Some weird guy sent me this

Discussion in 'malware problems & news' started by Dawgonit, Nov 19, 2010.

Thread Status:
Not open for further replies.
  1. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    FLVPlayer, Delphi, UPX.

    Unpacking looses its VT detections to just one, Virut. Virut infects excutables you accesses and opens a backdoor - none of which I detected in the time I looked at it so far.

    I think flv player has had some problems before, bundled with malware, toolbars and other adware and then aggressively pushed such as pay per install (PPI)
     
    Last edited: Nov 20, 2010
  2. vtol

    vtol Registered Member

    Joined:
    Apr 8, 2010
    Posts:
    774
    Location:
    just around the next corner
    there are a few suspicious reg entries

    Set Values

    Key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    Value: C:\12069003.exe
    Data: C:\12069003.exe:*:Enabled:InstallerCore?

    Query Value

    Key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
    Value: C:\12069003.exe

    Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS
    Value: 12069003.exe

    and winsock connectivity
    • Outgoing Connections
      • HTTP Data
        • Method: GET
        • Url: 75.101.140.155/cgi-bin/utils/IP2CC.psc
        • HTTP Version: HTTP/1.1
          • Header Data
            • Accept: */*
            • Host: rp.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
        • Method: POST
        • Url: 75.101.140.155/vc.psc?pcrc=1352896255
        • HTTP Version: HTTP/1.1
          • Header Data
            • Accept: */*
            • Host: rp.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
            • Content-Length: 670
            • Cache-Control: no-cache
        • Method: GET
        • Url: 72.21.211.171/products/FLVPlayer.cis
        • HTTP Version: HTTP/1.1
          • Header Data
            • Range: bytes=0-102399
            • Accept: */*
            • Host: cdnus.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
        • Method: GET
        • Url: 72.21.211.171/products/FLVPlayer.cis
        • HTTP Version: HTTP/1.1
          • Header Data
            • Range: bytes=307200-442058
            • Accept: */*
            • Host: cdnus.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
        • Method: GET
        • Url: 178.236.5.33/products/FLVPlayer.cis
        • HTTP Version: HTTP/1.1
          • Header Data
            • Range: bytes=102400-204799
            • Accept: */*
            • Host: cdneu.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
        • Method: GET
        • Url: 72.21.211.171/products/FLVPlayer.cis
        • HTTP Version: HTTP/1.1
          • Header Data
            • Range: bytes=204800-307199
            • Accept: */*
            • Host: cdnus.programmersupply.com
            • User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
     
  3. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Edited above post.

    Well I'm still running a vm so let's see.
     
  4. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA

    Its good to be running a good Anti-Executable in these cases so it does not have to be detected :)
     
  5. vtol

    vtol Registered Member

    Joined:
    Apr 8, 2010
    Posts:
    774
    Location:
    just around the next corner
    problem is that not everyone has a setup with anti-ex and a user going already the length to check with the VT url scanner could think that it is ok to download from such url, when it is not...
     
  6. vtol

    vtol Registered Member

    Joined:
    Apr 8, 2010
    Posts:
    774
    Location:
    just around the next corner
    it is probably not malicious, the FLV installer trying to fetch data from various CDN sources.
     
  7. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    Check out the Anubis report here. Somewhat nasty driveby.
     
  8. Franklin

    Franklin Registered Member

    Joined:
    May 12, 2005
    Posts:
    2,517
    Location:
    West Aussie
    MS VM aware but runs via Sandboxie Win 7 OK.
     
  9. vtol

    vtol Registered Member

    Joined:
    Apr 8, 2010
    Posts:
    774
    Location:
    just around the next corner
    some new urls popping up

    -http://videosstreamnow.erufa.com/template.php?q=2791-

    -http://crazytubevideos.hostingfreeweb.info/template.php?q=4014-
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.