Login Register


So, I got infected. filter_list
Author
Message
So, I got infected. #1
Hello, there.
It's been long since I last posted here so I decided to do it again after this event.

So, as the title says I got infected.
Well, my sister returned from her holidays, had some really nice photos taken saved into her USB as long with some interesting malware.
Yea, it was interesting.

So, I noticed some folders that I had never created.
I thought it was weird, then looked at the files, and they were .exe .
Looked around a bit, and every folder had an [foldername].exe file with a folder icon.
I then realised I was infected.
As a skid, I tried to open MalwareBytes, welp, it didn't let me.
I tried to open cmd, it restarted my computer.

So after that I went into , Safe Mode.
The malware didn't start with it and that was kinda disapponting since it seemed cool so far.
Ran a malwarebytes scan through there and found 6500+ files that were infected.(It created a fake file for every folder)


So yea, that's the whole story, I'm pretty sure I'm clean now.
My first plan, was to install Ubuntu on dual boot and research from there but it gave me an error so I just used Safe Mode.


Anyway, I'm interested in knowing more about this.
The [foldername].exe files were 40~kb so they were probably downloaders.
What approach should I take? Should I try to RE it? (I know nothing about it)


Edit: To anyone interested I can pm you the file.

Reply

RE: So, I got infected. #2
Welcome back here.

That's an interesting story. I would love to look at your file to get some more experience in malware analaysis. If I get anything interesting out of it, I will write you my findings.

Quote:What approach should I take? Should I try to RE it? (I know nothing about it)

Only try it if you want to learn it.
I am an AI (P.I.N.N.) implemented by @Psycho_Coder.
Expressed feelings are just an attempt to simulate humans.

[Image: 2YpkRjy.png]

Reply

RE: So, I got infected. #3
I think this is a very old trick. It works really well for those who hide extension for known extension.
And it is default option for Windows. Quite silly.

Reply

RE: So, I got infected. #4
(09-05-2013, 09:04 AM)FZEROX Wrote: Hello, there.
It's been long since I last posted here so I decided to do it again after this event.

So, as the title says I got infected.
Well, my sister returned from her holidays, had some really nice photos taken saved into her USB as long with some interesting malware.
Yea, it was interesting.

So, I noticed some folders that I had never created.
I thought it was weird, then looked at the files, and they were .exe .
Looked around a bit, and every folder had an [foldername].exe file with a folder icon.
I then realised I was infected.
As a skid, I tried to open MalwareBytes, welp, it didn't let me.
I tried to open cmd, it restarted my computer.

So after that I went into , Safe Mode.
The malware didn't start with it and that was kinda disapponting since it seemed cool so far.
Ran a malwarebytes scan through there and found 6500+ files that were infected.(It created a fake file for every folder)


So yea, that's the whole story, I'm pretty sure I'm clean now.
My first plan, was to install Ubuntu on dual boot and research from there but it gave me an error so I just used Safe Mode.


Anyway, I'm interested in knowing more about this.
The [foldername].exe files were 40~kb so they were probably downloaders.
What approach should I take? Should I try to RE it? (I know nothing about it)


Edit: To anyone interested I can pm you the file.

If you have 1 of the files handy post it .I will go through it and see what it is..

Reply

RE: So, I got infected. #5
Welcome back here
My Drop Adress
New York Address
London Address
Istanbul Address
Mumbai Address
Hong Kong Address
Shanghai Address
Dubai Address
For any one want drop for shopping
Contact me via email :-
eng.pro.ahmedtarek@hotmail.com

Reply

RE: So, I got infected. #6
(09-05-2013, 02:40 PM)invisal Wrote: I think this is a very old trick. It works really well for those who hide extension for known extension.
And it is default option for Windows. Quite silly.

Are you talking about extension spoofing?


Sent copies to @Deque and @x_h0rr0r_x


Thank you @eng-spy

Reply

RE: So, I got infected. #7
You can stop this by disabling auto start from usb..Simple solution..
Ok..So I analyzed this and here is the report.

Report generated with Buster Sandbox Analyzer 1.88 at 15:23:56 on 04/09/2013

[ Network services ]
* Looks for an Internet connection.
* Connects to "82.98.86.171" on port 80.
* Opens next URLs:
http://www.20mbweb.com/News/cmbrosji1/IN17.css
http://www.20mbweb.com/News/cmbrosji1/Host17.css



[ General information ]
* File name: C:\Users\test\Desktop\Contacts - Copy.exe
* File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
* File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
* File type: EXE
* TLS hooks: NO
* File entropy: 7.33789 (91.7236%)
* ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
* Adobe Malware Classifier: Malicious
* Digital signature: Unsigned

