With some friends at kernelmode.info, we have made a sort of 'monitoring team' for investigate this ransomware family. (i've profited of this to stop publishing unlock code for this one on my blog)
I will not tell what's we do and how we proceed but it's relatively easy to get the newest fake porn sites (even inactive domains who will be used in near future) by these bad guys.
The 'WinAD' gang are known for these winlocks:
'Bluetrash'
'Homoblocker'
'Pornorolik':
They are also known for using crypters such as Mystic compressor and VBCrypt.
The web process for get infected work like this
1) Fake porn site send you to the 'redirector'
2) The redirector send you to another fake porn site
3) The fake porn site conduct to malware download:
Note: new domains are spawn daily and same for the redirector who get all his links updated.
It's daily reversing for get unlock code of the day.
--
The first machine is a Sutra TDS (Traffic Distribution System)
The redirector if you prefer
Curently every redirector url used by these guys are named "in.cgi" (a elf file) who searh the good log file in function of the parameter passed.
Structure of the TDS:
The folder /data/ who have an htacess "deny from all" is used for redirect users.
The parameter '12' will send you to ransomware fake porn site:
Some factice sites are also here, in case if you don't come from Russia and with some others parameters:
SQLitle db dump, here the referers:
Pornorolik domains tracked (and this just for 25-26 Aug):
Stats (TDS dumped the 26)
That all for the TDS machine.
Now the fake porn site who conduct to malware download
Fake pages who conduct to malware download are in html (lol) a javascript code is used for display thumbles and the folder video just contain 'videos12.avi.exe'.
The folder diz-videoyou contain the site design and some php related to advisories
Folder 'diz-bravo' is also advisories related
diz-freshporn contain another website kit template
diz-npv contain 'new porno video' image for another kit.
As you can see nothing is 'developped' on these servers, pages are primitive.
The porn business seem good enought to infect people.
Bad guys who are under this use probably another machine (a windows?) with a timer who each x time rebuild/repack the ransomware and upload it automaticaly to servers, and can do a RDP connect for see what's going on. (that just my opignon about how they work, if you know more about these guys don't hesitate to contact me)
They bought also new domains each day and refresh their beeline numbers.
For do that... sure they have money.
WinAD related:
Bluetrash ransomware.. now updated with a bot.
Trojan.Ransom (HomoBlocker)
Trojan.Ransom (porn2o-rolik2.avi.exe)
(ext) Trojan Ransom (WinLock), a growing threat
Edit: Thanks to kmd for the picture :þ
Showing posts with label homoblocker. Show all posts
Showing posts with label homoblocker. Show all posts
Saturday, 27 August 2011
Sunday, 10 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: 64976d8f8023ef6116d35952a5ed1495 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9670670916
Number to Call: 9057266311
Number to Call: 9057861657
Number to Call: 9651894844
Number to Call: 9057265727
Number to Call: 9651893349
Number to Call: 9670670994
Number to Call: 9670671067
Code to unlock Windows: EXCEL
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11) ~ here (7 Jul 2k11) ~ here (8 Jul 2k11) ~ here (9 Jul 2k11)
Saturday, 9 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This summary is not available. Please
click here to view the post.
Friday, 8 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: f979b960b3e76c1e15851cec935aa497 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9651894161
Number to Call: 9651893195
Number to Call: 9651894765
Number to Call: 9670670344
Code to unlock Windows: PARALLEL
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11) ~ here (7 Jul 2k11)
Thursday, 7 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: 6baadab4a1d16c6aa95c807b85110b95 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9057861643
Number to Call: 9057861307
Number to Call: 9032809731
Number to Call: 9670670344
Code to unlock Windows: UPLOADS
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11)
Monday, 4 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: db813cbe9d0ac15d9bce8ada1eab9ed0 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9654226483
Code to unlock Windows: PLAYGIRL
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11) ~ here (4 Jul 2k11) ~ here (4 Jul 2k11)
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: 5b7d6c0ed6ffbf507f1cad4a062a99a5 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9654226763
Code to unlock Windows: NUMBERONE
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11) ~ here (4 Jul 2k11)
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: 3af0b0fb8f03869ce4b8f9ece4ef767 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9654171564
Number to Call: 9654227281
Number to Call: 9651893039
Number to Call: 9057439954
Code to unlock Windows: PLAYBOY
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11) ~ here (1 Jul 2k11)
Friday, 1 July 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: cf88fca0bcb74214c0325cb759a5d1c3 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9057859866
Number to Call: 9651893039
Number to Call: 9651893541
Number to Call: 9651893536
Number to Call: 9032809368
Number to Call: 9651893039
Number to Call: 9032809668
Number to Call: 9032809647
Code to unlock Windows: SVADBA
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11) ~ here (30 Jun 2k11)
Thursday, 30 June 2011
Trojan.Ransom (porno-rolik.avi.exe)
This trojan blocker ( MD5: 84c0d79c400e89a89fc127c94b63bb9c ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.
Number to Call: 9651894211
Number to Call: 9057344801
Number to Call: 9651894245
Number to Call: 9651893615
Code to unlock Windows: BOLITGOLOVA
Pornoplayer variant.
Already noticed on the past: here (28 May 2k11) ~ here (4 Jun 2k11) ~ here (9 Jun 2k11) ~ here (11 Jun 2k11) ~ here (12 Jun 2k11) ~ here (12 Jun 2k11) ~ here (13 Jun 2k11) ~ here (20 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (21 Jun 2k11) ~ here (22 Jun 2k11) ~ here (23 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (24 Jun 2k11) ~ here (25 Jun 2k11) ~ here (26 Jun 2k11) ~ here (27 Jun 2k11) ~ here (28 Jun 2k11) ~ here (29 Jun 2k11)
Subscribe to:
Posts (Atom)


