Viral Rewind: Virus.DOS.Luci (Luce/Lucifer_II)

  Рет қаралды 107

MB Education

MB Education

Күн бұрын

Luci/Luce/Lucifer_II (whatever else it could go by) variant 4628/4632 has to be one of the more convoluted pieces of malware when it comes to understanding how the virus replicates and performs various payloads. So much in fact I had to keep notes on what I discovered and even then I don't have 100% of the activation methods and results of what this virus can do.
This virus when first loaded will reside in memory and will first infect the COMMAND.COM ensuring it loads each time with the system. It is polymorphic which aids in avoiding detection and may be why it can be hard to decipher. It isn't stealthy so file size increases will be apparent. It infects .EXE and .COM files when accessed but it will infect .SYS files as well.
The payloads (from what I gathered) can be broken down in two categories: Non-System Affecting and System Affecting.
Non-System Affecting:
System must be booted during the specific day and time.
-Mondays/Thursdays between 12AM and 7PM (black bar scrolls vertically on screen)
-Fridays at the top of the hour for 20 minutes (screen bob up/down)
-Saturdays between 12AM and 4PM (black bar and screen bob)
(Tuesday, Wednesday and Sunday have no effects).
System Affecting:
Payloads are day of the week AND day number dependent (usually)
-Monday 1st/3rd (infects MBR)
-Monday 2nd (infects MBR/removes floppies CMOS)
-12th (removes floppies CMOS)
-Thursday 20th (display OVER-X)
Other possible payloads that have been exhibited include mass file deletion, programs not running, programs crashing and programs behaving oddly
-----------------------------------------------------------
Visit my Linktree to access my socials and other channels: linktr.ee/maus...

Пікірлер: 3
@NguyenHoang-pv2xd
@NguyenHoang-pv2xd 12 күн бұрын
Request: Trojan Win32 Gentee all variants Test on Windows XP include supplemental language East Asian language
@zzco
@zzco Ай бұрын
between Midnight and 7PM, meaning that it runs the whole damn day and sleeps for 3 hours later? Lol
@SugarTearz2003
@SugarTearz2003 Ай бұрын
Just like me fr
What Enterprise-Grade malware looks like
20:09
Eric Parker
Рет қаралды 62 М.
I Made The Ultimate Cheating Device
9:39
ChromaLock
Рет қаралды 202 М.
WORLD BEST MAGIC SECRETS
00:50
MasomkaMagic
Рет қаралды 34 МЛН
Brawl Stars Edit😈📕
00:15
Kan Andrey
Рет қаралды 43 МЛН
Новый уровень твоей сосиски
00:33
Кушать Хочу
Рет қаралды 3,8 МЛН
Viral Rewind: Virus.DOS.Casino
9:05
MB Education
Рет қаралды 223
The History of X11
58:19
RetroBytes
Рет қаралды 253 М.
QBA27. - To print the IMPOSSIBLE print!!!!
28:35
Dr. Doodle's QBasic Asylum
Рет қаралды 46
Harder Drive: Hard drives we didn't want or need
36:47
suckerpinch
Рет қаралды 1,7 МЛН
I Tested Malware Against Antiviruses
12:02
Crypto NWO
Рет қаралды 1,2 МЛН
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
The Top 10 Worst Operating Systems of All Time
25:40
Dan Wood
Рет қаралды 711 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 624 М.
Homelab Setup Guide - Proxmox / TrueNAS / Docker Services
2:44:39
Matthias Benaets
Рет қаралды 176 М.
WORLD BEST MAGIC SECRETS
00:50
MasomkaMagic
Рет қаралды 34 МЛН