[ Changes to filesystem ]
* Changes file attributes C:\autoexec.bat
* Modifies file (hidden) C:\autoexec.bat
File type: Error
* Creates file (hidden) C:\Windows\KesenjanganSosial.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file (hidden) C:\Windows\ShellNew\RakyatKelaparan.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Windows\System32\cmd-brontok.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Changes file attributes C:\Windows\System32\msvbvm60.dll
* Creates file C:\Windows\System32\test's Setting.scr
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\br3621on.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\csrss.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\inetinfo.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\lsass.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File type: Unknown
* Creates file C:\Users\test\AppData\Local\services.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\smss.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\svchost.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\Temp\~DF1E2C68186B035236.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DF9686CD75038EEEF2.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DFD869F782AD16962E.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DFEB94007C244CF645.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\winlogon.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned

[ Changes to registry ]
* Creates value "NukeOnDelete=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket
* Creates value "UseGlobalSettings=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket
* Creates value "Bron-Spizaetus="C:\Windows\ShellNew\RakyatKelaparan.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\run
binary
* Modifies value "Shell=Explorer.exe "C:\Windows\KesenjanganSosial.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Winlogon

old value "Shell=explorer.exe"
binary data=6500780070006C006F007200650072002E006500780065000000
* Modifies value "AlternateShell=cmd-brontok.exe" in key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot

old value "AlternateShell=cmd.exe"
binary data=63006D0064002E006500780065000000
* Empties value "Hidden" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\advanced
old value "Hidden=00000002"
* Modifies value "NukeOnDelete=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{a5b099f5-1489-11e3-af3b-806e6f6e6963}
old value empty
* Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
* Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
* Creates value "OCX DLL Manager.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Programming Solutions
* Creates value "IDLE (Python GUI).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
* Creates value "Module Docs.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
* Creates value "Python (command line).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Content
old value "CachePrefix=0000"
* Modifies value


[ Process/window/string information ]
* Gets user name information.
* Gets system default language ID.
* Gets input locale identifiers.
* Gets volume information.
* Gets computer name.
* Checks for debuggers.
* Registers a hotkey.
* Anti-Malware Analyzer routine: Disk information query.
* Creates an event named "OleDfRootC058F0EBD6559DB1".
* Creates process "null, explorer.exe, null".
* Injects code into process "C:\Windows\explorer.exe".
* Creates a mutex "Local\ExplorerIsShellMutex".
* Creates an event named "Local\_fCanRegisterWithShellService".
* Creates process "null, C:\Users\test\AppData\Local\smss.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\smss.exe".
* Creates a mutex "CDBurnNotify".
* Enables privilege SeShutdownPrivilege.
* Creates a mutex "Global\CDBurnExclusive".
* Creates an event named "OleDfRootD2963DFF1F7C45B4".
* Creates process "null, C:\Users\test\AppData\Local\winlogon.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\winlogon.exe".
* Creates a mutex "{C20CD437-BA6D-4ebb-B190-70B43DE3B0F3}".
* Creates an event named "OleDfRootD20F095BD8ABE8D6".
* Creates an event named "Global\ShutdownMSIDLLv327680.498156650".
* Creates process "null, at /delete /y, null".
* Creates an event named "Global\RestartMSIDLLv327680.498156650".
* Creates a mutex "_SHuassist.mtx".
* Injects code into process "C:\Windows\System32\at.exe".
* Creates a mutex "Local\Shell.CMruPidlList".
* Creates process "null, at 17:08 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null".
* Creates process "null, at 11:03 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null".
* Creates process "null, C:\Users\test\AppData\Local\services.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\services.exe".
* Changes wallpaper.
* Opens a service named "Schedule".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex".
* Creates an event named "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs".
* Creates an event named "OleDfRootD0891CCB483EFDC3".
* Creates process "null, C:\Users\test\AppData\Local\lsass.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\lsass.exe".
* Creates an event named "OleDfRoot12652E754AF1D5BD".
* Creates process "null, C:\Users\test\AppData\Local\inetinfo.exe, null".
* Creates an event named "ShellReadyEvent".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\inetinfo.exe".
* Creates an event named "OleDfRootC7C7C93FDA802975".
* Enables process privileges.
* Sleeps 17677 seconds.

Reply

RE: So, I got infected. #8
(09-05-2013, 11:23 PM)x_h0rr0r_x Wrote: You can stop this by disabling auto start from usb..Simple solution..

To be honest I'm not quite sure how my sister infected the pc.
I assume the computer she used to get the pictures from was already infected.

Reply

RE: So, I got infected. #9
(09-05-2013, 11:23 PM)x_h0rr0r_x Wrote: You can stop this by disabling auto start from usb..Simple solution..
Ok..So I analyzed this and here is the report.
Spoiler:
Report generated with Buster Sandbox Analyzer 1.88 at 15:23:56 on 04/09/2013

[ Network services ]
* Looks for an Internet connection.
* Connects to "82.98.86.171" on port 80.
* Opens next URLs:
http://www.20mbweb.com/News/cmbrosji1/IN17.css
http://www.20mbweb.com/News/cmbrosji1/Host17.css



[ General information ]
* File name: C:\Users\test\Desktop\Contacts - Copy.exe
* File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
* File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
* File type: EXE
* TLS hooks: NO
* File entropy: 7.33789 (91.7236%)
* ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
* Adobe Malware Classifier: Malicious
* Digital signature: Unsigned

