Translate

Posts mit dem Label Exploit werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Exploit werden angezeigt. Alle Posts anzeigen

2/19/2014

NEWLY DETECTED: ichoicecomputers.com & mwola.com
MULTIPLE EXPLOIT KITS (HEUR:Trojan.Script.Generic) Singapore



NEWLY DETECTED MALICIOUS SINGAPUR SITE: MULTIPLE EXPLOIT KITS

DOMAIN:

http://ichoicecomputers.com/
  • https://www.virustotal.com/de/url/f70c7291a017d9058b850ef001c861da6f09713dcaae03a346821e12e13cb4f0/analysis/1392799010/

INFECTION:
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/0cf10f4c2dd4723268d178c1c1530160f17902e1ef36ad4204cba7cefc933617/analysis/1392799595/
  • https://urlquery.net/report.php?id=9527754
FULL REPORT:
Document hosting: UploadEdit.com

2/17/2014

CVE-2010-1885:
oasissalesltd.com
G01-Pack EXPLOIT KIT & BLACKHOLE EXPLOIT KIT (V1)
(United States)




RBN 162
CVE-2010-1885
2 EXPLOIT KITS
G01-Pack EXPLOIT KIT & BLACKHOLE V1 & MORE
http://oasissalesltd.com/
  • https://www.virustotal.com/de/url/72db1f5817c25099af14a2eae08013fdcaab743073a4b93310c2df7eee5b62a2/analysis/1373801163/
Trojan-Downloader.JS.Iframe.chf
  • https://www.virustotal.com/de/file/bcd159c52a585704c5278afc54cb1cd3c0718c671edfacd4f1b11f52653311bd/analysis/
  • https://www.virustotal.com/de/file/0eba2d732c74fc34ce72293129ce7516931fa77a9f3401acbf55c44177b7d8ee/analysis/
Exploit:HTML/IframeRef.V
  • https://www.virustotal.com/de/file/e270ef91ae2795b7fe3e5362aff7ee020fb5584264096876eb09efd65f0cc565/analysis/1392554684/
  • http://wepawet.iseclab.org/view.php?hash=cd2f37b1cad3b1eabdc2800a56fc134f&t=1392554456&type=js
Likely Blackhole Exploit Kit Driveby Download Secondary Request
  • https://urlquery.net/report.php?id=9464549


FULL REPORT : 

Document hosting: UploadEdit.com

2/07/2014

MALWARE:
Trojan-Downloader.JS.Agent.gtu & HEUR:Trojan.Script.Generic
INFECTED SITE(s):
bretthersley.com & pvhetiozstg.findhere.org


MALICIOUS URL(s): 
(Trojan-Downloader.JS.Agent.gtu) 
MAL. Iframe Injection 
(RBN 275) 
Likely leading to EXPLOIT KIT



DOMAIN:
bretthersley.com
  • https://www.virustotal.com/de/url/385d06231a7226fa3998b97e62c5c10195485b57556cd52f3d3a0f4874e602d5/analysis/1391776537/

SPECIFIC LINK:
bretthersley.com/wp-content/themes/01_Super_Slick_VCard_-_Wordpress_Version/images/loader.gif
  • https://www.virustotal.com/de/url/225a220dd922c4e73a01ec0f40f5d9686c4d5960f28295dd720abce0cbffce41/analysis/1391775974/

FORMERLY:
Trojan-Downloader.JS.Agent.gtu
  • https://www.virustotal.com/de/file/3851fd1f908ad8e7a2c8f3b8fd7a5e73182fa8d99761903a743c12db24d90028/analysis/1375177800/

NOW:
Trojan-Downloader.JS.Agent.gtu
  • https://www.virustotal.com/de/file/7fb2f58d2fcc4d48f596e23c122441e8bc0f62cfda923868f1fe1731fe06d8dc/analysis/1391776994/

ALSO: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/828d91af1ebe3f81d909b1e836629bd73d759f72804b3094ecf8a4a690888b00/analysis/1391777096/

