Here's the dumped DLL from memory from the CCleaner backdoor: https://www.virustotal.com/#/file/2bc2dee73f9f854fe1e0e409e1257369d9c0a1081cf5fb503264aa1bfe8aa06f/detection …
-
Show this thread
-
Replying to @bartblaze
Hi bart can you explain how to extract the DLL ccleaner from the memory image..thks
1 reply 0 retweets 0 likes -
Replying to @danu_dirjas
You can dump the binary from memory, then use malfind (in Volatility) for example.
2 replies 0 retweets 0 likes -
Replying to @bartblaze
Here is my malfind dump...pic.twitter.com/A2BS7zB733
1 reply 0 retweets 0 likes
Replying to @danu_dirjas
Hey, apologies for late reply. Try to match the filesize with the sample I posted earlier. Alternatively, you can submit your dumps to VT.
2:32 AM - 10 Oct 2017
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.