Author Topic: Trojan Ransom  (Read 414130 times)

0 Members and 1 Guest are viewing this topic.

July 23, 2011, 04:56:34 am
Reply #60

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 23, 2011, 05:35:19 am
Reply #61

mc0blck

  • Jr. Member

  • Offline
  • **

  • 14
Amazon
Quote
hxxp://mansboxporn.ru/ (95.211.111.80) -> hxxp://mansboxporn.ru/video.htm (95.211.111.80) -> hxxp://bhtdsnz.ru/in.cgi?2 (95.211.111.80) -> hxxp://ttedhoki.s3.amazonaws.com/index.htm (72.21.214.144) -> hxxp://ttedhoki.s3.amazonaws.com/xxx_video.exe (72.21.214.144)

MBRLocker
Quote
New Blocker: hxxp://ALISSSASEX.ru/ (91.220.0.35) -> hxxp://valaskor.ru/in.cgi?5 (212.124.110.134) -> hxxp://mossdamozxxx.ru/ (91.220.0.35) -> hxxp://mossdamozxxx.ru/xxxvideo.avi.exe (91.220.0.35)
Blocker: hxxp://SOKIZSOSOK.ru/xxxvideo.avi.exe (91.220.0.35)
Blocker: hxxp://ANUSANALZHOPA.ru/xxxvideo.avi.exe (91.220.0.35)

July 23, 2011, 02:09:03 pm
Reply #62

EP_X0FF

  • Guest
Pornorolik back to business

Quote
hxxp://terabytepornovideo.ru/11/video/porno-rolik11.avi.exe
hxxp://terabytepornovideo.ru/12/video/porno-rolik12.avi.exe
hxxp://terabytepornovideo.ru/13/video/porno-rolik13.avi.exe
hxxp://terabytepornovideo.ru/16/video/porno-rolik16.avi.exe
hxxp://terabytepornovideo.ru/17/video/porno-rolik17.avi.exe
hxxp://terabytepornovideo.ru/18/video/porno-rolik18.avi.exe
hxxp://terabytepornovideo.ru/20/video/porno-rolik20.avi.exe

Quote
hxxp://davaypornosei4as.ru/11/video/porno-rolik11.avi.exe
hxxp://davaypornosei4as.ru/12/video/porno-rolik12.avi.exe
hxxp://davaypornosei4as.ru/13/video/porno-rolik13.avi.exe
hxxp://davaypornosei4as.ru/16/video/porno-rolik16.avi.exe
hxxp://davaypornosei4as.ru/17/video/porno-rolik17.avi.exe
hxxp://davaypornosei4as.ru/18/video/porno-rolik18.avi.exe
hxxp://davaypornosei4as.ru/20/video/porno-rolik20.avi.exe

Quote
hxxp://kakpravilnotrahattelok.ru/11/video/porno-rolik11.avi.exe
hxxp://kakpravilnotrahattelok.ru/12/video/porno-rolik12.avi.exe
hxxp://kakpravilnotrahattelok.ru/13/video/porno-rolik13.avi.exe
hxxp://kakpravilnotrahattelok.ru/16/video/porno-rolik16.avi.exe
hxxp://kakpravilnotrahattelok.ru/17/video/porno-rolik17.avi.exe
hxxp://kakpravilnotrahattelok.ru/18/video/porno-rolik18.avi.exe
hxxp://kakpravilnotrahattelok.ru/20/video/porno-rolik20.avi.exe

July 23, 2011, 03:06:41 pm
Reply #63

EP_X0FF

  • Guest
Amazon (previous locations dead)

Quote
hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe

trace path including redirector

Quote
hxxp://ninnporno.ru/ -> hxxp://ninnporno.ru/video.htm -> hxxp://jjkpornoz.ru/in.cgi?2 (95.211.111.80) -> hxxp://3rewporn.s3.amazonaws.com/index.htm -> hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe

where redirector -> jjkpornoz.ru is domain that always on the same IP: 95.211.111.80, so they are basically just generating new domains.
Quote
created:    2011.07.22
paid-till:  2012.07.22


Abuse response from LeaseWeb told me (regarding few previous domain working as redirectors) they will inform their customer about the problem and this is reply to all abuses.