REFERENCE:
  • http://jsunpack.jeek.org/?report=21aee5b48f214c4f99c87831e7d0ef38bcf6a694
Detected a Dynamic DNS URL
Detected malicious iframe injection
Detected a TDS URL pattern
  • https://urlquery.net/report.php?id=9276908
---> REMOTE
pvhetiozstg.findhere.org/vc.php?go=2
  • https://www.virustotal.com/de/url/026e9c1d6e32a50a62b715d7f58a057a1e3c68e3df6af13882c745ce2944a6d3/analysis/1391777504/
  • https://www.virustotal.com/de/file/214c3b683099a23da1e8ea88093f2c0ce6234f55f36943f810e031628cb7c93e/analysis/1369498120/
Detected a Dynamic DNS URL
Detected a TDS URL pattern
  • https://urlquery.net/report.php?id=9277385
--------------------------

ALSO:

WORDPRESS VERSION OUTDATED: RISK BEING VULNERABLE

2/06/2014

aromavietnam.com
Malicious Domain Infected with:
HEUR:Trojan.Script.Generic & Trojan.JS.Iframe.aeq
(EXPLOIT from VIETNAM)


MALWARE: EXPLOIT


DOMAIN:
aromavietnam.com
  • https://www.virustotal.com/de/url/ec13cdcd880da204742fbbb17ebb754f78fa9e9916c5d900393e779c09d017bf/analysis/1391695139/

Infected with: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/000ab3f5794c646ded51dd9b66d10749834dce17193ee9da1c28520fd23c52c1/analysis/1391697040/

EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator
  • https://urlquery.net/report.php?id=9256862
  • https://urlquery.net/report.php?id=9258051
  • https://urlquery.net/report.php?id=9258064

--->
173.237.187.203/post.php?id=704732
  • https://www.virustotal.com/de/url/aa23c1e60447fa417c7bf7cd25fdf3257e0b354fb1a37a143b8334b7bd96c1f5/analysis/1391698495/
  • https://urlquery.net/report.php?id=9258108

OTHER MALICIOUS LINK(s):
aromavietnam.com/stmenu.js
  • https://www.virustotal.com/de/url/e30a7f2e0271567938041e58cbccb2b2273e217c83110083ec79c4b747bef41c/analysis/1391694780/

Infected with: Trojan.JS.Iframe.aeq
  • https://www.virustotal.com/de/file/864d33b798d3c718263cb7ed78bea4a007133af53c704f45a54f0ca5e832aaa0/analysis/1391695003/

--->
37.59.120.98/704732.js
  • https://www.virustotal.com/de/url/eef9a6a86ae865da21b27b35623e5756f3569ceacb11a0a0fc444de13c413c0c/analysis/1391696634/
REF.: http://jsunpack.jeek.org/?report=05a453d8b0c4094c355d0f93ec02fe7f9619f4a2


1/19/2014

NEW MALWARE: Exploit.JS.Agent.bnu
found on
www.cretosocostruzioni.it (BLACKHOLE ITALY)



NEW MALWARE found on:
www.cretosocostruzioni.it
  • https://www.virustotal.com/de/url/56d645fd54a3131e943fffc38c7d8d2b08708d7fea96a0359b706e41c10b40ed/analysis/
INFECTED: Exploit.JS.Agent.bnu
  • https://www.virustotal.com/de/file/7fdbf0bce169b0e2ab441fda2d63ac7d7b114b85ec0dff12e509f074150d9f2d/analysis/1390128259/
www.cretosocostruzioni.it/online
  • https://www.virustotal.com/de/url/f2c0777c24805a398d42e4b2fcee5ff98fbd375a42482aac2c019334536fc97b/analysis/1390129080/
INFECTED: Exploit.JS.Agent.bnu
  • https://www.virustotal.com/de/file/742113b12396661ca1c2d2796834169e5543624111f75308b5ef1796d80634d1/analysis/1390128250/
81a338 (BLACKHOLE)
  • https://urlquery.net/report.php?id=8882516
---> REMOTE(s)

