MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.
Showing posts with label rogue. Show all posts
Showing posts with label rogue. Show all posts

7.13.2012

New variant of another fake antivirus program called Live Security Platinum


This is the icon used for the fakeAV


Technical information & PE file attribute
MD5 :  8ed72a01f6dd01cf353091492d7e96c6
SHA1:  a810430d6d26e97b1a8b48898d8effe4ed8a140e
['Microsoft Visual C++ v6.0'], ['Microsoft Visual C++ 5.0'], ['Microsoft Visual C++'], ['Microsoft Visual C++ v6.0'], ['Installer VISE Custom']


PE information & sections:      
      Win32 Executable MS Visual C++ (generic) (65.2%)
      Win32 Executable Generic (14.7%)
      Win32 Dynamic Link Library (generic) (13.1%)
      Generic Win/DOS Executable (3.4%)
      DOS Executable Generic (3.4%)


     Optional Header: 0x400000
     Address Of Entry Point: 0x1953
     Compile Time: 2012-07-12 09:06:36
     Number of RVA and Sizes: 16
     Number of Sections: 4


Imported DLLs and API:
[1] KERNEL32.dll     
     0x407000 Sleep
     0x407004 CloseHandle
     0x407008 GetProcAddress
     0x40700c GetModuleHandleA
     0x407010 InterlockedExchange
     0x407014 SetEvent
     0x407018 CreateFileA
     0x40701c VirtualAllocEx
     0x407020 LCMapStringA
     0x407024 GetStringTypeW
     0x407028 GetStringTypeA
     0x40702c MultiByteToWideChar
     0x407030 RaiseException
     0x407034 LoadLibraryA
     0x407038 GetOEMCP
     0x40703c GetStartupInfoA
     0x407040 GetCommandLineA
     0x407044 GetVersion
     0x407048 ExitProcess
     0x40704c HeapFree
     0x407050 TerminateProcess
     0x407054 GetCurrentProcess
     0x407058 UnhandledExceptionFilter
     0x40705c GetModuleFileNameA
     0x407060 FreeEnvironmentStringsA
     0x407064 FreeEnvironmentStringsW
     0x407068 WideCharToMultiByte
     0x40706c GetEnvironmentStrings
     0x407070 GetEnvironmentStringsW
     0x407074 SetHandleCount
     0x407078 GetStdHandle
     0x40707c GetFileType
     0x407080 HeapDestroy
     0x407084 HeapCreate
     0x407088 VirtualFree
     0x40708c RtlUnwind
     0x407090 WriteFile
     0x407094 HeapAlloc
     0x407098 VirtualAlloc
     0x40709c HeapReAlloc
     0x4070a0 GetCPInfo
     0x4070a4 GetACP
     0x4070a8 LCMapStringW
[2] USER32.dll       
     0x4070b0 LoadBitmapA
     0x4070b4 ShowWindow
     0x4070b8 LoadImageA
     0x4070bc LoadIconA
[3] WINMM.dll        
     0x4070c4 mixerGetControlDetailsA


VT information about detection rate 22/42


Live Security Platinum screenshots
Warning popups


Live Security Platinum GUI:





Live Security Platinum monetization

Live Security Platinum registration

** Information obtained through the automated process malware analysis of CrimewareAttack Service(by  MalwareIntelligence).

Alex



Ver más

2.14.2011

Facebook rogue applications still lurking around

For quite some time now there are rogue applications  trying to convince you that you are able to check whoever viewed your profile. There are a lot of different names for this rogue application, some but not all include:

  • creep exterminators
  • catch them being creepy
  • creepy profile peekers
  • privacy bros
  • we catch stalkers
So what will this fake application do? For starters, it will surely NOT show you who's been viewing your profile.  If you land on this application, you will be presented with the following screen:

Profile Creeps application

Request for permission

You then have to allow access from the application so they can show you who's been lurking around your profile. But wait ! You first have to complete a survey and then you are able to check it out. Simple, right?

Facebook verification

Not exactly. These fake surveys are pretty common on the internet. It is a typical scam. For example, I had one particular survey that urged me to download SmileyCentral, the other tried to deliver me Webfetti.

