View Single Post
  #27  
Old July 15th, 2010, 05:36 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Rootkit.TmpHider

Quote:
Originally Posted by frank_boldewin
hi guys,

has anyone already taken a deeper look at the malware?

i found stuff like this after some decryption/unpacking stages of MD5 sample 016169ebebf1cec2aad6c7f0d0ee9026

Code:
SOFTWARE\SIEMENS\WinCC\Setup STEP7_Version SOFTWARE\SIEMENS\STEP7 SOFTWARE\Microsoft\Windows\CurrentVersion\MS-DOS Emulation NTVDM TRACE
this points me to the Siemens WinCC SCADA system.
looks like this malware was made for espionage.

Maybe it was written by someone in the Utilities business?
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?