Archive for the 'Database Update' Category

24
Nov

New fake security software called Micro Antivirus 2008

Note: This site is distributing Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

Product named 2008 yet website is 2009. I see that microav2008.com is available, maybe they should register that too.  ;-)

Fake Product Name:microav2009-website
Micro Antivirus 2008

Site: microav2009.com

IP: 91.208.0.223
Location: Russia
Registration:
ICANN Registrar:  IN

TERNET.BS CORP.
Created:  2008-09-24

File:
MicroAVSetup.exe
VirusTotal coverage: 27/37
http://www.virustotal.com/analisis

/38e2f2bc89e9803b8d313424f21957cd

20
Nov

Antivirus 2009

Note: This site is distributing Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

Very low detection.
Site:
hxxp://antivirus-premium-scan.com/2009/1/en/_freescan.php?nu=77025304

File: A9installertest_77025304.exe
Virustotal: Result 1/36 (2.78%)

Additional information
File size: 163840 bytes
MD5…: ccdfcdcea179cf0ecf12035d5ee8b821
SHA1..: e85dd4eebb5ae4d61f36385281922637712a56bd
SHA256: 6ffe5e74108fce512aa3c2de39e13ea9aebdda9606a7966d424254282679c03c
SHA512: 4de947fd4bf09f6ac2ef6dc34fafdf471555fe6e37dc0f8722cd4e726b5d6dc5
3c76a98f2786df5af5527f0356715bf5787f2b6b44a15eeffea5ff7aed4b6d37
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)

15
Nov

Database Update - 19 Files (Low Detection)

Quite a few files added to the database today. As you can see below, these aren’t detected by many AV’s out there.

BE ADVISED: These URL’s may still be active. Proceed at your own risk!

A9installer_77024202.exe
Result: 0/36 (0%)
MD5: fd6c1b0cec99796c72213ee330eb7b58
VirusTotal
ThreatExpert Analysis
hxxp://allinone-scanner.com/2009

av_2009.exe
Result: 1/36 (2.78%)
MD5: 4c68e58e317f7111ac147d5279ef23e0
VirusTotal
ThreatExpert Analysis

zcodec.1482.exe
Result: 3/36 (8.34%)
MD5: 9acea07175a11ae690263f9be7828467
VirusTotal
ThreatExpert Analysis
hxxp://codecdownload.pc-storesoft.com

doc.pdf
Result: 10/36 (27.78%)
MD5: 220e84ba5748fbd62234f3f8db52c660
VirusTotal
hxxp://chanchoi.cn

default.exe
Result: 13/36 (36.12%)
MD5: 58e3a60289854bb435570a14ac3c616e
VirusTotal
ThreatExpert Analysis
hxxp://chanchoi.cn

kryostm.dll
Result: 21/36 (58.34%)
MD5: b8d72237913a95b597583f8f91181ed8
VirusTotal
ThreatExpert Analysis

kryo2.sys & pavtpk.sys
Result: 20/36 (55.56%)
MD5: abbce53fa9411adbd8a870ae9c27a92e
VirusTotal
ThreatExpert Analysis

test.pdf
Result: 10/36 (27.78%)
MD5: 220e84ba5748fbd62234f3f8db52c660
VirusTotal
hxxp://onlinestat.cn

file1.exe & U.exe
Result: 4/36 (11.12%)
MD5: 0fe5b393bef43d95f5e86c820097491e
VirusTotal
ThreatExpert Analysis
hxxp://onlinestat.cn

ntos.exe
Result: 4/36 (11.12%)
MD5: fbe5869d3f03108296e10a81e9b7d160
VirusTotal
ThreatExpert Analysis

