MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.

3.05.2010

Another very active SMS Ransomware

Ransomware activities originating with Russia don't stop. Constantly looking for committing fraudulent business feeding the information located in the system.

In this case, it's another ransomware that is In-the-Wild, and its detection rate is very low.

When the malicious binary is executed, it causes an alleged error in IE.

Just create a plain text file called xFoLOOOSErs.txt with the following information:

installed
19793214

And creates a registry key.

The number stored in this file corresponds to the telephone number the user must send an SMS to unlock the system. However, this is not the only number that uses the cyber criminal, and that also can display the following:

1971482
19777877
197852
197971412

Furthermore, the number of activation may vary between:

5370
5373
7250

Technical data:
MD5: 0cc435c5bfe3444ce7151f8f2a319728
SHA1: 9c00c70b220da9b59fc9be55d37d7a1f94abb2e0
File size: 71168 bytes
Packer: -

Countermeasures
For any telephone numbers used by this variant of ransomware and above can use any of the following codes:

0000000
1973143

Maintain updated antivirus program.

Related information

Ver más

SMS Ransomware for Windows In-the-Wild

Within the criminal business of the malicious code, a variant of well-known are the strategies implemented by ransomware malware type, where the main objective is financial gain in exchange for the return of something maliciously "hijacked".

In this case, it's the operating system crash by a malware Russian origin. According to the nomenclature of antivirus companies, the same is detected under names alluding to Blocker (Comodo/Fortinet/Kaspersky), LooksLike (McAfee), LockScreen (ESET), Fraud (Avast), Winlock (DrWeb), Dunik! Rts ( Microsoft).

Malware pretends to be the executable to install Flash Player using a file called install_flash_player.exe (ff27289c8a5ac530ce876bc08fe45f1e).

However, to be executed, the operating system crashes through a window, which is expressed in the Russian language (a feature which indicates its orientation toward the Russian audience) the order to send a text message SMS to a particular type phone number to get the unlock key.

Generated in the folder %temp% the files asd [x].cbt (D6110298A4E241BE6E7031ADA220BACC) and asd[x].tmp (this is a MZ file) (5E9C2819DA8463278F0CFA3C1CCAFF70), where [x] is a random number, found under the nomenclature Ransom PogBlock by some AV companies. The latter is the binary that controls the pop-up blocking system.

The ransomware disables the Task Manager and blocks the ability to access the system in Safe Mode by generating a reboot loop through a BSoD.

This activity is under the framework of the business of criminal malware itself, which the malware author attempts through the cost benefit that requires the sending of SMS. A more within the criminal world of crimeware that even if it's addressed to the Russian public, constitutes a serious threat to any system.

Countermeasures
Restart in Safe Mode.
Delete the file asd[x].tmp alocated in %temp%.
Delete the following registry key:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
c:\documents and settings\administrador\configuración local\temp\asd1.tmp
Maintain updated antivirus program.

The easiest part. Unblock with any of the following keys:

code:592100041 unlock:2002972524
code:592131650 unlock:3807350716
code:592108426 unlock:2111921530
code:592128602 unlock:838761711
code:592122374 unlock:4272582034
code:592100773 unlock:3071200006
code:592109181 unlock:2803729885
code:592109325 unlock:1494973728
code:592129826 unlock:3062337563
code:592105732 unlock:2478558886

Note: Should appear on your display a different number for those exposed, send an email to with the number disastersteam[at]malwareint[dot]com to receive the unlock key.

Related information
LockScreen. Your computer is infected by Spyware!!!

Ver más

2.24.2010

SpyEye Bot (Part two). Conversations with the creator of crimeware

In recent weeks, SpyEye (a new financial trojan) has been the talk of many for the positive acceptance was so in the underground scene due to its balance about cost/benefit, and the great impact that achievement to whiten the features in its latest version that allows systems to eliminate the activities of your competition: ZeuS.

Our previous report, “SpyEye. Analysis of a new crimeware alternative scenario,” addressed known technical issues involving the activities of this threat.

In this second part we present the exclusive interview by Ben Koehl, Crimeware Researcher of Malware Intelligence. Through interviews with the creator of crimeware, we reveal information that shows some of the thought process and brains behind the creator of SpyEye. We also see the source code for the Zeus Killer addition.

The way that Gribodemon thinks is not unique anymore in the cybercrime world. We are seeing individuals and groups becoming more specialized in the services they provide and are no longer spreading themselves thin. There are many industries within the cybercrime world. From coding to infrastructure support to public relations.

There was a large language barrier between me and the author so I had to keep the questions short and basic so his translator program could handle them (Lingvo.) We broke up the conversation in pieces to make it flow better to the reader.

This document can be downloaded from:

English version
Spanish version

Related information
SpyEye Bot. New bot on the market
Compendio Anual de Información. El crimeware durante el 2009

Jorge Mieres

Ver más

2.10.2010

SpyEye Bot. Analysis of a new alternative scenario crimeware

Earlier this year saw the light in the underground black market that moves the axes of crimeware, a new application designed to provide feedback for criminal and fraudulent business.


This application, called SpyEye, is aimed at facilitating the recruitment of zombies and managing your network (C&C - Command and Control) through management panel via the web, from which it is possible to process the information obtained (intelligence) and stored in statistics, a common activity of criminal packages today.

Depending on their characteristics, very similar to those proposed by his counterpart ZeuS, SpyEye is presented as a potential successor to this within the scenario crimeware. Furthermore, it is evident that the criminal activities now represent a large business where cyber criminals and would-be cyber criminals abuse their "kindness".

This document describes the activities of SpyEye from the stage of infection giving relevant information about their purpose.

The full document can be downloaded from:

Spanish version
English version

Related information
Compendio Anual de Información. El crimeware durante el 2009
SpyEye Bot. New bot on the market

Jorge Mieres

Ver más

1.05.2010

Crimeware in 2009

"Crimeware in 2009" presented in one document all that was channeled through this blog during the year in question on crimeware and associated hazards.

There are a total of 262 pages and is divided by the most relevant topics that describe the criminal activities that were a source of news on this blog. Has two indices for getting the news in a simple (content) and another on the images (image index).

Then let some of the themes they found in the document in question:

  • Current business outlook caused by crimeware
  • Framework Exploit Pack for botnets general purpose
  • Framework Exploit Pack for botnets particular purpose
  • Services associated with crimeware
  • Intelligence in the fight against crimeware
  • Campaigns of spread and infection
  • Other Exploits packs that were investigated
Short information
Malware Intelligence
Annual compendium of information. Crimeware in 2009
262 pages
Spanish language

Download


Jorge Mieres

Ver más