MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.
Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

1.30.2011

Big Brother Brazil 2011 (AKA BBB 2011) malware attack

Big Brother 2011 (AKA BBB 2011) begins in Brazil and it's a motivation for social engineering attacks.

Big Brother Brasil 2011 began on January 11th in Brazil and malware authors should be celebrating, thus, because this is something very popular so it's easy to attract victims (via social engineering) to 'see' videos or pictures of the BBB 2011 participants.

We will show you a threat which came in form of a phishing and using social engineering ask recipients to click in a link in order to watch a video of a transsexual which is making the man's participants of the BBB 2011 confused.

As you can see on the original e-mail below, the attacker uses a technique known as DHA (Directory Harvest Attack) against the @hotmail.com domain in order to send the phishing message to valid e-mail addresses.



Note that when you move the mouse to the link which appears that will get you to the youtube.com, on the status bar you can see that it will not get you to the youtube.com website. It will get you to the website hxxp://twurl.nl/rbpm6s.

Below you have the source code of the phishing message:

----------------------------------------------------------------
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtTQ0w9Ng==
X-Message-Status: n
X-SID-PRA: globo.com (BBB 2011)
X-SID-Result: Fail
X-DKIM-Result: None
X-AUTH-Result: FAIL
X-Message-Info: DkpufaDli9Iih8M1I3rOCBHB3/E1htFb2qXrXVLfpfjlNFuHVG90WYrx2zq5Mw1fmsHKOjL4weQGCOatyx0Pn7FYN0czafnY9kSTqtv24cY=
Received: from wl01.ws.poa.ige ([201.94.125.1]) by col0-mc3-f16.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
     Tue, 18 Jan 2011 10:21:08 -0800
Received: from wl01.ws.poa.ige (dcrs8211 [127.0.0.1])
    by wl01.ws.poa.ige (8.13.8/8.13.8) with ESMTP id p0IH1auJ030937;
    Tue, 18 Jan 2011 15:01:36 -0200
Received: (from httpd@localhost)
    by wl01.ws.poa.ige (8.13.8/8.13.8/Submit) id p0IH1ZXl030933;
    Tue, 18 Jan 2011 15:01:35 -0200
To: baa@hotmail.com, bbb@hotmail.com, bcc@hotmail.com,
bdd@hotmail.com, bee@hotmail.com
Subject: ariadna (transesual) no bbb 2011 deixa homens confuso....
X-PHP-Script: mylove2010.info/catastrofe/feed10.php for 187.57.247.86
Date: Tue, 18 Jan 2011 15:01:34 -0200
From: "globo.com (BBB 2011)"

Reply-to: "globo.com (BBB 2011)"

Message-ID: <63a5faa6442cd3b2f870f2ac7a99bde7@mylove2010.info>
X-Priority: 3
X-Mailer: Microsoft Outlook Express 6.00.2800.1409
X-MimeOLE: Produced By Microsoft MimeOLE V6.10.2800.1409.1718742875.rg.sm31
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="iso-8859-1"
Return-Path: httpd@wl01.ws.poa.ige

----------------------------------------------------------------

As you can see on the source code, this phishing message involves three main characteristics:

  1. A file named feed10.php
  2. A file named ariedina.jpg3
  3. A link pointing to the website hxxp://twurl.nl/rbpm6s.
 
Analyzing the file feed10.php
I have downloaded this script page by using the webget utility. See the screenshot below:

wget -v mylove2010.info/catastrofe/feed10.php


As you can see above, this is a smtp engine used by this threat. Just in case I have submitted this PHP script to virustotal and you can see the results. This sounds a true smtp engine script, so there is no malware associated to this program, while it might be used by malwares.

Analyzing the file ariedina.jpg3

This is just a picture which is used to attract people to click and see a 'video' at youtube.com, however, as you can see on the source code there is a HREF instruction so when the user clicks on this picture (anywhere) it will get the user to the malicious website: hxxp://twurl.nl/rbpm6s

I have downloaded this picture so I could analyze it and saw that it's really just a picture:

wget -v http://lh4.ggpht.com/_FJQwbg0nrOk/TTGRJVC1KtI/AAAAAAAAAMs/CUvYCECUkhM/ariedina.jpg3



I have submitted this file to the virustotal website so you can get the report using the link below. There are no detection since this is just a picture.

Analyzing the link hxxp://twurl.nl/rbpm6s

Using wget pointing to the URL hxxtp://twurl.nl/rbpm6s resulted in downloading a file named youtube_video756.exe.

wget -v http://twurl.nl/rbpm6s

Analyzing youtube_video756.exe

After submitting this sample to virustotal you can see that some AV vendors detects this threat. Some of them using signatures and a couple of them using a in-cloud technology.