DOMAIN:
lanotfo.com
  • https://www.virustotal.com/de/url/6ff7f2d41dd24b4613f5c7f2ddf8045fb0cf966e530535a171dc971168a03bdb/analysis/1390129287/
lanotfo.com/exit.php
  • https://www.virustotal.com/de/url/418aefb901fd9cef797a1419bd4c3b82f15eab2e5fac9688998f3ce1cee83775/analysis/1390129281/
DOMAIN:
gylaqim.com
  • https://www.virustotal.com/de/url/fc04abfc736f83c76d968a82259c71d4382cbb895c2f50e15d345948c08541a9/analysis/1390128973/
gylaqim.com/exit.php
  • https://www.virustotal.com/de/url/fa57933bb759bbb97a034a0ff3ecf1563a51474ad5795f06949b746e58bc6986/analysis/1390128981/
----------------------------------------------------------------------------------------------------------------------------------------------
OTHER RESULTS:
  • http://app.webinspector.com/public/reports/19564893
  • http://wepawet.iseclab.org/view.php?hash=334dfbfddf5c8dd2e23083b3665eb265&t=1390127730&type=js
  • http://zulu.zscaler.com/submission/show/11e7b4c701fdd5cc9d49ceff4e6c058d-1390127849



12/03/2013

SCAMMED UP: Nigerian Lottery SCAM from Mr Peter Chec in Connection with Compromised Website in Slovakia

As i tend to analyse my SPAM-Mails after a certain period of time, i started with a Nigerian SCAMMER, Mister Peter Chec (of course not his real name).



At beginning i thought the Sender as well as the sending Domain were randomly generated:
<izabeth@spsnmnv.sk>
It is clear that izabeth is cut out of the female prename ELizabeth.

Also the first look at the Domainname:
<spsnmnv.sk>
gives you an impression reading spam, like:
<spamnv.sk> or even maybe like sms (Short Message Service)   
<smsnpnv.sk>
And do not forget: .sk stands for Slovakia.

This may also be the reason why Mr. Chec calls himself Chec. For Czechoslovakia (Maybe to lazy to call himself like THAT). And all this coming in german Language from NIGERIA (IP Analysis, see at the bottom of this post). Isn't he a smart guy ? He surley thinks he is, i bet !

I prefer to call him Check Mister Chec.



However, my curiosity took me into digging deeper. So i launched that Domain in and with several Analysing Engines & Tools. No Alert. Even JSUNPACK gave up with a Connection Timeout. Except for one: quttera.com. This website for Anti-Malware is still young, but many times the service surprised me with finding serious threats where all wellknown Multiscanners and/or AVVs did not succeed. I took some Screenshots of that detection, as its possible that the next scan wont bring any results, due to the Cybercriminals wiping their malplaced act & code away, as soon as they get detected.



So, the Malware Source lays in this link:

spsnmnv.sk/mmk/cd/mmk-cd.iso
At this point of time you might think its a small ISO-file. But wrong. Its a TFF-file (extention-file). Now before Quttera's Analyse, i threw it through urlquery:

Here & Here. Nothing ! It is very unusual that, that urlquery does not spit any result out, especially in case of an Exploit. I decided then to change the User Agent as well as the referer. The Outcome is a (17 times-try) MALWARE Download:

Here is what he (Check Mister Chec) wrote (In German ! Smartguy !)
"Lieber Gewinner, 
Wir freuen uns, Ihnen mitzuteilen, dass Ihre E-Mail-Adressen mit Ihrem
Online-Winning Ticket-Nummer (11 14 18 20 37 41 46) mit BONUS (8) Sie haben in
der 2. Kategorie des Spiels gewonnen. Ihr Preis wurde am 10th. November 2013
veröffentlicht. 
Der Lotto Max Lotterie ist vollständig auf einem elektronischen Auswahl der
Gewinner mit ihrer E-Mail-Adressen oder Kauf von Rubbellos. 
Sie sind daher für eine Gesamtsumme von £ 4,000.000.00 britische Pfund
gutgeschrieben Ticketnummer 1EC-16529CE3-8887. Für die sofortige
Freilassung der Ihre Gewinne genehmigt wurde, füllen Sie bitte das Formular
aus und senden Sie es an uns über diese E-Mail:

freelotto3333@gmail.com

 (1) Ihr vollständiger Name: ....
 (2) Kontakt-Adresse: ...
 (3) TELEFON: ....
 (4) Beruf (e) ....
 (5) SEX: ...
 Geburt
 Mr Peter Chec."
Remarkable is here the e-mail adress. If you Google it up, it comes to 4 findings (at this moment of Post). It tells you that this SCAM-Email (Scheme) is still pretty fresh & young. And if you see (at VT) that the Domain spsnmnv.sk is classified as an Educational Institution, the doubts start growing when you check (CHEC) this Screenshot. But its not impossible being one...although.



