Showing posts with label acid.david9 ransomlock. Show all posts
Showing posts with label acid.david9 ransomlock. Show all posts

Tuesday, 22 February 2011

Bluetrash ransomware.. now updated with a bot.



Most of you know this threat as 'bluetrash' or 'porno player'
This malware have appear in April 2010 and currently alway active.
Named 'winAD' because of about box resource which present in both types and using fakes porn site sush as 'SpermTV' or 'EroTube' for distributing the malware.


Unblock codes and tel numbers are stored inside executables.
They do not use cryptor but Winlock code constantly morphing trying to break antivirus signatures, the dropper use the Windows Vista Media Player icon, is packed with UPX and extracts payload Winlock executable to %USERPROFILE%\[Digits]\[Digits].EXE


After few days, some variants appears, like the 'Homoblocker' ransomware, generaly distributed with a fake site coupled with Phoenix Exploit Kit

If we return one month ago, this malware was updated 2 or 3 per day.
Now... according to my malware bot, this ransomware is updated every hours.
And the homoblocker variante seem now not updated anymore.
Concerning the Homoblocker variants, sometime the guys who is under this have made some tests:


These 'tests' have appear on the homoblocker malware server the 03/02/2011 at 21:12:16 P.M (GMT+1) for 3 days with 8 updates in totals.
According to VirusTotal, when i've uploaded a sample, it was only detected by one antivirus.

For Bluetrash, i monitor every change of this ransom like homoblocker, and since one week now.. that become serious with updates and modifications. (some changes have appears like the 'reboot when dropped', Actually he dont do that anymore.)
A rapid calcul: 24*7 = 168 samples per week.
Tiny histogram:


An update error occured sunday 20 at 03:00 A.M (GMT+1)
Malware filesize in the server: 0 bytes, at 04:08 A.M, a new working sample was available.
Bluetrash ransomware is surely updated with a bot now.
Before, updates have occured only the day.. now it's day and night, h24.

Samples from yesterday downloaded every hours, as you can see the MD5 is alway not the same: 


Monitoring center:



Sample are updated every hours but still detected by most of AVs.
Also i want to thanks Crank69, i really appreciate your emails man.

Friday, 3 December 2010

Trojan.Ransom (xxx_video_32605.avi.exe)

This trojan blocker ( MD5: ed0cd3c04b2a4160bde59b477c23dc91 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.


Number to Call: 89165740131
Code to unlock Windows: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
(your serial can be what's you want but you need to make it exactly 90 in lenght)

Run MBAM to remove the infection.

Wednesday, 1 December 2010

Trojan.Ransom.Boot Seftad Removal Guide

This trojan.blocker ( MD5: 86a3a3ce16360e01933d71d0bf1f2c37 ) prevent hard drive booting
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.


If you are infected, follow this video:





Hiren's BootCD
Securelist: And Now, an MBR Ransomware

Monday, 29 November 2010

Trojan.Ransom (pornoplayer.exe)

This trojan blocker ( MD5: a73c020033d412803c230f75105ec328 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.


Number to Call: 9153652039
Number to Call: 9154709950
Number to Call: 9153652043
Number to Call: 9153652148
Number to Call: 9175955259

How to unlock
First thing to type: XYLIBOX
Second: 31337
Last: 31337
The first serial to type is not really important, but the second and the last must be the same for unlock Windows.

Run MBAM, or KAV to remove the infection.
Merci à Nicolas Brulez pour l'aide qu'il ma apporté sur IDA, que je ne connaissais vraiment pas.


Thursday, 23 September 2010

Ransomlock

Encore un ransomware.... développé par un français cette fois
Il fait passer sont malware pour un programme de triche World of Warcraft, les joueurs le télécharge et bim...
MD5: c3464bc2536908b200e90753120e9c33


Une fois exécuté, un installeur apparais

Le ransomlock et exécuté a la fin

Après 90 secondes le programme lance une procédure d'arrêt système
Les données ne sont en aucun cas supprimé après les 24 heures passé.










Si votre pc et infecté, tapez la clé d'activation: DIFAAAAAAAAAAAAAAAAAAAAAAAAA
Run MBAM to remove the infection.