If you run youtube_video756.exe, it will basically perform the following activities:

Create a copy of itself using a file named Recorte de tela e Iniciador do OneNote 2007.exe on the folder "C:\Documents and Settings\%user%\Start Menu\Programs\Startup\". This process is then launched.

It connects to the ftp site ftp.biancarox.net using the username cohabrox and a password which will not be reported here just in case. It downloads 10 files (listed below) to the folder C:\documents and setings\%user%\. While all of these files have a .txt extension, they are not a true .txt file. Looking at its strings you can see that they are really executables.


Taking a look at the process strings (below), we can see several internet bank sites of Brazil and two webmail websites.



When you open Internet Explorer and type one of the target URLs, like www.bradesco.com.br (which is a true bank of Brazil), it will kill iexplorer.exe and will load a new process C:\Document and Settings\%user%\®¢Ÿª¤ª¥ž¥.txt. If you type anoher URL on the IE address bar like www.bradescoprime.com.br, another process will be launched on this case it would be the ®ž“§«š§«š.txt.

This process is a fake application which emulates the requested website and it will capture your bank agency, account, token, passwords, etc. See screenshots below:



While you are typing your bank agency, account, password, token, etc, the trojan is capturing everything and is written it to a *.bsp file on the C:\Documents and settings\%user%\. Below you have an example:


Indicators of compromise

Check for the existence of the following MD5 on the C:\Documents and Settings\%user%\.

  • edaa81ad2165c65bb340e636bf642291
  • b82c51f94b0e516f461b6f84a668dfde
  • 76184bebea96f59086368b64a896d224
  • f590d18d7b50109c03c6237d86e8415d
  • 52ea037028eb2274147aef1edfb64865
  • daa21069ae179cc0f195cd42795b592b
  • 86802efad8fb5b8153d7c7de67cb66bb
  • fc7592c9f2e2264c687a806459387d30
  • 9547ff6be241b5bb8a87f0dabe3b3218
  • 5cd6a3ac2b2d97e36091a1ecd2fd0aec
Check if the process Recorte de tela e Iniciador do OneNote 2007.exe is running or present on the folder C:\Documents and Settings\*\Start Menu\Programs\Startup\ (it's MD5 is d34c8d3ad55f65d701264a5e8e278915)

Network connections to:

  • hxxp://mylove2010.info/catastrofe/feed10.php
  • hxxp://twurl.nl/rbpm6s
  • hxxp://livinianot.com.br/
  • ftp.biancarox.net
Below you have a report from VirusTotal regarding the samples that we have analyzed here:


id=968db70645fceeb734ba941ee78d51848057762b0559709238c59d4391d1c25e-1295986300
id=961a9c536b98d02172eb48bd2e0e4881591ac1eb607bf1ea7f267f4994c6b6f6-1295986210
id=e6a33cbba7e6348c41cb7e10acac4efaf47286603d54d1c7088f8772bb0f23e8-1295986257
id=4e908de9a38bb3b90435b0d8b733ad11836a8f65bff2cd6cd247fd47a332af16-1295996254
id=d12ef9562f2deae6ef8e7d5842bf1f1425fc23ce7b6c2265a62189eac14e966f-1295985855
id=8d1a2ece03010fe9610c852a70d13c22f9e91d93e39abc939a742d84b279ea64-1295996475
id=457278ad3bc382dd5159c0be8e9f2f2e3e1cf9191861b56497c81f21f423808d-1295996615
id=55d9afec1ad24fcfec03f03cbc7be9b6c21a614db87432e925cdc8112c551c5e-1295996949
id=73cc47196be7bd8c0f7764a46cb4488266bef2ea1ffccbdbd91cd0b62c79919d-1295997136
id=26f542326786e4facd624fcb170a71c6a2e709e23c8f4cffa4715e133869316b-1295980568
id=8f5c8ad99ded74d3cc233b691a803fc6f00ac3113ad67c6f6802ac3ea0f727fc-1295389644

Bruno Caseiro
Malware Researcher

Ver más

3.13.2010

Dangerous trojans, keyloggers and Spyware detected in you computer!!!

This is a new variant of ransomware that is In-the-Wild with, so far, a poor detection rate, the report from VirusTotal. Only 9 of 42 detected by antivirus engines.

It's a technique used by some scareware aggressive to try to "compel" the victims to "buy" the alleged antivirus solution is, in fact, the scareware.

In this case, the malware is hidden under a file called avlck.exe (md5: 04cb597a4ffddfbae9a76cde53833ab7). When run blocking access to the system screen showing the image above position which is expressed in an alleged problem of infection.

