![]() |
|
So, I got infected. - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Computers (https://sinister.ly/Forum-Computers) +--- Forum: Antivirus & Protection (https://sinister.ly/Forum-Antivirus-Protection) +--- Thread: So, I got infected. (/Thread-So-I-got-infected) Pages:
1
2
|
So, I got infected. - unnamed - 09-05-2013 Hello, there. It's been long since I last posted here so I decided to do it again after this event. So, as the title says I got infected. Well, my sister returned from her holidays, had some really nice photos taken saved into her USB as long with some interesting malware. Yea, it was interesting. So, I noticed some folders that I had never created. I thought it was weird, then looked at the files, and they were .exe . Looked around a bit, and every folder had an [foldername].exe file with a folder icon. I then realised I was infected. As a skid, I tried to open MalwareBytes, welp, it didn't let me. I tried to open cmd, it restarted my computer. So after that I went into , Safe Mode. The malware didn't start with it and that was kinda disapponting since it seemed cool so far. Ran a malwarebytes scan through there and found 6500+ files that were infected.(It created a fake file for every folder) So yea, that's the whole story, I'm pretty sure I'm clean now. My first plan, was to install Ubuntu on dual boot and research from there but it gave me an error so I just used Safe Mode. Anyway, I'm interested in knowing more about this. The [foldername].exe files were 40~kb so they were probably downloaders. What approach should I take? Should I try to RE it? (I know nothing about it) Edit: To anyone interested I can pm you the file. RE: So, I got infected. - Deque - 09-05-2013 Welcome back here. That's an interesting story. I would love to look at your file to get some more experience in malware analaysis. If I get anything interesting out of it, I will write you my findings. Quote:What approach should I take? Should I try to RE it? (I know nothing about it) Only try it if you want to learn it. RE: So, I got infected. - invisal - 09-05-2013 I think this is a very old trick. It works really well for those who hide extension for known extension. And it is default option for Windows. Quite silly. RE: So, I got infected. - x_h0rr0r_x - 09-05-2013 (09-05-2013, 09:04 AM)FZEROX Wrote: Hello, there. If you have 1 of the files handy post it .I will go through it and see what it is.. RE: So, I got infected. - eng-spy - 09-05-2013 Welcome back here RE: So, I got infected. - unnamed - 09-05-2013 (09-05-2013, 02:40 PM)invisal Wrote: I think this is a very old trick. It works really well for those who hide extension for known extension. Are you talking about extension spoofing? Sent copies to @Deque and @x_h0rr0r_x Thank you @eng-spy RE: So, I got infected. - x_h0rr0r_x - 09-05-2013 You can stop this by disabling auto start from usb..Simple solution.. Ok..So I analyzed this and here is the report. Report generated with Buster Sandbox Analyzer 1.88 at 15:23:56 on 04/09/2013 [ Network services ] * Looks for an Internet connection. * Connects to "82.98.86.171" on port 80. * Opens next URLs: http://www.20mbweb.com/News/cmbrosji1/IN17.css http://www.20mbweb.com/News/cmbrosji1/Host17.css [ General information ] * File name: C:\Users\test\Desktop\Contacts - Copy.exe * File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC * File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu * File type: EXE * TLS hooks: NO * File entropy: 7.33789 (91.7236%) * ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 * Adobe Malware Classifier: Malicious * Digital signature: Unsigned [ Changes to filesystem ] * Changes file attributes C:\autoexec.bat * Modifies file (hidden) C:\autoexec.bat File type: Error * Creates file (hidden) C:\Windows\KesenjanganSosial.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file (hidden) C:\Windows\ShellNew\RakyatKelaparan.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Windows\System32\cmd-brontok.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Changes file attributes C:\Windows\System32\msvbvm60.dll * Creates file C:\Windows\System32\test's Setting.scr File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\br3621on.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\csrss.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\inetinfo.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\lsass.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db File type: Unknown * Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db File type: Unknown * Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db File type: Unknown * Modifies file C:\Users\test\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db File type: Unknown * Creates file C:\Users\test\AppData\Local\services.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\smss.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\svchost.