Pornorolik

Quote
hxxp://smotripornomnogoxxx.ru/11/video/porno-rolik11.avi.exe
hxxp://smotripornomnogoxxx.ru/12/video/porno-rolik12.avi.exe
hxxp://smotripornomnogoxxx.ru/13/video/porno-rolik13.avi.exe
hxxp://smotripornomnogoxxx.ru/16/video/porno-rolik16.avi.exe
hxxp://smotripornomnogoxxx.ru/17/video/porno-rolik17.avi.exe
hxxp://smotripornomnogoxxx.ru/18/video/porno-rolik18.avi.exe
hxxp://smotripornomnogoxxx.ru/20/video/porno-rolik20.avi.exe

July 23, 2011, 05:49:17 pm
Reply #64

EP_X0FF

  • Guest
Pornorolik

Quote
hxxp://bestvideopornoxxx.ru/11/video/porno-rolik11.avi.exe
hxxp://bestvideopornoxxx.ru/12/video/porno-rolik12.avi.exe
hxxp://bestvideopornoxxx.ru/13/video/porno-rolik13.avi.exe
hxxp://bestvideopornoxxx.ru/14/video/porno-rolik14.avi.exe
hxxp://bestvideopornoxxx.ru/16/video/porno-rolik16.avi.exe
hxxp://bestvideopornoxxx.ru/17/video/porno-rolik17.avi.exe
hxxp://bestvideopornoxxx.ru/18/video/porno-rolik18.avi.exe
hxxp://bestvideopornoxxx.ru/20/video/porno-rolik20.avi.exe

MBRLocker

Quote
hxxp://soskisoskii.ru/xxxvideo.avi.exe

July 23, 2011, 06:17:02 pm
Reply #65

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Dropped my friends at Leaseweb an e-mail, IP should hopefully be down within the hour.
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 23, 2011, 06:25:46 pm
Reply #66

EP_X0FF

  • Guest
Seems it's already down :) Thanks so much!

July 23, 2011, 08:22:11 pm
Reply #67

mc0blck

  • Jr. Member

  • Offline
  • **

  • 14
Porno-rolik redirector ( + replace 13 on 11-20):
Quote
hxxp://asi-top.ru/gierqwwn.cgi?13 (88.208.33.154)
Blocker: hxxp://traxxxpornoavi.ru/13/ (195.226.220.141) -> hxxp://traxxxpornoavi.ru/13/video/porno-rolik13.avi.exe (195.226.220.141)

Amazon
Quote
Blocker: hxxp://scdporno.ru/ (91.221.99.241) -> hxxp://uiupoba12.ru/go.php?sid=1 (91.221.99.241) -> hxxp://porn4tow.s3.amazonaws.com/index.htm (72.21.214.42) -> hxxp://porn4tow.s3.amazonaws.com/xxx_video.exe (72.21.214.42)
Blocker: hxxp://pornpojpor.ru/ (95.211.111.80) -> hxxp://nixposdss.ru/in.cgi?2 (95.211.111.80) -> hxxp://3rewporn.s3.amazonaws.com/index.htm (72.21.203.149) -> hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe (72.21.203.149)
Blocker: hxxp://xxxbuxc.s3.amazonaws.com/index.htm (72.21.214.144) -> hxxp://xxxbuxc.s3.amazonaws.com/xxx_video.exe (72.21.214.144)
Blocker: hxxp://ninnporno.ru/ (95.211.111.80) -> hxxp://ninnporno.ru/video.htm (95.211.111.80) -> hxxp://movhpornd.ru/in.cgi?2 (95.211.111.80) -> hxxp://3rewporn.s3.amazonaws.com/index.htm (72.21.203.149) -> hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe (72.21.203.149)
Blocker: hxxp://fingopas.s3.amazonaws.com/index.htm (72.21.194.23) -> hxxp://fingopas.s3.amazonaws.com/xxx_video.exe (72.21.194.23)

July 24, 2011, 01:59:56 am
Reply #68

EP_X0FF

  • Guest
Amazon ransom trace

Quote
hxxp://scdporno.ru/ -> hxxp://scdporno.ru/video.htm -> hxxp://uiupoba12.ru/go.php?sid=1 -> hxxp://ebatporkas.s3.amazonaws.com/index.htm -> hxxp://ebatporkas.s3.amazonaws.com/xxx_video.exe

update ebatporkas.s3.amazonaws.com taken down, 404.

New trace

Quote
hxxp://amkkporno.ru/ -> hxxp://amkkporno.ru/video.htm -> hxxp://uiupoba12.ru/go.php?sid=1 -> hxxp://azxpoixx.s3.amazonaws.com/index.htm -> hxxp://azxpoixx.s3.amazonaws.com/xxx_video.exe

update azxpoixx.s3.amazonaws.com taken down, 404

Redirectors seems moved to Latvia.