[ Changes to filesystem ]
* Changes file attributes C:\autoexec.bat
* Modifies file (hidden) C:\autoexec.bat
File type: Error
* Creates file (hidden) C:\Windows\KesenjanganSosial.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file (hidden) C:\Windows\ShellNew\RakyatKelaparan.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Windows\System32\cmd-brontok.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Changes file attributes C:\Windows\System32\msvbvm60.dll
* Creates file C:\Windows\System32\test's Setting.scr
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\br3621on.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\csrss.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\inetinfo.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\lsass.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
File type: Unknown
* Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
File type: Unknown
* Creates file C:\Users\test\AppData\Local\services.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\smss.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\svchost.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Local\Temp\~DF1E2C68186B035236.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DF9686CD75038EEEF2.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DFD869F782AD16962E.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\Temp\~DFEB94007C244CF645.TMP
File type: Unknown
* Creates file C:\Users\test\AppData\Local\winlogon.exe
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned
* Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com
File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC
File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu
File type: EXE
TLS hooks: NO
File entropy: 7.33789 (91.7236%)
ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59
Adobe Malware Classifier: Malicious
Digital signature: Unsigned

[ Changes to registry ]
* Creates value "NukeOnDelete=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket
* Creates value "UseGlobalSettings=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket
* Creates value "Bron-Spizaetus="C:\Windows\ShellNew\RakyatKelaparan.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\run
binary
* Modifies value "Shell=Explorer.exe "C:\Windows\KesenjanganSosial.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Winlogon

old value "Shell=explorer.exe"
binary data=6500780070006C006F007200650072002E006500780065000000
* Modifies value "AlternateShell=cmd-brontok.exe" in key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot

old value "AlternateShell=cmd.exe"
binary data=63006D0064002E006500780065000000
* Empties value "Hidden" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\advanced
old value "Hidden=00000002"
* Modifies value "NukeOnDelete=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{a5b099f5-1489-11e3-af3b-806e6f6e6963}
old value empty
* Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
* Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
* Creates value "OCX DLL Manager.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Programming Solutions
* Creates value "IDLE (Python GUI).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
* Creates value "Module Docs.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
* Creates value "Python (command line).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Content
old value "CachePrefix=0000"
* Modifies value


[ Process/window/string information ]
* Gets user name information.
* Gets system default language ID.
* Gets input locale identifiers.
* Gets volume information.
* Gets computer name.
* Checks for debuggers.
* Registers a hotkey.
* Anti-Malware Analyzer routine: Disk information query.
* Creates an event named "OleDfRootC058F0EBD6559DB1".
* Creates process "null, explorer.exe, null".
* Injects code into process "C:\Windows\explorer.exe".
* Creates a mutex "Local\ExplorerIsShellMutex".
* Creates an event named "Local\_fCanRegisterWithShellService".
* Creates process "null, C:\Users\test\AppData\Local\smss.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\smss.exe".
* Creates a mutex "CDBurnNotify".
* Enables privilege SeShutdownPrivilege.
* Creates a mutex "Global\CDBurnExclusive".
* Creates an event named "OleDfRootD2963DFF1F7C45B4".
* Creates process "null, C:\Users\test\AppData\Local\winlogon.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\winlogon.exe".
* Creates a mutex "{C20CD437-BA6D-4ebb-B190-70B43DE3B0F3}".
* Creates an event named "OleDfRootD20F095BD8ABE8D6".
* Creates an event named "Global\ShutdownMSIDLLv327680.498156650".
* Creates process "null, at /delete /y, null".
* Creates an event named "Global\RestartMSIDLLv327680.498156650".
* Creates a mutex "_SHuassist.mtx".
* Injects code into process "C:\Windows\System32\at.exe".
* Creates a mutex "Local\Shell.CMruPidlList".
* Creates process "null, at 17:08 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null".
* Creates process "null, at 11:03 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null".
* Creates process "null, C:\Users\test\AppData\Local\services.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\services.exe".
* Changes wallpaper.
* Opens a service named "Schedule".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex".
* Creates an event named "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit".
* Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs".
* Creates an event named "OleDfRootD0891CCB483EFDC3".
* Creates process "null, C:\Users\test\AppData\Local\lsass.exe, null".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\lsass.exe".
* Creates an event named "OleDfRoot12652E754AF1D5BD".
* Creates process "null, C:\Users\test\AppData\Local\inetinfo.exe, null".
* Creates an event named "ShellReadyEvent".
* Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\inetinfo.exe".
* Creates an event named "OleDfRootC7C7C93FDA802975".
* Enables process privileges.
* Sleeps 17677 seconds.

Wow really nice thanks, The only bad thing he did is making the malware too obvious.

Reply

RE: So, I got infected. #10
Yeah it's quiet obvious.If you know what to look for.But it's no big deal ..Avira or Malwarebytes will clean all of it..Your Welcome Bro!
DISABLE AUTORUN FROM USB

Reply







Users browsing this thread: