Bitcoin Forum
April 23, 2024, 05:09:33 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Anyone else get this malware email?  (Read 1341 times)
theymos (OP)
Administrator
Legendary
*
Offline Offline

Activity: 5180
Merit: 12873


View Profile
May 24, 2012, 07:24:27 PM
 #1

I received this file via email. I suspect it is malware -- possibly a wallet-stealer. Did anyone else get this?

http://www5.zippyshare.com/v/12732912/file.html (Warning: probable malware)

Quote from: Email
Invitation to ecurrency conference.

http:// asiaelektronik.com/docs/processdl.html

Please let us know if you interested.

Thanks & Regards

The ecurrency part makes me think it's targeted to Bitcoin users.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
Bitcoin mining is now a specialized and very risky industry, just like gold mining. Amateur miners are unlikely to make much money, and may even lose money. Bitcoin is much more than just mining, though!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713892173
Hero Member
*
Offline Offline

Posts: 1713892173

View Profile Personal Message (Offline)

Ignore
1713892173
Reply with quote  #2

1713892173
Report to moderator
1713892173
Hero Member
*
Offline Offline

Posts: 1713892173

View Profile Personal Message (Offline)

Ignore
1713892173
Reply with quote  #2

1713892173
Report to moderator
1713892173
Hero Member
*
Offline Offline

Posts: 1713892173

View Profile Personal Message (Offline)

Ignore
1713892173
Reply with quote  #2

1713892173
Report to moderator
ribuck
Donator
Hero Member
*
Offline Offline

Activity: 826
Merit: 1039


View Profile
May 24, 2012, 07:29:54 PM
 #2

I got it too. I deleted it without clicking, so I don't know where the link goes.
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 24, 2012, 08:05:50 PM
 #3

File ends in .xls.scr.xls. .scr is the same as .exe, used in screensavers but can do anything that a standard executable can do.

EDIT: https://www.virustotal.com/file/b50dd5b511934b97edf77f7611e5b007d330c6adfe68adeb167068a20b38409f/analysis/#additional-info

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 25, 2012, 02:48:42 AM
 #4

File ends in .xls.scr.xls. .scr is the same as .exe, used in screensavers but can do anything that a standard executable can do.

EDIT: https://www.virustotal.com/file/b50dd5b511934b97edf77f7611e5b007d330c6adfe68adeb167068a20b38409f/analysis/#additional-info

A screensaver miner maybe?

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 25, 2012, 03:32:05 AM
 #5

File ends in .xls.scr.xls. .scr is the same as .exe, used in screensavers but can do anything that a standard executable can do.

EDIT: https://www.virustotal.com/file/b50dd5b511934b97edf77f7611e5b007d330c6adfe68adeb167068a20b38409f/analysis/#additional-info

A screensaver miner maybe?

LOL well you are welcome to risk your wallet to find out. Grin Don't say you weren't warned. Kiss

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 25, 2012, 03:36:43 AM
 #6

Truth be told, I ran it on my offline virtual machine, and I have no freaking Idea what it does.

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 25, 2012, 03:54:22 AM
 #7

Truth be told, I ran it on my offline virtual machine, and I have no freaking Idea what it does.
Run it in a VM with Sandboxie, with logging enabled. The Sandboxie logs will tell you all the files and registry objects that the programs touches, whether in a read or a write operation.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 25, 2012, 04:10:14 AM
Last edit: May 25, 2012, 04:36:28 AM by ZodiacDragon84
 #8

Give me a bit, and I will have a log ready as soon as I run it. Call it my White hat deed of the day...lol

Cant figure out how to make a log at moment, but none of my scans are showing really anything malicious.

multi scanner results

http://metascan.org/result.php?scan=MzkxODYx

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 25, 2012, 04:38:51 AM
 #9

imunitet and Panda did find this:

http://virusremoval.info/Remove/Trojan/TrojanHorse/Trojan.aspx?name=Trojan.Generic.KDV.102762

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
theymos (OP)
Administrator
Legendary
*
Offline Offline

Activity: 5180
Merit: 12873


View Profile
May 25, 2012, 05:53:31 AM
 #10

It just displayed gibberish when I opened it in Office 2007. Didn't touch any files. Maybe it targets some other vulnerable software.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
Foxpup
Legendary
*
Offline Offline

Activity: 4340
Merit: 3042


Vile Vixen and Miss Bitcointalk 2021-2023


View Profile
May 25, 2012, 06:09:45 AM
 #11

It just displayed gibberish when I opened it in Office 2007. Didn't touch any files. Maybe it targets some other vulnerable software.

It's a Win32 executable, not an Office file. The vulnerable software it targets is Windows. Wink

Will pretend to do unspeakable things (while actually eating a taco) for bitcoins: 1K6d1EviQKX3SVKjPYmJGyWBb1avbmCFM4
I am not on the scammers' paradise known as Telegram! Do not believe anyone claiming to be me off-forum without a signed message from the above address! Accept no excuses and make no exceptions!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 25, 2012, 06:13:18 AM
 #12

It is hiding a trojan. Out of the 32 scans I ran, it only popped up in 2 of them. All the appropriate information is posted in my previous posts links.

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 25, 2012, 12:50:20 PM
 #13

A form grabber. Interesting.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
Graet
VIP
Legendary
*
Offline Offline

Activity: 980
Merit: 1001



View Profile WWW
May 27, 2012, 03:24:34 AM
 #14

http://anubis.iseclab.org/
Anubis: Analyzing Unknown Binaries, rather useful site too Smiley

| Ozcoin Pooled Mining Pty Ltd https://ozcoin.net Double Geometric Reward System https://lc.ozcoin.net for Litecoin mining DGM| https://crowncloud.net VPS and Dedicated Servers for the BTC community
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
May 27, 2012, 03:45:19 AM
 #15

http://anubis.iseclab.org/
Anubis: Analyzing Unknown Binaries, rather useful site too Smiley
Cool site! Analysis of this particular sample: http://anubis.iseclab.org/?action=result&task_id=10628d7019a46f47405a49a63bcc93a25

It appears to be a trojan that does keylogging, and installs a reverse shell or VNC-type program. It does 2 DNS lookups and a few http connections, all shown in the report.

Here is the beginning of the text report, not all of it will fit due to forum limits on the amount of text in one post:
Code:
                           ___                __    _                          
         +  /-            /   |  ____  __  __/ /_  (_)____       -\  +         
        /s  h-           / /| | / __ \/ / / / __ \/ / ___/       -h  s\       
        oh-:d/          / ___ |/ / / / /_/ / /_/ / (__  )        /d:-ho       
        shh+hy-        /_/  |_/_/ /_/\__,_/_.___/_/____/        -yh+hhs       
      -:+hhdhyys/-                                           -\syyhdhh+:-     
    -//////dhhhhhddhhyss-       Analysis Report       -ssyhhddhhhhhd\\\\\\-   
   /++/////oydddddhhyys/     ooooooooooooooooooooo     \syyhhdddddyo\\\\\++\   
 -+++///////odh/-                                             -+hdo\\\\\\\+++-
 +++++++++//yy+/:                                             :\+yy\\+++++++++
/+soss+sys//yyo/os++o+:                                 :+o++so\oyy\\sys+ssos+\
+oyyyys++o/+yss/+/oyyyy:                               :yyyyo\+\ssy+\o++syyyyo+
+oyyyyyyso+os/o/+yyyyyy/                               \yyyyyy+\o\so+osyyyyyyo+


[#############################################################################]
    Analysis Report for Invitation of Ecurrency Conference.xls.scr.xls
                   MD5: 9c1f40c32a7f32c7e59396986098afef
[#############################################################################]

Summary:
    - Write to foreign memory areas:
        This executable tampers with the execution of another process.

    - Packed Binary:
        This executable is protected with a packer in order to prevent it
        from being reverse engineered.

    - Execution did not terminate correctly:
        The executable crashed.

    - Autostart capabilities:
        This executable registers processes to be executed at system start.
        This could result in unwanted actions to be performed automatically.

    - Changes security settings of Internet Explorer:
        This system alteration could seriously affect safety surfing the World
        Wide Web.

    - Performs File Modification and Destruction:
        The executable modifies and destructs files which are not temporary.

    - Spawns Processes:
        The executable produces processes during the execution.

    - Performs Registry Activities:
        The executable creates and/or modifies registry entries.                       

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ZodiacDragon84
Sr. Member
****
Offline Offline

Activity: 266
Merit: 250


The king and the pawn go in the same box @ endgame


View Profile
May 27, 2012, 08:40:43 PM
 #16

Thank you for adding! I always love new tools in my arsenal

Looking for a quick easy mining solution? Check out
www.bitminter.com

See my trader rep at Bitcoinfeedback.com
!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!