Pornorolik domain

Quote
hxxp://zapretnoepornokruto.ru/11/video/porno-rolik11.avi.exe
hxxp://zapretnoepornokruto.ru/12/video/porno-rolik12.avi.exe
hxxp://zapretnoepornokruto.ru/13/video/porno-rolik13.avi.exe
hxxp://zapretnoepornokruto.ru/16/video/porno-rolik16.avi.exe
hxxp://zapretnoepornokruto.ru/17/video/porno-rolik17.avi.exe
hxxp://zapretnoepornokruto.ru/18/video/porno-rolik18.avi.exe
hxxp://zapretnoepornokruto.ru/20/video/porno-rolik20.avi.exe

Quote
hxxp://megabytespornovideo.ru/11/video/porno-rolik11.avi.exe
hxxp://megabytespornovideo.ru/12/video/porno-rolik12.avi.exe
hxxp://megabytespornovideo.ru/13/video/porno-rolik13.avi.exe
hxxp://megabytespornovideo.ru/16/video/porno-rolik16.avi.exe
hxxp://megabytespornovideo.ru/17/video/porno-rolik17.avi.exe
hxxp://megabytespornovideo.ru/18/video/porno-rolik18.avi.exe
hxxp://megabytespornovideo.ru/20/video/porno-rolik20.avi.exe

Redirector to MBRLocker (likely Russian IP required to make it work)

hxxp://valaskor.ru/in.cgi?5 (212.124.110.134)

hxxp://212.124.110.134/in.cgi?5 <- working well for me.

Regarding to this redirector. This is another mutant, that previously was named habrmabrt.ru, tdschtotakoetds.ru, all hosts on the same IP. And all used to be MBRLock redirectors.
DigitalOne AG has ignored abuse we've sent 4 days ago.

Quote
inetnum:        212.124.108.0 - 212.124.111.255
netname:        DIGITALONE-NET
descr:          DigitalOne AG Colocation and Dedicated Servers
remarks:        --------------------------------------------------
remarks:        Please, send abuse reports to abuse@digitalone.com
remarks:        --------------------------------------------------
country:        US
admin-c:        DA440-RIPE
tech-c:         DA440-RIPE
status:         ASSIGNED PA
mnt-by:         MNT-TRI
changed:        noc@digitalone.com 20091111
source:         RIPE

role:           DigitalOne AG
address:        12100 Sunrise Valley Drive
address:        Reston, VA 20191, United States
e-mail:         noc@digitalone.com
abuse-mailbox:  abuse@digitalone.com
admin-c:        SO1294-RIPE
tech-c:         SO1294-RIPE
nic-hdl:        DA440-RIPE
mnt-by:         MNT-TRI
changed:        noc@digitalone.com 20091111
source:         RIPE

% Information related to '212.124.108.0/22AS47328'

route:          212.124.108.0/22
descr:          True Records Inc.
remarks:        ------------------------------------------------------
remarks:        Routing, peering and security:         noc@truerec.com
remarks:        Spam reports and abuse:              abuse@truerec.com
remarks:        ------------------------------------------------------
origin:         AS47328
mnt-by:         MNT-TRI
changed:        noc@truerec.com 20090630
source:         RIPE

July 24, 2011, 10:10:34 am
Reply #69

EP_X0FF

  • Guest
Some other redirector revealed.

hxxp://asi-top.ru/gifeesdccz.cgi?12 (88.208.33.154, ADVANCEDHOSTERS-NET) it will redirect you to pornorolik domains (all on the 195.226.220.141)
Changing the id used in as param of gifeesdccz.cgi?id gives the following locations

Quote
hxxp://domatolkodetixxx.ru/11/video/porno-rolik11.avi.exe
hxxp://domatolkodetixxx.ru/12/video/porno-rolik12.avi.exe
hxxp://domatolkodetixxx.ru/13/video/porno-rolik13.avi.exe
hxxp://domatolkodetixxx.ru/16/video/porno-rolik16.avi.exe
hxxp://domatolkodetixxx.ru/17/video/porno-rolik17.avi.exe
hxxp://domatolkodetixxx.ru/18/video/porno-rolik18.avi.exe
hxxp://domatolkodetixxx.ru/20/video/porno-rolik20.avi.exe

July 24, 2011, 10:33:37 am
Reply #70

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
DigitalOne AG has ignored abuse we've sent 4 days ago.

