A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5139  by Xylitol
 Tue Feb 22, 2011 8:31 pm
tiny post in my blog today
Image

Most of you know this threat as 'bluetrash' or 'porno player'
This malware have appear in April 2010 and currently alway active.
Named 'winAD' because of about box resource which present in both types and using fakes porn site sush as 'SpermTV' or 'EroTube' for distributing the malware.

Image

Unblock codes and tel numbers are stored inside executables.
They do not use cryptor but Winlock code constantly morphing trying to break antivirus signatures, the dropper use the Windows Vista Media Player icon, is packed with UPX and extracts payload Winlock executable to %USERPROFILE%\[Digits]\[Digits].EXE

Image

After few days, some variants appears, like the 'Homoblocker' ransomware, generaly distributed with a fake site coupled with Phoenix Exploit Kit

If we return one month ago, this malware was updated 2 or 3 per day.
Now... according to my malware bot, this ransomware is updated every hours.
And the homoblocker variante seem now not updated anymore.
Concerning the Homoblocker variants, sometime the guys who is under this have made some tests:

Image

These 'tests' have appear on the homoblocker malware server the 03/02/2011 at 21:12:16 P.M (GMT+1) for 3 days with 8 updates in totals.
According to VirusTotal, when i've uploaded a sample, it was only detected by one antivirus.

For Bluetrash, i monitor every change of this ransom like homoblocker, and since one week now.. that become serious with updates and modifications. (some changes have appears like the 'reboot when dropped', Actually he dont do that anymore.)
A rapid calcul: 24*7 = 168 samples per week.
Tiny histogram:

Image

An update error occured sunday 20 at 03:00 A.M (GMT+1)
Malware filesize in the server: 0 bytes, at 04:08 A.M, a new working sample was available.
Bluetrash ransomware is surely updated with a bot now.
Before, updates have occured only the day.. now it's day and night, h24.

Samples from yesterday downloaded every hours, as you can see the MD5 is alway not the same:

Image

Monitoring center:

