Posts Tagged ‘security’
Posted by Steve Espino on November 3, 2009

MaCatte Antivirus is a rogue av that attempts to impersonate McAfee scanners in order to scam users, which PC Tools Spyware Doctor with Antivirus aptly detects as RogueAntiSpyware.MaCatte
This scareware has been seen to be using a bogus My Computer online scan similar to ones we’ve seen here, here and here.

The online scan can be seen on this url:
hxxp://proscan5.info/25/26-088wLzQzL1EzL==
The downloader being served from this url is time-sensitive and will not work after a period of time. A session ID of some sort is embedded on the binary executable itself. After such time has elapsed, the downloader tells the user to contact MaCatte Antivirus support people. This prevents reverse-engineers from replicating the infection and gathering samples for analysis.
Presence of these files / folders would signal infection from this scareware:
C:\Documents and Settings\All Users\Application Data\msca
C:\Documents and Settings\All Users\Application Data\msca\MaCatte.ico
C:\Documents and Settings\All Users\Application Data\msca\mcull.exe
C:\Documents and Settings\All Users\Application Data\msca\msc.exe
C:\Documents and Settings\All Users\Application Data\msca\Viruses.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Media\WPtect.dll
C:\Documents and Settings\All Users\Desktop\MaCatte.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte\MaCatte.lnk
Unsuspecting users are set back from their hard-earned money by a hefty $99.
Stay away from these rogue apps.
Posted in Uncategorized | Tagged: fake app, fake av, MaCatte, MaCatte Antivirus, macatte.com, McAfee, PC Tools, proscan5.info, rogue app, rogue av, RogueAntiSpyware.MaCatte, scareware, security, Spyware Doctor, Spyware Doctor with AntiVirus | 2 Comments »
Posted by Steve Espino on October 15, 2009
Here are some screenshots of the members of this scareware family:
![[gickr.com]_6c803672-8a5f-25e4-5109-31b55ebdf362 [gickr.com]_6c803672-8a5f-25e4-5109-31b55ebdf362](http://r3v3rs3e.files.wordpress.com/2009/10/gickr-com_6c803672-8a5f-25e4-5109-31b55ebdf362.gif)
Beware of these rouge apps.
Posted in Rogue Apps | Tagged: rogue app, rogue av, security, Sysguard, TrustCop, TrustNinja, Winifighter, WiniShield | Leave a Comment »
Posted by Steve Espino on October 13, 2009