In that instance the malware connects to the site


Make a copy of itself into the Windows System folder under the name myserv.exe, and a reference in the registry Run key.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KeyMy c:\windows\myserv.exe 

Countermeasures

Restart in Safe Mode and delete the file myserv.exe found in the Windows folder.
Delete the reference KeyMy (c:\windows\myserv.exe) located in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Unlock the system to any of the following keys:

PozisyonAyarla
HerZamanUstte

Related information
SMS Ransomware for Windows In-the-Wild
LockScreen. Your computer is infected by Spyware!!!

Ver más

3.05.2010

Another very active SMS Ransomware

Ransomware activities originating with Russia don't stop. Constantly looking for committing fraudulent business feeding the information located in the system.

In this case, it's another ransomware that is In-the-Wild, and its detection rate is very low.

When the malicious binary is executed, it causes an alleged error in IE.

Just create a plain text file called xFoLOOOSErs.txt with the following information:

installed
19793214

And creates a registry key.

The number stored in this file corresponds to the telephone number the user must send an SMS to unlock the system. However, this is not the only number that uses the cyber criminal, and that also can display the following:

1971482
19777877
197852
197971412

Furthermore, the number of activation may vary between:

5370
5373
7250

Technical data:
MD5: 0cc435c5bfe3444ce7151f8f2a319728
SHA1: 9c00c70b220da9b59fc9be55d37d7a1f94abb2e0
File size: 71168 bytes
Packer: -

Countermeasures
For any telephone numbers used by this variant of ransomware and above can use any of the following codes:

0000000
1973143

Maintain updated antivirus program.

Related information

Ver más

SMS Ransomware for Windows In-the-Wild

Within the criminal business of the malicious code, a variant of well-known are the strategies implemented by ransomware malware type, where the main objective is financial gain in exchange for the return of something maliciously "hijacked".

In this case, it's the operating system crash by a malware Russian origin. According to the nomenclature of antivirus companies, the same is detected under names alluding to Blocker (Comodo/Fortinet/Kaspersky), LooksLike (McAfee), LockScreen (ESET), Fraud (Avast), Winlock (DrWeb), Dunik! Rts ( Microsoft).

Malware pretends to be the executable to install Flash Player using a file called install_flash_player.exe (ff27289c8a5ac530ce876bc08fe45f1e).

However, to be executed, the operating system crashes through a window, which is expressed in the Russian language (a feature which indicates its orientation toward the Russian audience) the order to send a text message SMS to a particular type phone number to get the unlock key.

Generated in the folder %temp% the files asd [x].cbt (D6110298A4E241BE6E7031ADA220BACC) and asd[x].tmp (this is a MZ file) (5E9C2819DA8463278F0CFA3C1CCAFF70), where [x] is a random number, found under the nomenclature Ransom PogBlock by some AV companies. The latter is the binary that controls the pop-up blocking system.

The ransomware disables the Task Manager and blocks the ability to access the system in Safe Mode by generating a reboot loop through a BSoD.

This activity is under the framework of the business of criminal malware itself, which the malware author attempts through the cost benefit that requires the sending of SMS. A more within the criminal world of crimeware that even if it's addressed to the Russian public, constitutes a serious threat to any system.

Countermeasures
Restart in Safe Mode.
Delete the file asd[x].tmp alocated in %temp%.
Delete the following registry key:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
c:\documents and settings\administrador\configuración local\temp\asd1.tmp
Maintain updated antivirus program.

The easiest part. Unblock with any of the following keys:

code:592100041 unlock:2002972524
code:592131650 unlock:3807350716
code:592108426 unlock:2111921530
code:592128602 unlock:838761711
code:592122374 unlock:4272582034
code:592100773 unlock:3071200006
code:592109181 unlock:2803729885
code:592109325 unlock:1494973728
code:592129826 unlock:3062337563
code:592105732 unlock:2478558886

Note: Should appear on your display a different number for those exposed, send an email to with the number disastersteam[at]malwareint[dot]com to receive the unlock key.

Related information
LockScreen. Your computer is infected by Spyware!!!

Ver más

12.15.2009

LockScreen. Your computer is infected by Spyware!!!

LockScreen is a trojan designed to block access to the operating system as a primary resource using the fear factor.

First, when activated displays a warning about an alleged infection caused by spyware, inciting to buy an antispyware which is really other malicious code. On the other hand, states that "if not eliminate spyware from the system in three hours, will be formatted".

Thus, the user victim of this malicious code will be forced to take extreme measures to try to access the operating system, or accept the purchase of a false solution to get the unlock key.

