<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: scr]]></title>
    <link>http://securityratty.com/tag/scr</link>
    <description></description>
    <pubDate>Mon, 07 Apr 2008 23:48:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Malware Install Hides Behind Fake Blue Screen Of Death]]></title>
      <link>http://securityratty.com/article/b8c8105b310966fe1ed31d74b627f52f</link>
      <guid>http://securityratty.com/article/b8c8105b310966fe1ed31d74b627f52f</guid>
      <description><![CDATA[This hijack typically begins with the following file opened up from the web





If the file is allowed to execute on the PC, depending on what files the bundle is rotating for download at the time of...]]></description>
      <content:encoded><![CDATA[
        This hijack typically begins with the following file opened up from the web:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys0.jpg" src="http://blog.spywareguide.com/images/sys0.jpg" class="mt-image-none" style="" height="60" width="149" /></span></div><br /> <div><br />If the file is allowed to execute on the PC, depending on what files the bundle is rotating for download at the time of install you may well see the dreaded <a href="http://en.wikipedia.org/wiki/Blue_Screen_of_Death">Blue Screen Of Death</a> (or BSOD to its friends).<br /><br />However, all is not what it seems. While the end-user is faced with the horrors of the BSOD, behind the scenes Malware is installing by the bucketload.How is this possible, I hear you cry? Surely if the PC has crashed, nothing can be installing?<br /><br />Not in this case, because the blue screen of death is <i>fake</i> - to be more accurate, the bad guys have taken Sysinternals <a href="http://technet.microsoft.com/en-us/sysinternals/bb897558.aspx">blue screen of death screensaver</a> and bundled it in with the hijack files. This is what the .scr file looks like on the PC:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys1.jpg" src="http://blog.spywareguide.com/images/sys1.jpg" class="mt-image-none" style="" height="80" width="86" /></span></div><br /><br /></div><div>And this is what you see if you explore the code:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys2.jpg" src="http://blog.spywareguide.com/images/sys2.jpg" class="mt-image-none" style="" height="126" width="299" /></span></div><br /></div><div><br />It seems the bad guys are not without a sense of humour. Hiding a blizzard of infection file installs behind a legitimate screensaver created by a security expert is pretty bizarre. Here is the registry entry created:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys6.jpg" src="http://blog.spywareguide.com/images/sys6.jpg" class="mt-image-none" style="" height="35" width="523" /></span><br /><br />Meanwhile, here are just some of the files installed onto the PC during the download:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/sys5.html" onclick="window.open('http://blog.spywareguide.com/images/sys5.html','popup','width=500,height=396,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/sys5-thumb-300x237.jpg" alt="sys5.jpg" class="mt-image-none" style="" height="237" width="300" /></a></span></div><br /></div><div><div align="center">Click to Enlarge<br /></div><br />The PC pretty much grinds to a halt while all of this is taking place:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys7.jpg" src="http://blog.spywareguide.com/images/sys7.jpg" class="mt-image-none" style="" height="189" width="357" /></span></div><br /></div><div><br />When the computer finally comes back under your contol, you can expect to see numerous warnings related to fake antispyware programs appearing all over the desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/sys8.html" onclick="window.open('http://blog.spywareguide.com/images/sys8.html','popup','width=610,height=414,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/sys8-thumb-310x210.jpg" alt="sys8.jpg" class="mt-image-none" style="" height="210" width="310" /></a></span><br /></div></div><div><div align="center"><br />Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/sys9.html" onclick="window.open('http://blog.spywareguide.com/images/sys9.html','popup','width=714,height=543,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/sys9-thumb-314x238.jpg" alt="sys9.jpg" class="mt-image-none" style="" height="238" width="314" /></a></span><br /></div></div><div><div align="center"><br />Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="sys10.jpg" src="http://blog.spywareguide.com/images/sys10.jpg" class="mt-image-none" style="" height="137" width="383" /></span></div><br /></div><div><br />Collectively, we detect the various bundles on offer here as <a href="http://www.spywareguide.com/product_show.php?id=31505">Fake.AV</a> and <a href="http://www.spywareguide.com/product_show.php?id=31502">Smiddy</a>.<br /><br />Discovery and Research: Chris Mannon, FSL Senior Threat Researcher<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 14:42:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/death">death</category>
      <category domain="http://securityratty.com/tag/blue">blue</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/scr file">scr file</category>
      <category domain="http://securityratty.com/tag/infection file installs">infection file installs</category>
      <category domain="http://securityratty.com/tag/hijack files">hijack files</category>
      <category domain="http://securityratty.com/tag/hijack">hijack</category>
      <category domain="http://securityratty.com/tag/death screensaver">death screensaver</category>
      <source url="http://blog.spywareguide.com/2008/07/malware-install-hides-behind-f.html">Malware Install Hides Behind Fake Blue Screen Of Death</source>
    </item>
    <item>
      <title><![CDATA[Romanian Script Kiddies and the Screensavers Botnet]]></title>