Another scareware has been spotted in the wild and it calls itself TrustFighter. This is a recent addition to the Winifighter family of scareware.
Same as other members of this family of scareware, as in a previous post, TrustFighter creates heaps of junk binary files in the %systemroot% and %system% directories.
Sample junk files are the following:
%systemroot%\51c0vzr24975.dll
%systemroot%\51cbthreatz1991.ocx
%systemroot%\524699py69fz.bin
%systemroot%\525z1vi9us4e4.cpl
%systemroot%\5294viz115.exe
%systemroot%\5eddaddwar9167z.dll
%systemroot%\5ezast95l495.dll
%systemroot%\5ezdaddware2359.cpl
%systemroot%\5z09s9yware545.cpl
%systemroot%\5z56th5eat19149.bin
%systemroot%\5z85thief22759.cpl
%systemroot%\5z99addware2835.ocx
%systemroot%\5z9bba5kdoor525.dll
%systemroot%\5z9cth5ef13559.cpl
%systemroot%\5zfdaddware950.bin
%systemroot%\5zfesparse709.exe
%systemroot%\6169th5zf99.ocx
%systemroot%\6210spywa5e192z.ocx
%system%\1905szea51146.cpl
%system%\190979iru57z7.ocx
%system%\190cszywa591879.exe
%system%\19105vizus1c.bin
%system%\19179virusz65.ocx
%system%\1930thief97z5.cpl
%system%\19559spamboz6bb.ocx
%system%\1958stezl2595.cpl
%system%\195b5hreat39894z.exe
%system%\19645worm7zd.exe
%system%\1969spz715.bin
%system%\1977zhacktool54d.cpl
%system%\19792troz5aa.bin
%system%\1987th5z92904.cpl
Here are some domains participating in this campain:
securityannounce(dot)com
securityadjust(dot)com
bestmalwaredetect(dot)com
pcprotectzone(dot)com
trustfighter(dot)com
Unsuspecting users get set back by $49.95 from their hard-earned money.
PC Tools Spyware Doctor protects your computers from the scum of the universe (the digital universe) and aptly detects TrustFighter as RogueAntiSpyware.Winifighter.
Posted in Rogue Apps | Tagged: bestmalwaredetect.com, Malware Research Centre, MRC, pcprotectzone.com, rogue app, rogue av, RogueAntiSpyware.Winifighter, scareware, security, securityadjust.com, securityannounce.com, theatypxdd.net, TrustFighter, trustfighter.com, Winifighter | Leave a Comment »
Posted by Steve Espino on September 25, 2009
The analysts at the PC Tools Malware Research Centre have been receiving bogus emails claiming to be coming from Microsoft:
…public distribution of this Update through the official website »www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all users Microsoft Windows OS.
as the computer set to receive notifications when new updates are available, which you have received this notice.
We have seen emails containing one of the following links:
hxxp://www2.sinel.com/microsoftupdate.html
hxxp://mail1.e-corecorporation.com/default.htm
They seem to be compromized websites being used by the bad guys in order to facilitate this attack.
The page default.html from hxxp://mail1.e-corecorporation.com/default.htm uses a refresh-type redirect to this url:
hxxp://0xc0.0xdc.0x6e.0xe4/microsoftupdate.html
The page microsoftupdate.html from sinel.com and 0xc0.0xdc.0x6e.0xe4 both execute another refresh-type redirect in order to download a file named update09.exe, which PC Tools Spyware Doctor with Antivirus detects as Trojan-Spy.Zbot.YETH.
Interestingly enough, this attack uses 0xc0.0xdc.0x6e.0xe4 to serve the malware. This IP-address translates to 192.220.110.228, which in turn resolves to summit102.summitdesign.net, another possibly compromised website used in this attack.
The presence of the following files/folders may indicate signs of infection:
%System%\sdra64.exe
%Temp%\tmp.exe
%System%\lowsec\
More here.
Posted in Malicious Intent | Tagged: 0xc0.0xdc.0x6e.0xe4, 192.220.110.22, fake microsoft update, lowsec, mail1.e-corecorporation.com, Malware Research Centre, microsoftupdate.html, sdra64.exe, security, sinel.com, Spyware Doctor, summit102.summitdesign.net, tmp.exe, Trojan-Spy.Zbot.YETH, update09.exe, Zbot | Leave a Comment »
Posted by Steve Espino on September 18, 2009
The PC Tools Malware Research Centre has been seeing new movement on the koobface front Lately.

As koobface-serving domains are being taken down as early as the good guys discover them, the bad guys are at it and they respond by registering new ones. At the moment, their, C&C server is hosted in China with IP Address 61.235.117.83.
The bad guys are still using a fake facebook website, as well as posing as a fake codec, in order to distribute koobface.

Clicking anywhere on the page, presents us with a file named setup.exe. Here are some of the IPs being used to distribute koobface:

115.130.27.204
123.202.200.84
151.204.31.67
196.206.65.53
221.126.0.105
24.215.207.229
41.238.76.198
61.93.34.23
67.206.253.52
68.47.48.240
69.18.107.115
69.254.215.173
70.122.242.250
70.212.232.126
71.116.37.213
71.130.216.179
71.194.236.32
71.80.105.40
72.13.138.210
72.190.87.208
75.181.171.110
75.251.94.44
76.119.98.22
76.22.160.28
76.23.203.64
81.192.192.160
98.140.58.163
98.244.224.140
98.26.40.38
99.22.74.229
The javascript component being by used by koobface, remains bascically the same as before
And as before, koobface is still serving up scareware. From time to time, users are presented with a My Computer online scan, going through these domains:

gotrioscan(dot)com
plazec(dot)info
At some instances, we also get these warnings:


At the moment, these warnings are serving Internet Antivirus Pro.
In order to be protected against these attacks, users of PC Tools Spyware Doctor are advised to use the latest PC Tools update.
An earlier post about koobface can be found here.
Update:
Koobface has been going at it and here’s another one that spoofs youtube and serves koobface malware as a fake codec:
hxxp://71.197.170.226/d=www.marcellaburnard.com/0x3E8/view/console=yes/?go

Posted in Malicious Intent, Rogue Apps | Tagged: 61.235.117.83, 71.197.170.226, C&C, fake codec, fake video codec, Internet Antivirus Pro, koobface, KROTEG, Malware Research Centre, My Computer online scan, Net-Worm.Koobface, PC Tools, rogue, rogue app, rogue av, rogue domain, RogueAntiSpyware.InternetAntiVirus, scareware, security, setup.exe | 4 Comments »
Posted by Steve Espino on August 27, 2009
Another website has recently been spotted to be serving up malware in the guise of fake video codecs.
This one praises itself as “The Best Nude Celebrity Movie Site”
hxxp://alyssafan.net/1.html

But in order to watch the any video, we would need to download and install their “Certified ActiveX video codec (VAC codec) use to protect content Copyrights”
The fake fake codec can be downloaded here:
hxxp://alyssafan.net/Mediacodec_v4.8.exe
One of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.

This script translates to:

This script downloads:
hxxp://ue4x08f5myqdl.cn/u3.exe
Which then gives us scareware Safety Center:

Beware of fake video codecs!
Posted in Uncategorized | Tagged: alyssafan.net, fake alert, fake app, fake av, fake codec, fake video codec, Mediacodec, porn, rogue app, rogue av, Safety Center, scareware, security, The Best Nude Celebrity Movie Site, ue4x08f5myqdl.cn, video | 2 Comments »
Posted by Steve Espino on August 21, 2009

Scareware is BIG business. They use heaps of scare tactics in order to convince unsuspecting users into buying rogue applications. But here’s one that does a bit more than just scaring.
RogueAntiSpyware.System Security terminates almost all running processes. This basically prevents us from using our computers. More importantly, this hinders execution of tools necessary to investigate the infection and aid in removal of this rogue app.
Back in the day, in order to evade detection and removal, malware writers have targeted security-related applications. They have a black list of applications including (but not limited to) the following:
avast.exe
avp.exe
cmd.exe
icesword.exe
kav.exe
regedit.exe
taskmgr.exe
But now they block even the most harmless Windows applications such as calc.exe and notepad.exe. But not all applications should be terminated, because that basically means no Windows. No Windows means no profit so the bad guys need basic Windows functionality. Which tells us that they have probably stopped using blacklisting and shifted to whitelisting instead. They now have a list of applications that they would allow to be executed in the system.
Here’s part of some disassembly taken from a sample of RogueAntiSpyware.System Security, showing us evidence of whitelisting:
Rogue app takes a snapshot of all the processes in the system:
.rsrc:140B4B4F push edi
.rsrc:140B4B50 push 2
.rsrc:140B4B52 call CreateToolhelp32Snapshot
.rsrc:140B4B57 mov [ebp+hObject], eax
...
.rsrc:140B4B79 push ecx
.rsrc:140B4B7A push eax
.rsrc:140B4B7B mov [ebp+var_64C], 22Ch
.rsrc:140B4B85 call Process32FirstW
...
.rsrc:140B4BAB push [ebp+dwProcessId] ; dwProcessId
.rsrc:140B4BB1 push 0 ; bInheritHandle
.rsrc:140B4BB3 push 1FFFFFh ; dwDesiredAccess
.rsrc:140B4BB8 call ds:OpenProcess
It then terminates the processes not found in the white list:
.rsrc:140B4C00 push 0FFFFFFFFh ; uExitCode
.rsrc:140B4C02 push edi ; hProcess
.rsrc:140B4C03 call ebx ; TerminateProcess
and displays this message as a notification in the system tray:
.rsrc:14039998 aApplicationCan: ; DATA XREF: sub_140B4ADD+16A
.rsrc:14039998 unicode 0,
.rsrc:14039998 unicode 0,
.rsrc:14039998 dw 0Ah
.rsrc:14039998 unicode 0, ,0
.rsrc:14039A5E align 10h
.rsrc:14039A60 aWarning: ; DATA XREF: .rsrc:140104BF
.rsrc:14039A60 ; sub_140B4ADD+1DB ...
.rsrc:14039A60 unicode 0, ,0
.rsrc:14039A72 align 4

It then resumes processing the snapshot created earlier and the cycle continues:
.rsrc:140B4CDF lea eax, [ebp+var_64C]
.rsrc:140B4CE5 push eax
.rsrc:140B4CE6 push [ebp+hObject]
.rsrc:140B4CEC call Process32NextW
Here’s the list of applications that the scareware allows:
.rsrc:14046A48 off_14046A48 dd offset aAlg_exe ; DATA XREF: sub_140B49CF+26
.rsrc:14046A48 ; "alg.exe"
.rsrc:14046A4C dd offset aCsrss_exe ; "csrss.exe"
.rsrc:14046A50 dd offset aCtfmon_exe ; "ctfmon.exe"
.rsrc:14046A54 dd offset aExplorer_exe ; "explorer.exe"
.rsrc:14046A58 dd offset aServices_exe ; "services.exe"
.rsrc:14046A5C dd offset aSlsvc_exe ; "slsvc.exe"
.rsrc:14046A60 dd offset aSmss_exe ; "smss.exe"
.rsrc:14046A64 dd offset aSpoolsv_exe ; "spoolsv.exe"
.rsrc:14046A68 dd offset aSvchost_exe ; "svchost.exe"
.rsrc:14046A6C dd offset aSystem ; "system"
.rsrc:14046A70 dd offset aIexplore_exe ; "iexplore.exe"
.rsrc:14046A74 dd offset aLsass_exe ; "lsass.exe"
.rsrc:14046A78 dd offset aLsm_exe ; "lsm.exe"
.rsrc:14046A7C dd offset aNvsvc_exe ; "nvsvc.exe"
.rsrc:14046A80 dd offset aWininit_exe ; "wininit.exe"
.rsrc:14046A84 dd offset aWinlogon_exe ; "winlogon.exe"
.rsrc:14046A88 dd offset aWscntfy_exe ; "wscntfy.exe"
.rsrc:14046A8C dd offset aWuauclt_exe ; "wuauclt.exe"
As we can see, RogueAntiSpyware.System Security is more than just scareware. You won’t be able to properly use your computer unless you buy the rogue app. Sounds more like ransomeware to me.
But, now that we know that it uses whitelisting, we can do a little work around and bypass this technique. We can rename a copy of the tools that we need to run as one of the whitelisted applications and voila! We’ve already taken one step into regaining full use of our infected computer.
We have previously discussed RogueAntiSpyware.System Security being linked to Net-Worm.Koobface and a fake Facebook website at an earlier post.
PC Tools Spyware Doctor with Antivirus detects and removes RogueAntiSpyware.System Security.
Posted in Malicious Intent, Rogue Apps | Tagged: app, blacklist, Facebook, fake, fake alert, fake av, Net-Worm.Koobface, PC Tools, ransomware, rogue, rogue av, RogueAntiSpyware.System Security, scareware, security, Spyware Doctor, terminateprocess, whitelist | Leave a Comment »
Posted by Steve Espino on August 20, 2009

Another scareware has been spotted and it calls itself Windows Protection Suite.
You can get Windows Protection Suite from one of these urls:
hxxp://searchscanner.net/?p=WKmimHVlbXCHjsbIo22EfYCIt1POo22YXZmK0qR0qay9sYmbm5h2lpd9fXCHodjSbpRelWZsmGGZYWPMU9jSzKKsl3OWh9esb2VraWhpbWyWX5aMlJNq
hxxp://linewebsearch.com/?p=WKmimHVlbXCHjsbIo22EfYCIt1POo22YXZmK0qR0qay9sYmbm5h2lpd9fXCHodjSbpRelWZsmGGZYWPMU9jSzKKsl3OWh9esb2VraWhpbWyWX5aMlJNq
hxxp://linewebsearch.com/?p=WKmimHVlaGuHjsbIo22Eh4uLt1POo22eU9LXoKitiJ%2FY1cRflJ2dcZqTgX6YU9janW1eZWpslGGbZmGXkonZ0Zqop5uikomtpXFqZmxtbWmaYZyfV5OQcQ%3D%3D
hxxp://linewebsearch.com/build8_102.php?cmd=getFile&counter=1&p=WKmimHVlaGuHjsbIo22EfYCLt1POo22eU9LXoKitiJ/Y1cRflJ2dcZqTgX6ZU9janW1jZWJsmGGXZGSeXonZ0Zqop5uikomtpXFqZmxsa3CaXpmbV5OQcQ==
hxxp://guardinfo.net/?p=WKmimHVlbm2HjsbIo22EfYCIt1POo22cU9LXoKith6Swz9KwoFqbnZxxmpinc4rapZxql2OemI6WaWeZY5WK2J%2Bgo6vKnpRfpqd2ZWppaHCUXpeaaFaQl28%3D
It uses the same tactic as seen on earlier posts here and here where the website claims to scan the unsuspecting user’s computer, detects heaps of infections, and offers a bogus solution.

Looking at the installed scareware we find out that Windows Protection Suite is nothing but a clone of Windows Security Suite.

Even their websites are clones:

hxxp://windowsprotectionsuite.com
hxxp://windowssecuritysuite.com
Posted in Rogue Apps | Tagged: clone, fake alert, fake av, guardinfo.net, linewebsearch.com, rogue app, rogue av, scareware, searchscanner.net, security, Windows Protection Suite, Windows Security Suite, windowsprotectionsuite.com, windowssecuritysuite.com | Leave a Comment »
Posted by Steve Espino on August 19, 2009

A recently leaked threesome sex tape, involving Grey’s Anatomy’s “McSteamy” Eric Dane and wife Rebecca Gayheart, has been circulating around the internet. And we all know that controversial stuff like these are often taken advantage of and used to distribute malware using techniques such as social engineering and SEO (search-engine optimization). Users of one particular website have been spotted to be talking about the sex tape. There was no video on the site itself so people wanting to see the video might be enticed to clicking the links posted by fraudulent users and are tricked into downloading and installing malware on their computers.
There’s one such post suggesting we go to hentaiplace.org to watch the leaked video:

Here the malware poses as a fake video codec Divxcoder that users need to install in order to watch the video.
hxxp://hentaiplace.org/play.php?id=Eric_Dane_and_Rebecca_Gayheart_sex_tape

Following the download link hxxp://hentaiplace.org/promo.php, we are redirected to hxxp://fiopolosa.com/download/7933547766773d3dd846130c20090815/FlashCodecPlugin.exe
The malware presents the user with a License Agreement while doing its dubious deeds in the background. And you don’t even need to agree to the License Agreent to install the malware!

The malware changes the affected computer’s DNS settings to use the following IP Addresses as DNS servers:
85.255.112.80
85.255.112.168
This means that the affected computer’s will have to contact these IPs for name resolution and this gives the bad guys a really good opportunity to redirect users to fake websites and steal passwords, login details and other confidential information.
PCTools Spyware Doctor detects the malware as Trojan.DNS_Changer.
This malware employs Rootkit.TDSS and Trojan.TDSServ in order to hide its presence on the infected machine.
Posted in Malicious Intent | Tagged: Divxcoder, dns changer, dnschanger, Eric Dane, fake codec, fiopolosa.com, FlashCodecPlugin.exe, hentaiplace.org, huffingtonpost, malware, McSteamy, Rebecca Gayheart, Rootkit.TDSS, scandal, security, sex tape, social engineering, threesome, Trojan.DNS_Changer, Trojan.TDSServ | Leave a Comment »
Posted by Steve Espino on August 13, 2009
I was reading a blog about a Rogue AV then I noticed a suspicious comment on it:

It the user was recommending an antispyware program and gave us the following url:
www(dot)tinyurl(dot)com/qlft9c
Following the link, tinyurl does its magic and we are directed to:
hxxp://macrovirus(dot)com/?hop=starbasi

If we believe everything we see and hear, we’ll be downloading and installing a scareware:

Here we can see that the bad guys are clearly taking advantage of the url shortening service from tinyurl.com.
Also, you might notice, there’s a striking resemblance between the following:
bassey edet
and
hxxp://macrovirus(dot)com/?hop=starbasi
This is probably giving us a hint as to how the bad guys get paid.
If you got this scareware, remove it immediately.
Posted in Rogue Apps | Tagged: fake alert, fake av, macrovirus, qlft9c, rogue app, rogue av, scareware, security, starbasi, tinyurl | Leave a Comment »