After multiple runs through a sandbox, these different binaries were downloaded

ntos.exe
Result: 4/36 (11.12%)
MD5: df4f605f59823324cceaf359d46a5d27
VirusTotal
ThreatExpert Analysis

ntos.exe
Result: 5/36 (13.89%)
MD5: fa736d7136176eebfcefd109b33f2e90
VirusTotal
ThreatExpert Analysis

soft.exe
Result: 9/36 (25%)
MD5: dcdd783dd8f84ef8b9a0c8233d152540
VirusTotal
ThreatExpert Analysis

csrss7.dll
Result: 3/36 (8.34%)
MD5: e87c0ab9c96b000f86199118d38539c1
VirusTotal
ThreatExpert Analysis

This also modified the hosts file to block international search engines (AOL, Google, & MSN)

doc.pdf
Result: 12/36 (33.34%)
MD5: 9b3822a11c9e94763150282f0c9b1d01
VirusTotal

default.exe & ~.exe
Result: 8/36 (22.23%)
MD5: 4dcc389638a9cf14972752df79ed0dd6
VirusTotal
ThreatExpert Analysis

nvaux32.exe
Result: 8/36 (22.23%)
MD5: 94d724d0740a3f6a26b624051950b053
VirusTotal
ThreatExpert Analysis

user32.dll
Result: 8/35 (22.86%)
MD5: 5f24060f06fd415314485a66a0be8726
VirusTotal
ThreatExpert Analysis

flash_update.exe (Koobface Facebook Worm)
Result: 7/36 (19.45%)
MD5: f47a95dc8003bb0f206d836b757fa9f3
VirusTotal
ThreatExpert Analysis
hxxp://youtube-cam.com

13
Nov

Database Update - 16 Files (Low-Moderate Detection)

Another update for tonight. Should have more over the weekend. Find them in /pnuemo-malware/.

BE ADVISED: These URL’s may still be active.  Proceed at your own risk!

services.exe
Result: 19/36 (52.78%)
MD5:
c629db60a9a5d7303419b5153d3e9b0b
VirusTotal
ThreatExpert Analysis

nd82m0.dll
Result: 5/36 (13.89%)
MD5: d6f2135dc562c7d4992cf2cea2166707
VirusTotal
ThreatExpert Analysis
hxxp://85.17.166.182

kb600179.dll
Result: 5/36 (13.89%)
MD5: f946f8c3de445d45c7eb34591bee037b
VirusTotal
ThreatExpert Analysis
hxxp://89.188.16.30

setup_457_6777_.exe
Result: 1/36 (2.78%)
MD5: e9339f9045368947789ec70739de4b21
VirusTotal
ThreatExpert Analysis
hxxp://files.download-antispyware.com

scanner_457_6777_.exe
Result: 16/36 (44.44%)
MD5: e0f855c6c5fc93f0a8ed1fe9e702e492
VirusTotal
ThreatExpert Analysis
hxxp://dl.storage-antispyware.com/get/

42.exe
Result: 4/36 (11.12%)
MD5: f5201b9e77b7b31443b4e0e6190e219f
VirusTotal
ThreatExpert Analysis
hxxp://85.92.157.141/mxlivemedia/

msansspc.dll
Result: 6/36 (16.67%)
MD5: 3cc545e42b9bb14df4a63f2a37aebdb0
VirusTotal
ThreatExpert Analysis

mvnzivtlmzhxi.dll
Result: 7/36 (19.45%)
MD5: 7614e7448f1983b9641e9699f67576a4
VirusTotal
ThreatExpert Analysis

pdf.pdf
Result: 6/36 (16.67%)
MD5: a3f83503a165a19c4b01328463175cd7
VirusTotal
hxxp://activision.cc/1/spl

twext.exe
Result: 11/36 (30.56%)
MD5: 5767c816cb20753976df2edb60eaf448
VirusTotal
ThreatExpert Analysis

load.exe
Result: 12/36 (33.34%)
MD5: 9b467bdc6dd1b3e68651b7039cd373c8
VirusTotal
ThreatExpert Analysis
hxxp://activision.cc/1/