The IP address (Poor Reputation) to that e-mail: 41.203.69.6
For further info on the IP:
Header Analysis Quick Report
Originating IP: 41.203.69.6
Originating ISP: Globacom Ltd
City: n/a
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline 41.203.69.6

12/01/2013

New Malicious Code - Compromised Domain (Hacked): pupolandia.com (www.pupolandia.com)

Following Domain has been hacked & infiltrated with Malware (Neutrino Exploit Kit):

pupolandia.com Analysis Reports

Neutrino Exploit Kit Clicker.php (TDS)
c0896 Hacked Site Response Hex (Inbound)
c0896 Hacked Site Response (Inbound) 4
Snort Alert
Obfuscated Split String (Double Q) 8


REMOTE DESTINATION TO:

- hr.oncallinteractive.com/clicker.php

Read more about the Neutrino Exploit Kit:

11/26/2013

Symantec:
Blackshades Remote Access Tool (RAT) still being bargained

Cybercriminals are increasingly using the Blackshades Remote Access Tool (RAT), a malicious program whose source code was leaked three years ago, according to an analysis by Symantec.


Santiago Cortes, a security response engineer at Symantec, wrote in a blog post, that Blackshades, which Symantec identifies as W32.Shadesrat”, has been infecting more MS Windows computers and is being controlled by many hundreds of CnC Botnets worldwide, despite the alleged arrest of Michael Hogue (a/k/a “xVisceral,”) in June 2012, the author who wrote the malicious code (program, tool).



As already mentioned, Blackshades is a Remote Access Tool (RAT) that collects usernames and passwords for email and/or Web services, Instant Messaging applications (like ICQ), FTP clients and many more. It has been sold on Black Hat Forums since at least 2010.

It’s common for hackers to use RAT’s, which can be used to upload other Malicious Software to a computer or to destroy and manipulate files. To avoid AV-Software, the program itself is often frequently modified, that is why a Malware Variant changes its name in the eyes of AV-Softwareanalytics, for instance this file is called W32.Shadesrat.C, usually means (like in this case), it’s the 3rd (A,B,C) modified (Variant) or, Generation, if you want so.

In his post, Cortes mentions that Lithuania and the United States have the highest number of command-and-control servers. Mostly all of those "Servers" have hosted exploit kits at some point in time, a type of baited trap that delivers additional malware to CPU’s with software vulnerabilities (don’t forget to update). Referring to Blackshades, Cortes says, that India, the U.S. and the U.K. have the most computers infected with this RAT.

Cortes writes:

“The distribution of the threats suggests that the attackers attempted to infect as many computers as possible, the attackers do not seem to have targeted specific people or companies.”

Earlier this year, Symantec articled in a blog that a license to use Blackshades may cost around $40 to $100 a year.


To this graph, i’d like to point out to 2 earlier Posts of Malicious IPs , that likely shows how involved the small country Luxembourg, in the heart of Europe, is, inbetween Malicious Activity:


Symantec wrote as well that Blackshades had been promoted on underground forums by a person going by the nickname “xVisceral,”


In June 2012, the U.S. Attorney’s Office for the Southern District of New York announced the arrest of Michael Hogue (Rogue?) in Tucson, Arizona. Hogue was arrested with 23 others in a “carding” scheme, which involved trafficking in financial details.


FBI Article: Two-Year FBI Undercover “Carding” Operation Protected Over 400,000 Potential Cyber Crime Victims and Prevented Over $205 Million in Losses

He was charged with conspiracy to commit computer hacking and distribution of malware.

11/24/2013

Category MALICIOUS IP: 80.92.67.155
(Trojan) Heuristic.BehavesLike.Win32.Suspicious.H

The IP Address 80.92.67.155 (IP LOCATIONLuxemburg) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. Specific Malware that has been Found: Heuristic.BehavesLike.Win32.Suspicious.H . This Malicious File stood under communication with the Malicious IP. See 80.92.67.155 IP address information at VT for additional information.

Last detection: 20/11/2013 @ CBL

IP 80.92.67.155 is also listed at Spamhaus.org
IP 80.92.67.155 has 66 Bad Host appearances in Spam E-mail or Spam Post URLs

Other information on this IP:


Other Remarkable Detections on this IP:



SCREENSHOT




RELATED POST: Symantec: Blackshades Remote Access Tool still being bargained