However, you will notice some large differences as it seems to have encryption and downloading capabilities. If you set a breakpoint on the Crypt function and step through the code you see the following:



Part II - Behavior and the Additional Downloads



Security Researcher: Joren McReynolds




