This activity is typical of the concept ransomware, which produces the "kidnapping" of the operating system or part thereof, but through more complex processes which usually involves some encryption algorithm and the "payment" (usually money) to obtain the unlock key.

Although malware isn't a complex, currently has a low detection rate, being detected only by 11 antivirus companies a total of 41, as shown in the report of VirusTotal.

Technical Data
MD5: f3a7d1054e79dda8e8a16901d95770e1
SHA1: c1887445b1fd5d89f61e638231d554c5bcff49ab
File size: 32768 bytes
Packer: -

Countermeasure
Restart the computer in Safe Mode Errors (by pressing the F8 key during startup) and delete the file "benimserverim.exe" which is hosted in the Windows folder.

Then clean the system registry by removing the key "benimAnahtar" from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

In case you can not restart the computer in Safe Mode Errors, another alternative is to restart the computer and for the moment, after the inception of the desktop is displayed, quickly press the Ctrl + Alt + Del to access the Task Manager and end the process called "Project1".

Then delete the file "benimserverim.exe" hosted in the WINDOWS folder and the registry key "benimAnahtar" found at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

Or... the password required to unlock the system is DosyaYolu.

Malware Disasters Team

Ver más

12.14.2009

Waledac/Storm. Past and present a threat

At the beginning of 2007 jumped from the darkness to begin a malicious code to be a source of important news because of their particular strategies of deception and a major campaign at the global level of infection that still remain a subject of research by the community security.

This is Storm, aka Nuwar or Zhelatin depending on the identity assigned by the antivirus companies, although it's known as "storm", perhaps alluding to the manner in which systems ravaged by which he transformed into zombies, recruiting teams under the command of the botnet.

At present, the threat posed Storm hasn't been to one side, but transferred to its twin brother, Waledac, which remains essentially the characteristic of trying to innovate in terms of apology necessary for the spread and recently has awakened after a period of hibernation.

Some features of this threat are:

The spread is through the unwanted e-mail (spam)
Uses deception strategies (Social Engineering) different for each campaign to spread
Through a link embedded in the body of a message routed to a site where malware is downloaded
The infected computers are part of a botnet
To complete the cycle of infection through the spread of spam
Fast-Flux networks
They have polymorphic capabilities at the server level

During virtually the entire 2007, Storm (the first appearances as a strategy of deception used to display a video on a storm unleashed in Europe) used as a means of propagation/infection e-mail with questions and topics varied inciting to click on a link embedded in the message body, which in some cases direction of a page (some of them also tried to spread Storm exploit vulnerabilities using iframe tags as resources) and others directed to the download of a binary in Storm both cases.

Already for next year (2008), Storm joined the "surprise effect" linking the e-mail link provided to a web site that accompanied the excuse presented in the case of mail with an image alluding also to the theme that, the as in 2007, rotating with each major event (Valentine's Day, Independence of the USA, Christmas, etc). In addition, some variants spread through blogs.

After several months of inactivity in terms of the spread of the threat, in January of this year appears Waledac, a trojan that uses the same mechanisms used by Storm and many security professionals are beginning to see the similarity between them.

After several investigations, says that Waledac is, one might say, the twin brother of Storm. Using the same methodologies of Social Engineering with a broad portfolio of images and themes used as an excuse to capture users' attention. Passing through images rather the typical "love" for the month of Valentine Cases of alleged terrorist attacks, among others, to the recent course on a video on YouTube.

There are, among others, two very interesting features in both Waledac Storm: the use of Fast-Flux networks and polymorphic capabilities on the server.

The first of these threats were allowed to spread across different IP addresses and using different domain names that constantly rotate between each other with the name resolution. This causes, through a certain time to live (TTL) pre-configured every x amount of jumps between nodes (infected computers) from the same domain, you download a different prototype of malware.

This leads to the second feature, the polymorphism. In this way, each time the package (malware) is established TTL attempt to download a different version of the malicious code to be "changes" every certain amount of time (also predetermined by the attacker) establishing capacity polymorphic.

The diagram below provides the direct relationship, over time, the threat was used as a strategy of deception.

Each of the zombies that are part of the botnet created by Waledac, focus your intentions in sending spam. In this sense, a very interesting extract from a report that says Waledac has the ability to send about 150,000 spam emails per day.

Perhaps, then you know that Storm/Waledac are running campaigns with high rates of spread of infection globally and overcrowded, it's clear that their creators are continuing their criminal operations for a financial issue, which is nothing new for malware today.

via Pistus Malware Intelligence Blog
Malware Disasters Team

Ver más

12.05.2009

Swizzor reload. Adware and control of P2P networks

P2P networks are one of the sources used to propagate different types of malicious code. That makes him very dangerous vector for those who don't take into account certain preventive measures.