      <link>http://securityratty.com/article/5b5c2da1c83dfe7fd39c5e9ccf463c0b</link>
      <guid>http://securityratty.com/article/5b5c2da1c83dfe7fd39c5e9ccf463c0b</guid>
      <description><![CDATA[Shall we turn into zombies, and peek into the modest botnet courtesy of Romanian script kiddies, that are currently spamming postcard.scr greeting cards? Meet the script kiddies. This botnet is going...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R_oeXF281TI/AAAAAAAABio/QsYu3itLwtk/s1600-h/romania_malware_screensaver_botnet.jpg"><img id="BLOGGER_PHOTO_ID_5186491302929028402" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R_oeXF281TI/AAAAAAAABio/QsYu3itLwtk/s200/romania_malware_screensaver_botnet.jpg" border="0" /></a>Shall we turn into zombies, and peek into the modest botnet courtesy of Romanian script kiddies, that are currently spamming postcard.scr greeting cards? Meet the script kiddies. This botnet is going nowhere mostly because knowing how to compile an IRC bot doesn't necessarily mean you posses a certain know-how, a know-how that <a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">experienced botnet masters have been outsourcing for years</a>. Malware is obtained through links pointing to :<br /><br /><strong>xhost.ro/filehost/phrame.php?action=saveDownload&amp;fileId=15735</strong><br /><strong>xhost.ro/filehost/phrame.php?action=editDownload&amp;fileId=12923</strong><br /><strong>xhost.ro/filehost/phrame.php?action=saveDownload&amp;fileId=3656</strong><br /><strong>xhost.ro/filehost/phrame.php?action=editDownload&amp;fileId=10936</strong><br /><br /><strong>Scanners result</strong> : Result: 22/32 (68.75%)<br />Trojan.Zapchas.F; IRC/BackDoor.Flood; Backdoor.IRC.Zapchast<br /><strong>File size:</strong> 735139 bytes<br /><strong>MD5</strong>...: 015e5826084f2302b4b2c3237a62e244<br /><strong>SHA1</strong>..: 7d05949f6dfffdc58033c9d8b86210a9bd34897c<br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/R_ssml281WI/AAAAAAAABjA/DrdQlceTJq8/s1600-h/romania_malware_screensaver_botnet2.jpg"><img id="BLOGGER_PHOTO_ID_5186788437356500322" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R_ssml281WI/AAAAAAAABjA/DrdQlceTJq8/s200/romania_malware_screensaver_botnet2.jpg" border="0" /></a><strong>Sample traffic output :</strong><br />"NICK Mq2kC01<br />USER las "" "pic.kauko.lt" :Px7aW6<br />USER las "" "Helsinki.FI.EU.Undernet.org" :Px7aW6<br />USERHOST Mq2kC01<br />NICK :Rk1zK50<br />AWAY :Eu te scuip in cap si'n gura, tu ma pupi in cur si'n pula =))!<br />MODE Mq2kC01 +i<br />ISON loverboy loveru SirDulce<br />JOIN #madarfakar<br />USER kzg "" "Helsinki.FI.EU.Undernet.org" :Ho5xI1<br />NICK :Vm3uF52<br />MODE Mq2kC01 +wx"<br /><br />And in next couple of hours, the most interesting domain that joined the IRC channel was :<br /><br />Ny2fW15 is <a href="mailto:fwuser@mails.legislature.maine.gov">fwuser@mails.legislature.maine.gov</a> * Kg1jT7<br />Ny2fW15 on #madarfakar<br />Ny2fW15 using Noteam.Vs.undernet.org I'm too lazy to edit ircd.conf<br />Ny2fW15 is away: Eu te scuip in cap si'n gura, tu ma pupi in cur si'n pula =))!<br />Ny2fW15 has been idle 1min 31secs, signed on Fri Apr 04 12:05:17<br />Ny2fW15 End of /WHOIS list.<br /><br />This botnet's futile attempt to scale is a great example of the growing importance of <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">knowlege and experience empowered botnet masters</a>, as a key success factor for sustainability, and also, basic understanding of economic forces, namely, when they're not making an investment there cannot be a return on investment on their efforts at the first place. Take a peek at <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">the efficiency level of remote file inclusion</a> achieved by another botnet, and at <a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">alternative botnet C&amp;C channels</a> courtesy of botnet masters realizing that diversity is vital.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ly3a6VG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ly3a6VG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y7KiH0G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y7KiH0G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4BP9Gvg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4BP9Gvg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gvREVog"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gvREVog" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wpJ8ZTG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wpJ8ZTG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=EpMGHOG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=EpMGHOG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bpwnKNg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bpwnKNg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/266216944" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 23:48:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/botnet masters">botnet masters</category>
      <category domain="http://securityratty.com/tag/script kiddies">script kiddies</category>
      <category domain="http://securityratty.com/tag/romanian script kiddies">romanian script kiddies</category>
      <category domain="http://securityratty.com/tag/botnet courtesy">botnet courtesy</category>
      <category domain="http://securityratty.com/tag/ny2fw15">ny2fw15</category>
      <category domain="http://securityratty.com/tag/alternative botnet">alternative botnet</category>
      <category domain="http://securityratty.com/tag/irc">irc</category>
      <category domain="http://securityratty.com/tag/irc bot">irc bot</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/266216944/romanian-script-kiddies-and.html">Romanian Script Kiddies and the Screensavers Botnet</source>
    </item>
  </channel>
</rss>
