MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.

8.16.2010

New Russian SMS ransomware In-the-Wild

The development of malware designed to block access to the operating system is in full expansion. Despite being at present a very different generation of ransomware the first generations where, using cryptovirology, literally kidnapped by encrypting user files and requesting a financial compensation in exchange for the release key, the concept and goal has not changed.

In this case, it’s a new variant of SMS ransomware blocking access to the operating system screen showing an alleged safety report in which reference is an infection caused by a variant of trojan recruits zombie botnets for ZeuS is actually false.


The brief report is in Russian language with which it follows that the objectives of malware are the users of that country. However, the spread of the threat has no boundaries and no language limitations.

According to the text, to get a key to unlocking it's necessary to send a message such as SMS to 4161 with the message 2AV112239. This set of alphanumeric characters isn’t the only one who can show, as it has a list that is displayed at random. The list consists of the following springs:

2AV166522, 2AV288764, 2AV222419, 2AV288888, 2AV266555, 2AV119999, 2AV121436, 2AV178477, 2AV166522, 2AV111199, 2AV187211, 2AV133211, 2AV111223, 2AV243562, 2AV211246, 2AV244533, 2AV277631, 2AV233884, 2AV242665, 2AV233211, 2AV288599, 2AV299884, 2AV286442, 2AV248864, 2AV222464, 2AV288434, 2AV265543, 2AV211278, 2AV299977, 2AV165431, 2AV131313, 2AV132218, 2AV155543, 2AV166666, 2AV186443, 2AV155422, 2AV198775, 2AV144366, 2AV199797, 2AV197797, 2AV177979, 2AV166321, 2AV111229, 2AV155322, 2AV187532, 2AV112239, 2AV164554, 2AV134274, 2AV153221, 2AV311111, 2AV311112, 2AV311113, 2AV311114, 2AV311115, 2AV311116, 2AV311117, 2AV311118, 2AV311119, 2AV311120, 2AV311121, 2AV311123, 2AV311124, 2AV311125, 2AV311126, 2AV311127, 2AV311128, 2AV311129, 2AV311130, 2AV311131, 2AV311132, 2AV311133, 2AV311134, 2AV311135, 2AV311136, 2AV311137, 2AV311138, 2AV311139, 2AV311140, 2AV311141, 2AV311142, 2AV311143, 2AV311144, 2AV311145, 2AV311146, 2AV311147, 2AV311148, 2AV311149, 2AV311150, 2AV311151, 2AV311152, 2AV311153, 2AV311154, 2AV311155, 2AV311156, 2AV311157, 2AV311158, 2AV311159, 2AV311160, 2AV311161, 2AV311162, 2AV311163, 2AV311164, 2AV311165, 2AV311166, 2AV311167, 2AV311168, 2AV311169, 2AV311170, 2AV311171, 2AV311172, 2AV311173, 2AV311174, 2AV311175, 2AV311176, 2AV311177, 2AV311178, 2AV311179

The malware disables the possibility to access the system in Safe Mode and access the following programs:
  • TASKMGR.EXE
  • REGEDT32.EXE
  • MSCONFIG.EXE
  • EXPLORER.EXE
  • TEXPL.EXE
  • ANVIR.EXE
Countermeasure
Unlock using the following key:
  • Environ
Click the first button and press the Enter key.
Restart the system.
Delete the registry key from ctfmon.exe.


Run an updated antivirus.

Related information
New variant of ransomware through porn sites IV
New variant of ransomware through porn sites III
New variant of ransomware through porn sites  II
New variant of ransomware through porn sites
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild

Ver más

8.11.2010

PC Defender Antivirus rogue update system registry

The criminals who are behind the development of PC Defender Antivirus rogue in the last few hours have updated the registration system for the false application.

The record in the first version was to send a text message SMS rate telephone number located in Russia, while this new version requests a serial number (supposedly under the hardware-locked system) generated using as part of a activation key.

It also adds a button (Buy) that redirects to a form hosted on Plimus, and updated the malware into English. The first version was only in Russian.

This action makes it quite evident that behind the spread of these threats, lies across an organization intended to develop malware to accommodate an underground economy that feeds, increasingly, fraudulent methods.

