MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.

5.04.2010

New variant of ransomware through porn sites II

A new variant of this malware is In-the-Wild. It spreads through pornographic websites. When the user clicks on any of the images that presents the page to view the video course, an alert box warns about the need to install the Flash Player 10 application and offers the download of executable called flash_player.exe course (f26c45393af03e80a40ea06aafb01c63).

Like the case previously presented in this blog, this is a ransomware that displays a window with pornographic content.

As usual in this type of malicious code in order to eliminate the annoying image, requests to send a text message SMS rate (3381) to a specific phone number (84234321)

In addition, constantly opening a website with pornographic content is also hosted at IP address 77.247.179.176


Countermeasures
Delete the following processes:
  • plugin.exe
  • watcher.exe
Delete the folder hosted on Media C:\Documents and Settings\All Users\Media

Delete the following registry key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Module > c:\documents and settings\all users\media\plugin.exe

Or unlock with the following code: 19282736

Related information
Copyright violation: copyrighted content detected
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild
Desktop Hijack by Internet Security 2010. Your System Is Infected!
LockScreen. Your computer is infected by Spyware!!!

Ver más

4.25.2010

Copyright violation: copyrighted content detected

New ransomaware In-the-Wild that under the excuse of being issued by an alleged entity that protects copyrights, tries to obtain money by deception strategy that seeks to "negotiate" with the victim to pay a fine.

At the time of executing its payload, operating system crashes showing a window as shown below, in which "warned" of the alleged violation of the copyright in the computer to detect copyright material.

The information presented on the screen can be displayed in ten languages: English, Czech, Danish, Dutch, French, German, Italian, Portuguese, Slovak and Spanish. This feature shows the professional looking for the attackers because every translation is well done, which is achieved by outsourcing translation work.

On occasion wallpaper set as the following image:


Furthermore, to ensure a good level of credibility, the strategy uses the legal aspect of the present as set forth in the Copyright Law of the European Union, and displays information from the headquarters of the agency who understands this type of conflict, depending on country is the victim.


For geo-location information, the malware establishes a connection from IP address 91.209.238.2 found in Moldova, Republic Of Eugenia E. Groza reporting IP address, and then do a whois to establish the country of origin of the victim.

> 91.209.238.2/m5tools/ip.php
                        > 91.209.238.2/m5tools/whois.php


Countermeasures
Press the Ctrl + Alt + Del to bring up task manager.
End process "iqmanager.exe"
Delete the folder IQmanager that is located in C:\Documents and Settings\Administrator\Application Data
Delete the Desktop icon

Enter the code below: RFHM2-TPX47-YD6RT-H4KDM


Related information
New variant of ransomware through porn sites
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild
Desktop Hijack by Internet Security 2010. Your System Is Infected!
LockScreen. Your computer is infected by Spyware!!!

Ver más

4.20.2010

New variant of ransomware through porn sites

This summary is not available. Please click here to view the post.

Ver más

3.13.2010

Dangerous trojans, keyloggers and Spyware detected in you computer!!!

This is a new variant of ransomware that is In-the-Wild with, so far, a poor detection rate, the report from VirusTotal. Only 9 of 42 detected by antivirus engines.

It's a technique used by some scareware aggressive to try to "compel" the victims to "buy" the alleged antivirus solution is, in fact, the scareware.

In this case, the malware is hidden under a file called avlck.exe (md5: 04cb597a4ffddfbae9a76cde53833ab7). When run blocking access to the system screen showing the image above position which is expressed in an alleged problem of infection.

In that instance the malware connects to the site


Make a copy of itself into the Windows System folder under the name myserv.exe, and a reference in the registry Run key.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KeyMy c:\windows\myserv.exe 

Countermeasures

Restart in Safe Mode and delete the file myserv.exe found in the Windows folder.
Delete the reference KeyMy (c:\windows\myserv.exe) located in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Unlock the system to any of the following keys:

PozisyonAyarla
HerZamanUstte

Related information
SMS Ransomware for Windows In-the-Wild
LockScreen. Your computer is infected by Spyware!!!

Ver más

3.08.2010

myLoader. Base C&C to manage Oficla/Sasfis Botnet

myLoader a particular purpose Framework developed to manage the activities of a botnet. The data reflected in this report were collected based on the study of the criminal activities of a botnet containing a quantity of more than 210,000 zombies zombies.

We describe the potential threat of this crime through the breakdown of the modules comprising the package that allows the management of the botnet ophicleide / Sasfis. Also presents some information that helps explain his behavior both in propagation strategy as in the processes of infection and prevention to help counteract their actions.

Spanish | English | Author: Jorge Mieres | Malware Intelligence | 2010, March

Ver más