xcvb.pdf
Result: 4/36 (11.12%)
MD5: e3b86145de00ebfab3e3159d24b81104
VirusTotal
hxxp://91.203.92.137/xcv/

install.exe
Result: 16/36 (44.45%)
MD5: 0869881865032bd1b3b08d82e5e4f404
VirusTotal
ThreatExpert Analysis
hxxp://91.203.92.137/xcv/

beep.sys & figaro.sys
Result: 29/36 (80.56%)
MD5: c4618f889863b5aa357f5f5ba8f353d6
VirusTotal
ThreatExpert Analysis

brastk.exe
Result: 14/36 (38.89%)
MD5: 0d63a88fdb4259de8280f8bb7d78ec35
VirusTotal
ThreatExpert Analysis

KB908268.exe
Result: 7/36 (19.45%)
MD5: 504eb66e741186a61792862f0a83ff82
VirusTotal
ThreatExpert Analysis
hxxp://76.74.239.143/weruoiq/

msansspc.dll
Result: 6/36 (16.67%)
MD5: 3cc545e42b9bb14df4a63f2a37aebdb0
VirusTotal
ThreatExpert Analysis

12
Nov

Database Update - 13 Files (Low-Moderate Detection)

Only a smaller update today. Files available in /pnuemo-malware/. The installers I’ve been collecting are getting nastier and nastier. Keep everything updated!

xloader.exe
Result: 6/36 (16.67%)
MD5: efe48c6ea123b7d5a07f1beaf4b9efb1
VirusTotal
ThreatExpert Analysis
hxxp://adwords.google.com.upload.main.update.kliauj.cn

winlogon.exe
Result: 5/36 (13.89%)
MD5: 6c161cf9aefd577235547a0514ea7336
VirusTotal
ThreatExpert Analysis

brastk.exe
Result: 23/36 (63.89%)
MD5: 89bbe87df33a7722ce6bc890023a82c0
VirusTotal
ThreatExpert Analysis

uesiuqcr.exe & svchost.exe
Result: 14/36 (38.89%)
MD5: f74dc617cec41d36aca9ffc793add258
VirusTotal
ThreatExpert Analysis

getfn32.dll
Result: 6/36 (16.67%)
MD5: 98c8c4cc9ae42cbd630fc8c1aec50a50
VirusTotal
ThreatExpert Analysis

smwin32.dll
Result: 6/36 (16.67%)
MD5: 47c4fa178eefe5379856c7d35e953acd
VirusTotal
ThreatExpert Analysis

beep.sys
Result: 32/36 (88.89%)
MD5: e2bba2140204d6e4134828445a9c486c
VirusTotal
ThreatExpert Analysis

svchost.exe
Result: 19/36 (52.78%)
MD5: 57841b5c7ed709f6b5ff0027c014083b
VirusTotal
ThreatExpert Analysis

svchost.exe
Result: 24/36 (66.67%)
MD5: 26fafa838db23646661bfde34b537059
VirusTotal
ThreatExpert Analysis

l.exe
Result: 12/36 (33.34%)
MD5: 3f052a786ef71d4d9368732f9d25bfdf
VirusTotal
ThreatExpert Analysis
hxxp://worldfirefighter.com/wellstonfd

LDR24.tmp
Result: 18/36 (50%)
MD5: bd336a1191044325d0165b70fecc5520
VirusTotal
ThreatExpert Analysis

svchost.exe
Result: 17/36 (47.23%)
MD5: ff22b4365b9d2f8b8940c1558c82effd
VirusTotal
ThreatExpert Analysis

KB908995.exe (TDSServ Rootkit)
Result: 6/36 (16.67%)
MD5: 942aa524ab0de25a6750c5e9772fa387
VirusTotal
ThreatExpert Analysis
hxxp://google-analyze.cn

12
Nov

Fake control panel app installing multiple malware binaries

Came across this nasty bugger today. It installs a few banker trojans, generic trojans, and a rootkit. Below you can see all of the files that it installs on the computer. These files are available in /pnuemo-malware/. Please read our FAQ for access to our repository.

