A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5392  by Xylitol
 Thu Mar 10, 2011 3:11 am
wow, sample have evolved !
loc: hXXp://axaxd.com/porno_video1019.avi.exe

Image

Image

Image

Image

Image
Code: Select all
Number to Call: 9636254756
Number to Call: 9646284189
Number to Call: 9645730849
Number to Call: 9057922996
Number to Call: 9652637446
Code to unlock Windows: 852852
Attachments
See archive comment for password
(757.09 KiB) Downloaded 62 times
 #5458  by Xylitol
 Mon Mar 14, 2011 6:19 am
updated and full undetected https://www.virustotal.com/file-scan/re ... 1300080800

hXXp://welkhwlcc.ru/pornoxxx_video891134.exe
Attachments
See archive comment for password
(788.27 KiB) Downloaded 57 times
 #5571  by Xylitol
 Mon Mar 21, 2011 4:45 am
yay like the good old time
loc: hXXp://rutrahxxx.ru/xxxvideo_best_porno.avi.exe

Image

Image

Image

Result: 0 /43 (0.0%)
https://www.virustotal.com/file-scan/re ... 1300671945
Attachments
See archive comment for password
(829.68 KiB) Downloaded 64 times
 #7309  by EP_X0FF
 Fri Jul 15, 2011 4:18 pm
@ Sotherbee

All malware requests must be only in dedicated topic. For "how to" format your request refer to first post in Malware Requests topic.
All malware requests not in this topic will be removed automatically.
 #7510  by EP_X0FF
 Fri Jul 22, 2011 2:22 pm
This business won't be dead in near perspective :) Because it's very easy money and it almost safe for criminals. Until they do not realize that someone knocking in their doors with arrest order - this will continue.

10. They buying a lot of tel numbers (likely with help and support inside Russian tel operators, with discount, or for free if affiliated).

20. Next they doing fast copy-past in Delphi/C++ (whatever), packing this with primitive crypter (passing build through private av-check board, cleaning signatures if needed) and uploading to the internet (if no money or they are greedy - using free hosting, otherwise something low cost outside Russia).

30. If only one victim will pay on only one number - it's already PROFIT. After few days guys closing phone bills and getting money.

40. GOTO 10.
 #7524  by rkhunter
 Fri Jul 22, 2011 7:58 pm
May be is present list of dark side hosting providers on Russia/Ukraine, who distribute blockers? As i know it distribute from porno sites and legal hosts as Narod/Yandex.
 #7534  by EP_X0FF
 Sat Jul 23, 2011 1:42 am
Ransoms are heavily distributed through tizer networks. They are not only on pornosites etc. For example you browsing some online library - and suddenly some annoying banner appears on the screen. You click [x] and immediately forwarded to malware host full of ransoms and exploits (like in case of MBRlocker, Lock'Em'All).

Without local authorities contribution - this is endless eight.