Ver más

Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus

Pay-per-Install is one of the business models by which an affiliate system provides a set of "clients" one or more malicious code, paying each a percentage of money as a commission for each installation the malicious application successful.

Phoenix Exploit's Kit is a crimeware by which intelligence is done collecting statistical information related to each of the infected computers. You enter through an access panel via the http protocol as we see in the screenshot.

PC Defender Antivirus is a rogue Russian origin whose spread is being made through Phoenix Exploit's Kit, reporting at the same time to an affiliate system that records the installation of each downloaded copy.

In addition to collaborating with the criminal circuit feeding back the fraudulent business through Pay-per-Install, the rogue has the grain of usual business whereby it’s intended that the fraudulent application is purchased, also via the web, this action involving form information stored somewhere confidential credit card. The cost of the rogue is USD 59.95.

Through Phoenix Exploit's Kit spreads a trojan downloader called exe.exe, in this case MD5 e49be7ef82250a36cf7410004ac3d69c that, after it establishes a connection to fordkaksosat.info (193.105.207.45 - AS50793 "ALFAHOSTNET") from which it downloads and executes the rogue (PCDefenderSilentSetup.msi - ecff63c1f983858dfd7fb926738cb478).

In this instance, the rogue is reported to the affiliate system to load the information on successful installation through count_installs.php file, and begins a malware scan issuing alerts about alleged attempts to connect infections and also false. This activity is usual in this type of malware to be one of their employers.


The release system for the alleged security application is similar to that used by some families of ransomware through the business model that involves sending a text message SMS to a specific type of phone number.

In this case, the information should be sent to the number 5711000002209 with the message 6681.


The threat has a timer which generates a false statement Blue Screen of Death (BSoD), in which shows the incentive to record the program, exerting a fear (psychological warfare) on the user that after reading this information might think register/buy what you think, this is a real antivirus solution.


Countermeasures
Terminate the processes called prockill32.exe, proccheck.exe and rundelay.exe. You can use the ProcessExplorer to view and terminate processes.

Remove PC Defender folder (which houses six files) located in C:\Program Files\Def Group\

Delete the system registry PC Defender key from HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run, which refers to c:\program files\def group\PC Defender\pcdef.exe. You can use the Autoruns to view and delete the key.

Related Information
New variant of ransomware through porn sites IV
New variant of ransomware through porn sites III
New variant of ransomware through porn sites  II
New variant of ransomware through porn sites
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild
Desktop Hijack by Internet Security 2010. Your System Is Infected!
LockScreen. Your computer is infected by Spyware!!!

Ver más

7.23.2010

SMS Ransomware porn template update

A new variant of ransomware type blocker that promotes pornographic sites is In-the-Wild, with the inner slightly modified. Basically you have changed the number to which the victim must send messages like SMS. Now the number is 86571252 and the message remains the same: 6005.

Another change is in the location which holds the copy of the threat. In this case, the path is C:\Documents and Settings\Default User\Media\ under the name run32.exe. The first image shows the previous version, while the second corresponds to the new variant of the SMS Ransomware.

The ransomware is distributed, as in previous cases, through porn sites. This variant uses the same name as cover (flash_player.exe), its MD5 is 2e8f56ce39270e10f7082a35d13a735a and as I write this update has a detection rate average, 12/42 being detected by antivirus engines.


Countermeasures
Identify and terminate the process called "run32.exe." At this time ransomware window disappears.
** The name of the process can also be process32.exe.

*** To kill the process you can use Task Manager or the native Windows application ProcessExplorer.

Delete the following system information
Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Module
Value:
AModule
"C:\Documents and Settings\Administrador\Media\run32.exe"
*** You can also use Autoruns application to view the record in an orderly manner.

Folders:
C:\Documents and Settings\Default User\Media

Files:
C:\Documents and Settings\All Users\Media\run32.exe
C:\Documents and Settings\All Users\Media\rdb.bat

Related information

New variant of ransomware through porn sites IV
New variant of ransomware through porn sites III
New variant of ransomware through porn sites  II
New variant of ransomware through porn sites
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild

Ver más

7.18.2010

New variant of ransomware through porn sites IV

This summary is not available. Please click here to view the post.

Ver más