Another fake survey wanted me to fill in my phone number, and afterwards send an (expensive) text message to 'unlock' the application. In addition to letting you fall into one of these scams, the rogue application also promotes itself on all of your friends’ walls:





Rogue application spreading itself on other people’s wall


If you would like to remove it, follow the steps below:
  • Go to your Facebook profile. Find the post that mentions the "stalker" application
  • Skim over it and you will see an X appear. Click on it and choose "Remove (name of the fake application here)".
  • Additionally, you can also report it as abusive to help in stopping these type of applications.
  • Next step is to click on My Account and choose Privacy Settings. Down below you can see "Apps and websites". Click on Edit your settings.
  • Select Remove unwanted or spammy apps. You can now Edit the application and remove it.

MalwareIntelligence Team

Ver más

8.31.2010

AntiSpy Safeguard with new social engineering approach

AntiSpy Safeguard is a new rogue that is In-the-Wild and that its spread is new coverage of using deception in a video shown and a false report in the style of the services offered by VirusTotal or Virscan.

 
The following image belongs to the inicial interface that is displayed in the first instance on a system infected by this rogue.


To read the full report MalwareIntelligence blog.

Related information

Litter Korean rogue lurking V
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

8.29.2010

Litter Korean rogue lurking V

Another piece of rogue from Korea and belonging to the family of PrivacyKeep, PrivacyCorp and PCScan.

ProtectInfo

protectinfo.co.kr - 114.108.168.8 - DACOM-NET LG DACOM


The IP address also resolves the following domains:
ad-clear.com
privacycop.co.kr
privacykeep.co.kr
protectinfo.co.kr

protectinfo_home.exe (a48e62c64f68a2b32dc601efffa2973d)

update.protectinfo.co.kr/instchk.php

226
[COUNTER]
NUM=6

[CHECK1]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK2]
HKEY=HKLM
REGPATH=PrivacyCheck
REGNAME=DisplayName
REGVALUE=.......... ....

[CHECK3]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK4]
HKEY=HKLM
REGPATH=............
REGNAME=DisplayName
REGVALUE=............

[CHECK5]
HKEY=HKLM
REGPATH=..........
REGNAME=DisplayName
REGVALUE=..........

[CHECK6]
HKEY=HKLM
REGPATH=privacykeep
REGNAME=DisplayName
REGVALUE=............

[HISTORYREG]
PATH="............"


protectinfo.co.kr/app_linkage/app_install.php?addr=000C29CA888C&ptn=infocode0067
protectinfo.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C

3d
payed=0
pw_usr=
pw_sup=1470
hp1=
hp2=
hp3=
small=300
big=300


log.adsence.co.kr/logexp.php?aid=protectinfo&pid=infocode0067&kind=inst
file.protectinfo.co.kr/update.php

protectinfo.exe=0.325
pnfoupdater.exe=0.113
pnfohk.dll=0.110
pnfouninst.exe=0.1
pnfowcher.exe=0.116
pnfopopd.dll=0.1


protectinfo.co.kr/app_linkage/app_boot.php?ver=.0.398
protectinfo.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C
protectinfo.co.kr/settlement/paysys/mobile/Deliver.php
protectinfo.co.kr/settlement/paysys/pbill/Deliver.php
protectinfo.co.kr/settlement/paysys/ars/Deliver.php



Countermeasures

Uninstall from Program Files
Running updated antivirus

Related information



Litter Korean rogue lurking IV
Litter Korean rogue lurking III
Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Jorge Mieres 

Ver más

8.22.2010

Litter Korean rogue lurking IV

Korean rogue fourth part of the "litter" that haunts the past few days looking for potential victims caught in Korea. At times the rogue that spread can have an option to change the language, so that coverage is much wider infection, however, in this case, it's directed at specific populations rogue.

PrivacyCorp
privacycop.co.kr - 114.108.168.8 - DACOM-NET LG DACOM


The IP is also the following domains:
ad-clear.com
info-dr.com

privacycop_setup.exe (8362c089bc4f7932dc885e23044cb2f6)
privacy_mediccop.exe (46f2a84d7217a5ca56208ea0b13c6f52)

The circuit is part rogue criminal systems led by members who pay a percentage of money for each installation of the threat spread. This case is no exception. The rogue reports successful installation immediately after infection.

