I can Finally share this malware sample. As some background context: As I have been getting so, SO many requests "do you have a sample of.." (and each request was about a different malware, mostly 'normal, day to day' malwares, which I dont collect or try to analyze, simply because it's not interesting. And, those will inevitably get detected(if they are atm undetected) by AV's and stuff.

I wanted to share this malware sample. A file related to the IRATEMONK project.

[!]
And, I have begun to make warnings of my samples more clear. I will include one here.

I warn you who reads this -That-
This is a ⚠️ MALWARE SAMPLE ⚠️
do NOT continue until you are 100% SURE about what you are getting yourself into.

 

hxxps://github [dot] com/loneicewolf/nls_933w_dll

- https://securelist.com/equation-the-death-star-of-malware-galaxy/68750/
- https://www.schneier.com/blog/archives/2014/01/iratemonk_nsa_e.html

- https://www.virustotal.com/gui/file/83d14ce2dcfc852791d20cd78066ba5a2b39eb503e12e33f2ef0b1a46c68de73/detection

- https://www.virustotal.com/gui/file/07fc80ecaa8f12f0d57fbf9627d5505b8f969a84fc3907c31dd68f5022edf643/detection

#github
#iratemonk
#loneicewolf
#eqgrp
#equationgroup
#bootkit
#rootkit
#dll
#firmware_level_malware
#nsa

Equation: The Death Star of Malware Galaxy

The Equation group is probably one of the most sophisticated cyber attack groups in the world.

Kaspersky