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Local\Temp\~DF1E2C68186B035236.TMP File type: Unknown * Creates file C:\Users\test\AppData\Local\Temp\~DF9686CD75038EEEF2.TMP File type: Unknown * Creates file C:\Users\test\AppData\Local\Temp\~DFD869F782AD16962E.TMP File type: Unknown * Creates file C:\Users\test\AppData\Local\Temp\~DFEB94007C244CF645.TMP File type: Unknown * Creates file C:\Users\test\AppData\Local\winlogon.exe File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned * Creates file C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com File signature (PEiD): MEW 11 1.2 -> NorthFox/HCC File signature (Exeinfo): MEW 11 SE 1.2 by Northfox (2004) - http://Northfox.uw.hu File type: EXE TLS hooks: NO File entropy: 7.33789 (91.7236%) ssdeep signature: 768:hzx/4NOHLJ4bc0xn6hU+HjGnGEe2v35BMCJ:RBrHLccKnH+aLeA59 Adobe Malware Classifier: Malicious Digital signature: Unsigned [ Changes to registry ] * Creates value "NukeOnDelete=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket * Creates value "UseGlobalSettings=00000001" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\BitBucket * Creates value "Bron-Spizaetus="C:\Windows\ShellNew\RakyatKelaparan.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\run binary * Modifies value "Shell=Explorer.exe "C:\Windows\KesenjanganSosial.exe"" in key HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Winlogon old value "Shell=explorer.exe" binary data=6500780070006C006F007200650072002E006500780065000000 * Modifies value "AlternateShell=cmd-brontok.exe" in key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot old value "AlternateShell=cmd.exe" binary data=63006D0064002E006500780065000000 * Empties value "Hidden" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\advanced old value "Hidden=00000002" * Modifies value "NukeOnDelete=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{a5b099f5-1489-11e3-af3b-806e6f6e6963} old value empty * Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware * Creates value "Malwarebytes Anti-Malware.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware * Creates value "OCX DLL Manager.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Programming Solutions * Creates value "IDLE (Python GUI).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3 * Creates value "Module Docs.lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3 * Creates value "Python (command line).lnk=00000001" in key HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\test\AppData\Roaming\Content old value "CachePrefix=0000" * Modifies value [ Process/window/string information ] * Gets user name information. * Gets system default language ID. * Gets input locale identifiers. * Gets volume information. * Gets computer name. * Checks for debuggers. * Registers a hotkey. * Anti-Malware Analyzer routine: Disk information query. * Creates an event named "OleDfRootC058F0EBD6559DB1". * Creates process "null, explorer.exe, null". * Injects code into process "C:\Windows\explorer.exe". * Creates a mutex "Local\ExplorerIsShellMutex". * Creates an event named "Local\_fCanRegisterWithShellService". * Creates process "null, C:\Users\test\AppData\Local\smss.exe, null". * Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\smss.exe". * Creates a mutex "CDBurnNotify". * Enables privilege SeShutdownPrivilege. * Creates a mutex "Global\CDBurnExclusive". * Creates an event named "OleDfRootD2963DFF1F7C45B4". * Creates process "null, C:\Users\test\AppData\Local\winlogon.exe, null". * Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\winlogon.exe". * Creates a mutex "{C20CD437-BA6D-4ebb-B190-70B43DE3B0F3}". * Creates an event named "OleDfRootD20F095BD8ABE8D6". * Creates an event named "Global\ShutdownMSIDLLv327680.498156650". * Creates process "null, at /delete /y, null". * Creates an event named "Global\RestartMSIDLLv327680.498156650". * Creates a mutex "_SHuassist.mtx". * Injects code into process "C:\Windows\System32\at.exe". * Creates a mutex "Local\Shell.CMruPidlList". * Creates process "null, at 17:08 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null". * Creates process "null, at 11:03 /every:M,T,W,Th,F,S,Su "C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates\5424-NendangBro.com", null". * Creates process "null, C:\Users\test\AppData\Local\services.exe, null". * Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\services.exe". * Changes wallpaper. * Opens a service named "Schedule". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex". * Creates an event named "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterEvent". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit". * Creates a mutex "Global\C::Users:test:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs". * Creates an event named "OleDfRootD0891CCB483EFDC3". * Creates process "null, C:\Users\test\AppData\Local\lsass.exe, null". * Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\lsass.exe". * Creates an event named "OleDfRoot12652E754AF1D5BD". * Creates process "null, C:\Users\test\AppData\Local\inetinfo.exe, null". * Creates an event named "ShellReadyEvent". * Injects code into process "C:\Sandbox\test\DefaultBox\user\current\AppData\Local\inetinfo.exe". * Creates an event named "OleDfRootC7C7C93FDA802975". * Enables process privileges. * Sleeps 17677 seconds. RE: So, I got infected. - unnamed - 09-05-2013 (09-05-2013, 11:23 PM)x_h0rr0r_x Wrote: You can stop this by disabling auto start from usb..Simple solution.. To be honest I'm not quite sure how my sister infected the pc. I assume the computer she used to get the pictures from was already infected. RE: So, I got infected. - unnamed - 09-05-2013 (09-05-2013, 11:23 PM)x_h0rr0r_x Wrote: You can stop this by disabling auto start from usb..Simple solution.. Wow really nice thanks, The only bad thing he did is making the malware too obvious. RE: So, I got infected. - x_h0rr0r_x - 09-05-2013 Yeah it's quiet obvious.If you know what to look for.But it's no big deal ..Avira or Malwarebytes will clean all of it..Your Welcome Bro! DISABLE AUTORUN FROM USB |