privacycop.co.kr/app_linkage/app_install.php?addr=000C29CA888C&ptn=home
log.adsence.co.kr/logexp.php?aid=privacycop&pid=home&kind=inst
privacycop.co.kr/app_linkage/app_setting.php?mac=00-0C-29-CA-88-8C
3e
payed=0
pw_usr=
pw_sup=1470
hp1=
hp2=
hp3=
small=300
big=3660

file.privacycop.co.kr/update.php
6d
privacycop.exe=0.328
pvcupdater.exe=0.112
pvchk.dll=0.1
pvcuninst.exe=0.1
pvcwcher.exe=0.112
pvcpopd.dll=0.1

privacycop.co.kr/app_linkage/app_boot.php?ver=.0.4.5.3
privacycop.co.kr/popup_settle.html?addr=00-0C-29-CA-88-8C


Countermeasures
Terminate the processes called privacycop.exe and pvcwcher.exe. You can use the ProcessExplorer to view and terminate processes.

Uninstall from Program Files
Running updated antivirus

Related information

Litter Korean rogue lurking III
Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

Litter Korean rogue lurking III

PCScan is another rogue Koreans that have appeared in recent days, in addition to the two previously showed.

pcscan.kr - 114.108.129.233 - DACOM-NET LG DACOM

The IP also resolves the following domains:
eroza.net
master.to84.net
to84.net
www.tvbaro.net

Setup.exe (a85900759318ea66dc94ba789aae2cfe)
PCScan.exe (665b846b82d959843744d9d3a7b39bdc)
PCScanMon.exe (01cdb8f8955a4df6eebb1aca04d6a43c)
Uninstall.exe (76cd1340bded9d96050df30999f6274d)

Unistaller.exe file simulates the uninstaller antivirus program assumes, however, no effect arises because it’s false.

Check the following pages:
pcscan.kr/request/module_setup.php?p=PCScan&a=type1
pcscan.kr/request/License.txt
pcscan.kr/down/install.exe
down.elineguide.com/down/install.exe

pcscan.kr/down/files.php?strMode=setup&strID=PCScan&arg=type1&strSite=&strPC=000c29ca888c
pcscan.kr/down/PCScan.exe
pcscan.kr/down/PCScanMon.exe
pcscan.kr/down/Uninstall.exe
pcscan.kr/down/PCScanControl.dll

pcscan.kr/value.php?strMode=setup&strID=PCScan&arg=type1&strSite=&strPC=000c29ca888c&url=
pcscan.kr/settle.php?strID=PCScan&arg=type1&strPC=000c29ca888c&strSite=pcscan.kr
pcscan.kr/bill_danal/bill_home/with_bill.php?strID=PCScan&arg=type1&strPC=000c29ca888c&strSite=pcscan.kr
pcscan.kr/consultation.php


Countermeasure

Terminate the processes called PCScan.exe. You can use the ProcessExplorer to view and terminate processes.

Remove PCScan folder (which houses six files) located in C:\Program Files\pcscan\

Delete the system registry pcscan key from HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run, which refers to "C:\Program Files\pcscan\pcscan.exe". You can use the Autoruns to view and delete the key.

Delete the desktop shortcut.

Running updated antivirus

Related information

Litter Korean rogue lurking II
Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

8.21.2010

Litter Korean rogue lurking II

Se trata de otro rogue perteneciente a la camada que actualmente se encuentra al acecho. Su nombre es PC Boan Plus.
pcboanplus.com - 222.122.84.56 - KORNET KOREA TELECOM

Domains that resolve to the same IP:
postmaster.8282tv.co.kr
pspd.org

PcBoanPlus2SetupH.exe (0ab2cc07373a4b88a0084f12ae63f54f)



This rogue report a system of affiliates Pay-per-Install that resolves the domain to an IP address corresponding to the ISP "KRNIC".

211.33.123.40/pcboanplus/install.php?mac=000C29CA888C&partner=PcBoanPlus&ver=

file.pcboanPlus.com/app/updater/PcBoanPlus2Up.exe
file.pcboanplus.com/app/Client/PcBoanplus2.exe
pcboanplus.com/app/badinfo.php?Vn=2005010100&Kind=comp

s223.pc-korea.net/badlist/2010080700_badfile.dat



Countermeasure

Uninstall from Program Files
Running updated antivirus


Related information

Litter Korean rogue lurking I
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!
Pirated Edition. Affiliate program Pay-per-Install
Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI 

Ver más

Litter Korean rogue lurking I

Language issues are not limited to developers of malicious code and the objectives of the criminals are far beyond any border, and although it is usually the largest flow of varieties are in English and, to a lesser extent Russian every now and then the guns are aimed at specific audiences, as in this case: Korean rogue.

MegaVaccine
megavaccine.com - 218.146.255.151 - KORNET KOREA TELECOM

The IP is also the following domains:
goodprivacy.co.kr
megavaccine.com
pc-privacy.co.kr
pc-up.co.kr
pcsweeper.co.kr
pctool.co.kr
privacyboan.com
privacyq.com
rprotect.co.kr
uprivacy.net
wowprotect.co.kr

megavaccine_setup.exe (2234041b04e072aa7585209fa66e8550)

down.megavaccine.com/autoupdate/MegaVaccine/MVaccine.exe
down.megavaccine.com/Update_db/addb.dat
down.megavaccine.com/Update_db/adsub.dat
down.megavaccine.com/Update_db/adtc.dat
down.megavaccine.com/Update_db/avmon.dat
down.megavaccine.com/Update_db/inter.dll
down.megavaccine.com/Update_db/pwdb.dat
down.megavaccine.com/Update_db/vsdb.dat
down.megavaccine.com/Update_info/2010081900-00-.txt
down.megavaccine.com/Update_ini/MegaVaccine/autoupdate.ini
down.megavaccine.com/app/weboard.html

Countermeasure

Uninstall from Program Files
Running updated antivirus


Related information
PC Defender Antivirus rogue update system registry
Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Desktop Hijack by Internet Security 2010. Your System Is Infected!

Ver más

8.11.2010

PC Defender Antivirus rogue update system registry

The criminals who are behind the development of PC Defender Antivirus rogue in the last few hours have updated the registration system for the false application.

The record in the first version was to send a text message SMS rate telephone number located in Russia, while this new version requests a serial number (supposedly under the hardware-locked system) generated using as part of a activation key.

It also adds a button (Buy) that redirects to a form hosted on Plimus, and updated the malware into English. The first version was only in Russian.

This action makes it quite evident that behind the spread of these threats, lies across an organization intended to develop malware to accommodate an underground economy that feeds, increasingly, fraudulent methods.

Ver más

Phoenix Exploit's Kit and Pay-per-Install via PC Defender Antivirus

Pay-per-Install is one of the business models by which an affiliate system provides a set of "clients" one or more malicious code, paying each a percentage of money as a commission for each installation the malicious application successful.

Phoenix Exploit's Kit is a crimeware by which intelligence is done collecting statistical information related to each of the infected computers. You enter through an access panel via the http protocol as we see in the screenshot.

PC Defender Antivirus is a rogue Russian origin whose spread is being made through Phoenix Exploit's Kit, reporting at the same time to an affiliate system that records the installation of each downloaded copy.

In addition to collaborating with the criminal circuit feeding back the fraudulent business through Pay-per-Install, the rogue has the grain of usual business whereby it’s intended that the fraudulent application is purchased, also via the web, this action involving form information stored somewhere confidential credit card. The cost of the rogue is USD 59.95.

Through Phoenix Exploit's Kit spreads a trojan downloader called exe.exe, in this case MD5 e49be7ef82250a36cf7410004ac3d69c that, after it establishes a connection to fordkaksosat.info (193.105.207.45 - AS50793 "ALFAHOSTNET") from which it downloads and executes the rogue (PCDefenderSilentSetup.msi - ecff63c1f983858dfd7fb926738cb478).

In this instance, the rogue is reported to the affiliate system to load the information on successful installation through count_installs.php file, and begins a malware scan issuing alerts about alleged attempts to connect infections and also false. This activity is usual in this type of malware to be one of their employers.


The release system for the alleged security application is similar to that used by some families of ransomware through the business model that involves sending a text message SMS to a specific type of phone number.

In this case, the information should be sent to the number 5711000002209 with the message 6681.


The threat has a timer which generates a false statement Blue Screen of Death (BSoD), in which shows the incentive to record the program, exerting a fear (psychological warfare) on the user that after reading this information might think register/buy what you think, this is a real antivirus solution.


Countermeasures
Terminate the processes called prockill32.exe, proccheck.exe and rundelay.exe. You can use the ProcessExplorer to view and terminate processes.

Remove PC Defender folder (which houses six files) located in C:\Program Files\Def Group\

Delete the system registry PC Defender key from HKLM\SOFTWARE\Microsoft\Windows\ CurrentVersion\Run, which refers to c:\program files\def group\PC Defender\pcdef.exe. You can use the Autoruns to view and delete the key.

Related Information
New variant of ransomware through porn sites IV
New variant of ransomware through porn sites III
New variant of ransomware through porn sites  II
New variant of ransomware through porn sites
Dangerous trojans, keyloggers and Spyware detected in you computer!!!
Another very active SMS Ransomware
SMS Ransomware for Windows In-the-Wild
Desktop Hijack by Internet Security 2010. Your System Is Infected!
LockScreen. Your computer is infected by Spyware!!!

Ver más

3.13.2010

Dangerous trojans, keyloggers and Spyware detected in you computer!!!

This is a new variant of ransomware that is In-the-Wild with, so far, a poor detection rate, the report from VirusTotal. Only 9 of 42 detected by antivirus engines.

It's a technique used by some scareware aggressive to try to "compel" the victims to "buy" the alleged antivirus solution is, in fact, the scareware.

In this case, the malware is hidden under a file called avlck.exe (md5: 04cb597a4ffddfbae9a76cde53833ab7). When run blocking access to the system screen showing the image above position which is expressed in an alleged problem of infection.

In that instance the malware connects to the site


Make a copy of itself into the Windows System folder under the name myserv.exe, and a reference in the registry Run key.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KeyMy c:\windows\myserv.exe 

Countermeasures

Restart in Safe Mode and delete the file myserv.exe found in the Windows folder.
Delete the reference KeyMy (c:\windows\myserv.exe) located in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Unlock the system to any of the following keys:

PozisyonAyarla
HerZamanUstte

Related information
SMS Ransomware for Windows In-the-Wild
LockScreen. Your computer is infected by Spyware!!!

Ver más

12.26.2009

Desktop Hijack by Internet Security 2010. Your System Is Infected!

The Desktop Hijack is to "hijack" the desktop background, changing the image and blocking its configuration defined in a way that this can not be restored. This is a clear indication that the system was the victim of a malicious code, a kind of rogue, also known as scareware.

Internet Security 2010 is a rogue who performs this activity. The same is distributed through a crimeware called Siberia Exploit Pack. Below is a screenshot of the Desktop Hijack.

When this malware infects your system, then block the Desktop background settings, installs in the Program Files folder. This threat is aimed at Windows platforms infection in English, so that those who have Spanish versions aren't affected. We then see a screenshot of the interface of the rogue.

Each particular seconds, deploy dissuasive actions designed to generate "fear" in the user through warnings about malicious activity generated by alleged infections. Some of the warnings are:

In order for the user, looking for a solution to the alleged problems of infection, finish buying the full version of the antivirus program. To which, in this instance, you must access via a web form from which you request the "product", even, in some cases you may find advice in real time.

This modus operandi is common and is a rogue employer, including "purchase form" that in many cases until they are supported by https. In this case, Internet Security 2010, is marketed at a cost of nearly USD 50, so if you believe that its spread is related to a botnet, is easy to deduce the amount of money that criminals get through this type of activities.


Countermeasures
Terminate the processes called winupdate86.exe and IS2010.exe (eventually you can find the process winlogon86.exe).
NOTE: The malware can deshactiva conventionally access to cmd, registry and the Task Manager, therefore, to complete the process easily recommend using Process Explorer.

Then, access the system registry and delete the following keys:
In HKLM\Software\Microsoft\Windows\CurrentVersion\Run delete the key Internet Security 2010.
Under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run delete the key winupdate86.exe.
Under HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\Userinit change the call reference that points to C:\WINDOWS\system32\winlogon86.exe with C:\WINDOWS\system32\userinit.exe.

Unregister the dll call winhelper86.dll
NOTE: To perform this action you must access the Start/Run/cmd and type regsvr32 /u [dll name].

Delete the folder InternetSecurity2010 located at C:\Program Files, and files 41.exe (this number may vary found files with numeric names such as 5705.exe, 28145.exe, etc.), winhelper86.dll, winlogon86.exe and winupdate86.exe found in C:\WINDOWS\system32\.

Remove also the direct link called Internet Security 2010 which is on the Desktop and reboot the machine.

Install and run an updated antivirus

Malware Disasters Team

Ver más