DigitalOne have a US address but are a Swiss company, and known to be bulletproof (just like their upstream). I'll have another word with True Records upstream and see what we can do about this.
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

July 24, 2011, 11:34:42 am
Reply #71

EP_X0FF

  • Guest
Thanks :)

Fresh pornoroliks (binaries updating with new unlock codes, tel numbers)

Quote
hxxp://lolkorussiangirlsporno.ru/11/video/porno-rolik11.avi.exe
hxxp://lolkorussiangirlsporno.ru/12/video/porno-rolik12.avi.exe
hxxp://lolkorussiangirlsporno.ru/13/video/porno-rolik13.avi.exe
hxxp://lolkorussiangirlsporno.ru/16/video/porno-rolik16.avi.exe
hxxp://lolkorussiangirlsporno.ru/17/video/porno-rolik17.avi.exe
hxxp://lolkorussiangirlsporno.ru/18/video/porno-rolik18.avi.exe
hxxp://lolkorussiangirlsporno.ru/20/video/porno-rolik20.avi.exe

Amazon
Quote
hxxp://tix3porn.s3.amazonaws.com/xxx_video.exe

July 24, 2011, 04:17:19 pm
Reply #72

EP_X0FF

  • Guest
Amazon update site down, 404
Quote
hxxp://rim5tporn.s3.amazonaws.com/xxx_video.exe

Pornorolik

Quote
hxxp://russkieebutteloknaprirode.ru/11/video/porno-rolik11.avi.exe
hxxp://russkieebutteloknaprirode.ru/12/video/porno-rolik12.avi.exe
hxxp://russkieebutteloknaprirode.ru/13/video/porno-rolik13.avi.exe
hxxp://russkieebutteloknaprirode.ru/16/video/porno-rolik16.avi.exe
hxxp://russkieebutteloknaprirode.ru/17/video/porno-rolik17.avi.exe
hxxp://russkieebutteloknaprirode.ru/18/video/porno-rolik18.avi.exe
hxxp://russkieebutteloknaprirode.ru/20/video/porno-rolik20.avi.exe

July 24, 2011, 06:19:29 pm
Reply #73

EP_X0FF

  • Guest
Amazon ransom starts spreading through their new hosting previously used only for redirectors.

Quote
hxxp://PORNBIJJIN.ru/ (91.221.99.241) -> hxxp://PORNBIJJIN.ru/xxx_video.exe (91.221.99.241)
hxxp://PORNODAPORN.ru/ (91.221.99.241) -> hxxp://PORNODAPORN.ru/xxx_video.exe (91.221.99.241)
hxxp://XRASVIXPORN.ru/ (91.221.99.241) -> hxxp://XRASVIXPORN.ru/xxx_video.exe (91.221.99.241)

Quote
hxxp://z4nixxxi.s3.amazonaws.com/index.htm (72.21.211.171) -> hxxp://z4nixxxi.s3.amazonaws.com/xxx_video.exe (72.21.211.171)

this list is courtesy of mc0blck :)

July 25, 2011, 09:05:44 am
Reply #74

EP_X0FF

  • Guest
I've done some research in case of Amazon ransom and found their sites actually contains obfuscated redirection code that leads to another server, full of exploits.

Below is the links I've gathered from there.

Page with exploit pack, gives fake 404 error, code obfuscated
Quote
hxxp://6g12w.ru/indexx.php?tp=8b797d0916c09fa8

6g12w.ru
IP: 85.15.231.110

Quote
inetnum:        85.15.231.107 - 85.15.231.122
netname:        LE_Collocation
mnt-by:         latvenergo-mnt
descr:          SIA "Projektam.lv" clients
country:        LV
admin-c:        SL666
tech-c:         SL666
status:         ASSIGNED PA
mnt-by:         projektamlv-mnt
changed:        meistars@projektam.lv 20110308
source:         RIPE

person:         Solution Solution6
address:        SL666
abuse-mailbox:  solutionsolution6@gmail.com
phone:          +37126546676
nic-hdl:        SL666
mnt-by:         projektamlv-mnt
changed:        meistars@projektam.lv 20110308
source:         RIPE


Trojan ransom similar to that located on Amazon WS
Quote
hxxp://6g12w.ru/d.php?f=236&e=2

There can be more files, I just deobfuscated page and quickly looked inside.

Amazon ransom I've examined to get this results
Quote
hxxp://kinvivifas.s3.amazonaws.com/index.htm

Binary itself
Quote
hxxp://kinvivifas.s3.amazonaws.com/xxx_video.exe

Exploit PDF (Exploit.JS.Pdfka.eka) extracted from sploit pack code:
Quote
hxxp://6g12w.ru/games/2fdp.php?f=236


Some malware Java package (Exploit.Java.229)
Quote
hxxp://6g12w.ru/games/worms.jar

+ some other stuff for Java
Quote
hxxp://6g12w.ru/games/java_trust.php?f=236