Jump to content

Recommended Posts

  • ExTS Admin
Posted

A new variant of the CryptoLocker malware has been discovered that uses Yahoo Messenger as its delivery mechanism and is targeting Windows systems.

My friends at NSHC in Singapore and Seoul have been battling with the malware that has hit a number of financial institutions throughout Asia Pacific. The variant infects systems and distributes itself out through contacts in Yahoo Messenger, with the payload disguised as an image.

 

The malicious file named “YOURS.JPG.exe” requires users to download and execute the code utilizing social engineering tactics. Once this is initiated a series of steps take place and modules are dropped and downloaded to the system and files are encrypted on the system.

 

http://img.photobucket.com/albums/v708/starbuck50/file11_zps07b4595f.png

 

Once ”YOURS.JPG.exe” is executed an injector file “Omari[Rnd].exe” is put into a random directory and the original “YOURS.JPG.exe” file is then deleted via a .bat file that is also dropped and executed.

 

The injector file then searches through a list of processes using the Windows ‘ToolHelp’ library to find the PID of ‘explorer.exe’. The malware then gains control of explorer.exe and copies code into memory using ‘CreateRemoteThread’.

 

If certain conditions are met it will download an additional module that will initiate the encryption process on on the system. The new encryption module reads in files encrypts them and overwrites the original file.

 

 

Full description here:

 

http://www.tripwire.com/state-of-security/vulnerability-management/new-cryptolocker-variant-spread-yahoo-messenger/

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...