Moreover, the main function is to deploy adware popups displaying advertising without us even asking him many times after infection, it can display advertising even when a connection is made.

This is an increasingly common case where different types of malware interact with each taking control of the computer to download and install additional malware.

Nomenclature: NSIS/TrojanDownloader.Swizzload.A (ESET)
Md5: e2a2089255811ff295cdb695e426adc4
Sha1: 99eccdc87671138b9f4b15b0610bef8a3df418b6
Report VirusTotal 15/41 (36.59%)
Packer: NSIS

It spreads through web pages using a strategy of social engineering. When run a number of file download from which there is an update of itself.

From install.x3codec.com/get_file.php?file=program&program=codec_x3 download:

Nomenclature: -
File: x3codec.exe located in codec_x3.zip
Md5: 06579ded81b2b648c5106d4732a4b06f
Sha1: a2d05264eeb807e5fadd3bd60df3c0b6495c5a75
Report Virus Total 0/41 (0.00%)
Packer: -

From install.x3codec.com/get_file.php?file=program&program=p2pc download

Nomenclature: Trojan-Dropper.Agent (Ikarus)
File: p2pc.exe alojado en p2pc.zip
Md5: 9964ee2867cb2128c8f3c84b311bdb86
Sha1: a83edbe783856edf5c1838e2e1f9df9bca6ea6f2
Report Virus Total 3/41 (7.32%)
Packer: NSIS

Nomenclature: Downloader.Agent (Ikarus)
File: VistaPutcher.exe alojado en p2pc.zip
Md5: c899655cf6c26eadcd4f8adbc32d7da6
Sha1: f316b3d09519cb73b512a58be6b7b688374839eb
Report Virus Total 9/41 (21.95%)
Packer: NSIS

After checking a number of information in the system makes the connection against connect.p2pcontrol.com/?command=install&uid={EE72CD72-7427-E246-A983-AF903B5DEC0E}&affid_tr=&os=XP where down the instructions to install the programs.

The aim is to control the downloads through P2P networks by establishing a number of eDonkey servers and Kademila.

From http://connect2.p2pcontrol.com/?command=download&filename=known_e.met establishes the following servers:

  • 208.53.131.220:4662
  • 208.53.131.221:4662
  • 76.73.89.210:61895
  • 208.53.131.220:27600
  • 208.53.131.221:7258
  • 76.73.77.66:52352
  • 76.73.77.66:53352
  • 208.53.131.221:4500

From install.x3codec.com/get_file.php?file=minime connects to http://space.cachefly.net/7714569/ and download the malware

Nomenclature: a variant of Win32/TrojanDownloader.Swizzor.NCV (ESET)
File: minime.exe
Md5: 898a21afe498579797e8bc8163f4b1e2
Sha1: 817f44e1fbf98f51f3266a35b246af757574ebd1
Report Virus Total 22/39 (56.41%)
Packer: -

It also installs adware, responsible for changing the settings of Internet Explorer and Firefox through the following lines:

[InternetExplorer]
MinVersion=6
HomePage=http://www2.iesearch.com/
DefaultSearchEngine=Ask
SearchUrl=http://www2.iesearch.com/s/?q={searchTerms}&iesrc={referrer:source?}
GuidHash=x3Codec-search

[FireFox]
MinVersion=2.0
HomePage=
DefaultSearchEngine=Ask
SearchUrl=http://www2.firesearch.com/s/?q={searchTerms}&src=FF-SearchBox



Some countermeasures


  • Uninstall programs Ask Search, P2PControl and x3Codec
  • Delete the folders option bird and x3Codec located in the Program Files
  • Delete entry inside eggs located in the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • Delete entry eggs joy math type located in the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Delete the folder option bird located in X:\Documents and Settings\Administrator\Application Data. This folder contains the files: SEEKOWNSMETA.exe [a variant of Win32/TrojanDownloader.Swizzor.NDE Trojan (ESET)]. borereadmebike.exe [a variant of Win32/TrojanDownloader.Swizzor.NCS Trojan (ESET)]. tfonuuvu.exe [E:\malware\not\tfonuuvu.exe - a variant of Win32/TrojanDownloader.Swizzor.NCY Trojan (ESET)]
  • Restart your computer
  • Delete the folder Bind army eggs joy located in Documents and Settings\All Users\Application Data
  • Change the start page in the browser and delete temporary files
  • Run your antivirus program updated

Malware Disasters Team

Ver más