BE ADVISED: These URL’s may still be active.  Proceed at your own risk!

video.cpl
Result: 19/36 (52.78%)
MD5: c87f1736ab9ac5d80a4027b5ba139f7c
VirusTotal
ThreatExpert Analysis
hxxp://amateur-sexy.whyza.net

kodnkwnv.sys
Result: 3/36 (8.34%)
MD5: 4ad5d5229f85f42e873fda98190b2f19
VirusTotal
ThreatExpert Analysis

certificado.exe
Result: 11/36 (30.56%)
MD5: 500a7df333ebe3d1e11d18b08b005e1e
VirusTotal
ThreatExpert Analysis

msnsgs.exe
Result: 17/36 (47.23%)
MD5: f53fea0cef9389535f9df74981527268
VirusTotal
ThreatExpert Analysis

codecs.exe & svchosts.exe & avg.exe
Result: 20/36 (55.56%)
MD5: 7b51419b022709cffec32fa24a23f510
VirusTotal
ThreatExpert Analysis

nppagent.exe
Result: 13/36 (36.12%)
MD5: 91f4c75a4f000f3b5bdc2cd74fb5d0d8
VirusTotal
ThreatExpert Analysis

outlok.exe
Result: 24/36 (66.67%)
MD5: 4dd0afcca8764bce567ebd853f022db7
VirusTotal
ThreatExpert Analysis

sounds.exe
Result: 11/35 (31.43%)
MD5: 0fba190253a84d28d022008ee42ea8e5
VirusTotal
ThreatExpert Analysis

sysmod.exe
Result: 11/35 (31.43%)
MD5: 2eb09ac08f87b9c4dd54c9d4be9241cc
VirusTotal
ThreatExpert Analysis

11
Nov

Database Update - 13 Files (Moderate Detection)

Here is an overdue update. I’ve been out of the loop for a bit. These files are of course available in /pnuemo-malware/ and please read the readme once more. I have changed again my cataloging. Sorry about that folks.

I have changed my cataloging again so please have a look at the readme. Also, there is a new feature this week. I have added a list of hashes from files I’ve collected but haven’t highlighted in this post. You can read more below or download the txt file.

AdobeMovie_v312.exe (Downloads or Creates: 9129837.exe & newdrv.sys)
Result: 15/36 (41.67%)
MD5: b362bd8f16d527b630793a520af91c67
VirusTotal
ThreatExpert Analysis

9129837.exe
Result: 28/36 (77.78%)
MD5: 642a588272e9fe723fb2f1dd8fccede5
VirusTotal
ThreatExpert Analysis

new_drv.sys
Result: 35/36 (97.23%)
MD5: a54de1d46ff7bdefbf9d9284c1916c5e
VirusTotal
ThreatExpert Analysis

doc.pdf (Downloads or Creates: vhosts.exe)
Result: 11/36 (30.56%)
MD5: 7156f4280b8ac9cda47074fb0fc49f86
VirusTotal

vhosts.exe
Result: 19/36 (52.78%)
MD5: 47565702c7796af23a64111e89a5ad91
VirusTotal
ThreatExpert Analysis

gadcom.exe
Result: 19/36 (52.78%)
MD5: ce4dbc7f1d6330ecc0f76f4fd31c3ac5
VirusTotal
ThreatExpert Analysis

file.exe (Downloads or Creates TDSSserv.sys rootkit)
Result: 25/36 (69.45%)
MD5: 40b3a11cd3d2a039dd1c305df1092be8
VirusTotal
ThreatExpert Analysis

install.exe
Result: 23/35 (65.72%)
MD5: 95207d0c1ec805b09ff0d72b67db0625
VirusTotal
ThreatExpert Analysis

figaro.sys & beep.sys
Result: 31/36 (86.12%)
MD5: a59f21ef436c750d259d136913c4be21
VirusTotal
ThreatExpert Analysis

brastk.exe
Result: 23/36 (63.89%)
MD5: fc039650b5152a40c5637fcd1abcd4c6
VirusTotal
ThreatExpert Analysis