Image

Image

Sample are updated every hours but still detected by most of AVs.
Also i want to thanks Crank69, i really appreciate your emails man.
Code: Select all
20/02/2011 - 20:18:31 - EE9E5FAAB6B0D5E14DB7A83FAF3F82FA_pornoplayer.exe.ViR
DONE! ~ WAITING
20/02/2011 - 21:18:33 - 6137DD625ABFDDB958FCD7531DB263DF_pornoplayer.exe.ViR
DONE! ~ WAITING
20/02/2011 - 22:18:33 - 3C447299CCDE8D1F0C2FCCF6301DC453_pornoplayer.exe.ViR
DONE! ~ WAITING
20/02/2011 - 23:18:35 - 977B20936119D6259AA307B0D7FC1C55_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 00:18:35 - 93364ABEBBCA243AE6F0602960FF4364_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 01:18:35 - 1C60F6C56789BEF98983BC84BB1E2C77_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 02:18:39 - BFF84A8C312C4638201467225020A916_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 03:18:40 - 39C01EDAA8C005FEAAA073077CBF3C46_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 04:18:40 - 8924157220F1CDA9CA5D0583517C5326_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 05:18:40 - 238AB3B52787F0B3D91392B7B5D77851_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 06:18:43 - DDDDB1C40366CAE08818BFCDC6AE957A_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 07:18:43 - 2A032D31C3521C45DCA861D7F74A4B53_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 08:18:43 - 3754EF7A6BC2CD148F4249EB5299500E_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 09:18:43 - 69FB5628108263D450C083E55EBAD699_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 10:18:43 - B6F83C092E24766ACC2F9AE748BEBAA6_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 11:18:43 - 517E715FAB980E4FF95E474D4FD1AF20_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 12:18:43 - 8C41F66E19AC209C33FE663CB16284D7_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 13:18:44 - 2D06C39C147F7FB7164275ACBCB67872_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 14:18:45 - DF042EB1CA8153D8056555F6B4B66F29_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 15:18:46 - 22CFB5E6CF601F3A86147F17D6D1E545_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 16:18:47 - E0F9FBB95177EDA58D6A6FC06E24EED6_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 17:18:48 - 0628DE133FB18E17548BB3C7230EB33F_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 18:18:48 - AD9BDF044EC6A5A34B5C6452B65EAB20_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 19:18:50 - 61CE213F3BC47EBF962C0F16D7526707_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 20:18:53 - 417F93F2E582DC518E771D3BA3792AFA_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 21:18:56 - B663B4BE6027F12C5E37066506A56EAE_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 22:18:56 - F2D1005673FB4E78264011A1F731D5C1_pornoplayer.exe.ViR
DONE! ~ WAITING
21/02/2011 - 23:18:57 - 1375C8FD0AD538F2BF63D3F0E42FD6B0_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 00:18:57 - 21AFCD12CA19B1DCE1BEF43ADEA4B63F_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 01:18:58 - ED105DCCDF719364C3A316556AC50368_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 02:19:02 - 6B1D5F0BAC766ECC3CD64345A119ABF6_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 03:19:03 - 6F3B0E329EC3A78D5452862A0DD6844C_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 11:44:29 - E6316021C1B5BB9E2C289169B856825F_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 12:44:30 - D1402514A469B92E2C25FEBFA7D74A25_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 13:44:31 - 0BFBC1B1DD18B26EAC3665FB05DD9A02_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 14:44:32 - C8AB6CA90A5A6F48AA95D295B916B867_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 15:44:32 - 52F38A5A5A37A0D3C8108C2BE026C79E_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 16:44:53 - 2AB9DBAE4839453E3249C33C34A08FA1_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 17:44:55 - 3D9517AAB5DBC9EBD51BBC9832726296_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 18:44:54 - 5FDECC9BFBCBFDD44772652EE6D2CFD7_pornoplayer.exe.ViR
DONE! ~ WAITING
22/02/2011 - 19:44:56 - 93D6552A9A456CE09601FCF2DB7F868A_pornoplayer.exe.ViR
DONE! ~ WAITING
ok22/02/2011 - 20:44:59 - 584D846843525083239433C6C91C174B_pornoplayer.exe.ViR
DONE! ~ WAITING
Attachments
See archive comment for password
(1.89 MiB) Downloaded 46 times
 #5163  by EP_X0FF
 Fri Feb 25, 2011 8:39 am
Unblock code: KERRIGAN IS SO SEXY
 #5182  by GMax
 Sun Feb 27, 2011 7:56 am
URL "spermTV"
eroktube.info
eroltube.info
fnakedgirls.info
fuckgirlsc.info
fuckgirlsx.info
fuckgirlsz.info
gigasexa.info
gigasexi.info
gigasexo.info
gigasexp.info
gnakedgirls.info
hworldxxx.info
jworldxxx.info
kworldxxx.info
lworldxxx.info
xclipdplay.info
xclipfplay.info
xclipgplay.info
xclipsplay.info
xxxbazac.info
xxxbazax.info
xxxbazaz.info
znakedgirls.info
 #5184  by Xylitol
 Sun Feb 27, 2011 2:04 pm
new locs: hXXp://dnakedgirls.info/xxx/q37v2x4o4nh2v4q39f6fs1t8i864i97y/pornoplayer.exe
hXXp://dnakedgirls.info/y42n2urm8l9e3h21571x8wp8yolpvzm2/pornoplayer.exe
hXXp://inakedgirls.info/xxx/qg7cft426ic822ty4py72q61u9jez5h4/pornoplayer.exe
hXXp://inakedgirls.info/gywt9496866f8pnp7t7ovg3c859qph75/pornoplayer.exe
Attachments
See archive comment for password
(4.5 MiB) Downloaded 44 times
 #5261  by GMax
 Tue Mar 01, 2011 8:20 pm
hxxp://xcliphplay.info/e41il1f1g28746w218647xlkg7ll215t/pornoplayer.exe
Code: Select all
Num to Call: 9652076283 
Unlock cod: KERRIGAN IS NOT SEXY
new unlock cod :D
 #5269  by Xylitol
 Wed Mar 02, 2011 4:15 pm
hXXp://mnakedgirls.info/h41w736fmu2d5az7xwkydahe88e12bb8/pornoplayer.exe
hXXp://mnakedgirls.info/xxx/9i2inkua48wwhvxqp777f3f8eek446jt/pornoplayer.exe
Code: Select all
Number to Call: 9652077094
Number to Call: 9057065585
Number to Call: 9670998902
Attachments
see archive comment for password
(1.23 MiB) Downloaded 45 times
  • 1
  • 5
  • 6
  • 7
  • 8
  • 9
  • 17