• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / tools / ATMMalScan: Find malware on ATMs

ATMMalScan: Find malware on ATMs

18/01/2021 19:20 by Anastasis Vasileiadis

ATMMalScan is a command line tool for Windows 7 or later operating systems that helps detect malware in an ATM using the DFIR process.

The program examines the current processes of a system as well as the hard disk, depending on the specified file path. To scan a system, a user with standard permissions is enough. However, ATMMalScan provides better results with administrator privileges.

Problems

ATMMalScan does not currently support pages that require Unicode, which means that on Windows operating systems that are defined e.g. in Cyrillic or Chinese may have no effect.

Use (Example)

Step 1: Process memory and disk scan. Check if administrator privileges are available on the device for best results!

1 Scan Mem Disk - ATMMalScan: Find malware on ATMs

Step 2: ATMMalScan detects malware called XFS_DIRECT and gives details of the threads and rules that match.

In addition, it has saved a complete processmemory to disk to detect malicious process, sections, and stack and heap pages.

2 Scan Malware Detected - ATMMalScan: Find malware on ATMs

Step 3: You will find Dump here \ Dump.

3 Scan Malware Dump - ATMMalScan: Find malware on ATMs

Step 4: Open the dumpfile with Windbg and extract the ATM malware to disk using ".writemem"

4 Windbg Malware Extraction - ATMMalScan: Find malware on ATMs

Step 5: Fix the dumped PE with one of your favorite PE-Fixers and start analyzing the malware in detail.

5 PEDumpFixerIDA - ATMMalScan: Find malware on ATMs

You can download the program from here.

ATMMalScan: Find malware on ATMs was last modified: 18 January, 2021, 7: 20 mm by Anastasis Vasileiadis

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: toolstag: ATM, malware

You May Also Like

British Ministry of Education distributed notebooks with malware
Freki - Malware Analysis Platform
Microsoft warns of Adrozek infecting browsers

About Us Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Previous Post: « Protect yourself online Garud: Discover subdomains automatically
Next Post: Inkscape 1.0.2 was released for Linux, Windows and Mac »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.