23.exe (Downloads or Creates: E0D39066.dll & c39e8db.sys)
Result: 31/36 (86.12%)
MD5: da0ff007073da42f3328e16de0b61716
VirusTotal
ThreatExpert Analysis

E0D39066.dll
Result: 30/36 (83.34%)
MD5: 446dbceeaac129665302955c0f67c5f4
VirusTotal
ThreatExpert Analysis

c39e8db.sys
Result: 22/36 (61.12%)
MD5: 09f66bbe922e46f475e600b1110a3acb
VirusTotal
ThreatExpert Analysis

Continue reading ‘Database Update - 13 Files (Moderate Detection)’

07
Nov

Spyware Protector

Note: The sites we talk about in this post distribute Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

Here is a newer rogue threat we found to be active today.  The files are not available yet.

Spyware Protector

Whois:

ICANN Registrar:  ONLINENIC, INC.
Created:  2008-09-29
Expires:  2009-09-29
Updated:  2008-11-05
Registrar Status:  ok
Name Server:  NS1.FREEFASTDNS.COM (has 135 domains)
Name Server:  NS2.FREEFASTDNS.COM
Whois Server:  whois.onlinenic.com

Server Data
IP Address:  89.149.255.190
IP Location   - Germany - Netdirekt E.k
Response Code:  200
Domain Status:  Registered And No Website

DomainTools Exclusive
Registrant Search: “Shestakov Yuriy” owns about 4,332 other domains

Terse Summary:

GET hxxp://adserver.eosads.com/redirect3/traf.php?id=454 200 OK
GET hxxp://adserver.eosads.com/redirect3/scr.php?a=754739&lang=en-us&id=454&ref=http://spyware-protector.com/  200 OK
GET hxxp://spyware-protector.com/in.php  404 Not Found
GET hxxp://spyware-protector.com/install.php 200 OK
GET hxxp://spyware-protector.com/favicon.ico 404 Not Found

06
Nov

Antispyware 2008 Rogue Served Through Download.com Ads

A few months ago we warned of Google sponsored results pointing to rogue anti-malware applications  (read: Sponsored Result != Safe) and more recently we talked about malicious ad content being displayed through pop-up ads hosted by Motigo’s free analytic services (read: Antivirus 2009…brought to you by Motigo).  Today we received word from a fellow security researcher, mwdisector, that a rogue anti-malware application was being served via ads in the bottom right corner of the Download.com website.

In our previous post regarding a related incident where Motigo served Antivirus 2009 rogue pop-up ads we told website Owners to  make sure they fully understand the all of the risks involved in implementing third party tools, ads, or services.

It’s obvious that the ad companies are not doing a good enough job at making sure their links are safe.  For this very reason, you do not see Google Adsense or similar types of advertisements on Malware Database. It would result in our viewers being infected and that is something we cannot have.  MalwareBytes and Panda Security are two companies that we stand by and those are the only type of ads you will see here, ads that we can guarantee not to lead to infections.

Download.com does have an initiative for malware free downloads but they state nothing about making sure their text based and image advertisements are malware free.  We are hoping the people at Download.com read this and take a stand against current and future threats promoted through their sponsored ads!

Rogue sponsored link served via download.com

Antispyware 2008 ad

Points to the Antispyware 2008 Rogue

*Do not attempt to visit this site or download the software*

Antispyware 2008

What it looks like

Antispyware 2008

File: setupxv.exe
VirusTotal:
Result: 12/36 (33.33%)
File size: 5620057 bytes
MD5…: 15134735aff21a9162bef607684b9ca4
SHA1..: 72eff32a2187c339115e6842f80f6aa2273c48be
SHA256: f438f8c9b9f04fb4ee4fbbd2b215abbffb863c99e4a7f28012b0b45c8fe628ed
SHA512: f1e6b742c32c2931697d3ac9c06010d91bb4014d87d5d3a7ac8b6f667e5a08d0
f52ab7bb7864d87ad1ee7d9e1f664713b2c59f529869719294f0b380d27f4e44
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (75.0%)
Win32 Executable Generic (16.9%)
Generic Win/DOS Executable (3.9%)
DOS Executable Generic (3.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×412c8f
timedatestamp…..: 0×4466b13c (Sun May 14 04:25:32 2006)
machinetype…….: 0×14c (I386)

Removal Information:Need assistance removing this malware?
Click here for more information about malware removal.

Don’t forget to ask for help in our user forums!

03
Nov

Antivirus Pro 2009 - Exploiting Human Weakness for Money

Note: Thie sites we talk about in this post distribute Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

Almost everyday our viewers ask us about Rogue anti-malware software.  Out of all of the questions we receive, the most common is “When will these attacks stop?”  The sad truth is that we cannot see an end to this problem in near sight.  As long as the malicious individuals are able to trick or force users into downloading, installing, and eventually paying for their fake “Rogue” anti-malware products, they will continue to develop and push the envelope.

AntivirusPro 2009

Antivirus Pro 2009

The user will be prompted with the following message in the event that the browser blocks the download.  When the user clicks on “Click here to get full advanced real-time protection and continue browsing”, it will automatically forward them to the payment gateway page.

“Insecure Internet Activity. Threat of Virus Attack!  Due to the insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes”

Antivirus Pro 2009 Browser Warning

Installer:

There are three possible options to the Antivirus Pro 2009 Installer. Continue, Terms of Service and Cancel.

Antivirus Pro 2009

Canceling the Installation:

When attempting to exit the installer via the cancel button, the setting defaults to “Continue with installing and running free scanner.”

Antivirus Pro 2009 Cancel Install

Terms of Service:

Antivirus Pro 2009 Terms of Service

Interface:

The interface may look convincing to unsuspecting victims.

Antivirus Pro 2009 Interface

Scare Messages:

Victims are presented with various scare messages to entice a purchase.

“WARNING! Antivirus Pro 2009 has found 27 useless and UNWANTED files on your computer!”

Personal data at the reach of anyone’s hand

Internet history records available

Compromising and adult material stored on your system

Chat sessions’ logs and personal Emails easily reachable

Antivirus Pro 2009 Scare Tactics

Payment Gateway:

hxxps://secure.soft-payments.com via AS20495 (WEDARE We Dare BV Autonomous System)

secure.soft-payments.com

Antivirus Pro 2009 Payment Gatweay

SharedNS:

Antivirus Pro 2009 Shared NS

VirusTotal:

7/36 (19.44%) –>hxxp://www.av-pro-2009.com

7/36 (19.44%) –> hxxp://xp-as-2009.com

11/36 (30.56%) –>hxxp://xpas-2009.com

16/36 (44.44%)–> hxxp://av-pro2009.com

16/36 (44.44%)–>hxxp://avpro-2009.com

16/36 (44.44%)–>hxxp://avpro2009.com/

Removal Information:Need help removing this malware?
Click here for more information on the removal process.

Don’t forget to ask for help in our user forums!




Malware Database Forum



Click for

Malware Removal Information



Special Deals


$20 Off Panda Internet Security 2009

 

December 2008
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  

Support Malware Database!


Security Engineering: A Guide to Building Dependable Distributed Systems

Reversing: Secrets of Reverse Engineering

Crimeware: Understanding New Attacks and Defenses (Symantec Press)

Security Power Tools

IT Security Interviews Exposed: Secrets to Landing Your Next Information Security Job

Windows Command-Line Administrator's Pocket Consultant, 2nd Edition

CompTIA Security+ Certification Kit