HomeInvestigations Greek security researcher Andreas Venieris has identified a new version of the virus...

[EXCLUSIVE] Greek security researcher Andreas Venieris has identified a new version of the Police virus!

Greek security researcher Mr. Andreas Venieris , a reader of SecNews, has identified a new version of the well-known Police virus , which takes over computers of unsuspecting users, even demanding a ransom of €1500 for their "release" !!!

The researcher analyzed the malware, determining its origin, and the results of the study are published EXCLUSIVELY on SecNews.

Origin & attack detection

The new version of the “police virus” was identified on a server abroad by Mr. Venieris. The server is equipped with software that launches attacks to steal money from “unsuspecting users through threats and psychological violence,” as the researcher specifically states.

The attack is "launched" from the following domains and hyperlinks:

The above links are sent to unsuspecting victims either via e-mail (phishing attack) or are located within websites with dubious content (pornography, betting websites, etc.).

Country of origin/server details

The new version of the “police virus” is located on the server with IP 146.185.220.194. The electronic trail indicates that this IP belongs to the domain hosted-by.mdsnet.org. The domain is located in Russia, specifically in St. Petersburg, at the Internet service provider Petersburg Internet Network Ltd.The geographical representation is as follows:

The search using reverse IP also yielded the following domains:

  • h821g5.com
  • n5gg87.com
  • s21d68.com

but also 12 additional domains that also distribute malware!

Malware analysis

A quick study of the malicious program by Mr. Venieris identified a particularly interesting feature:

[box_alert]

<form action=”https://p16n42.com/processing.php?step=1″ method=”post” onsubmit=”return check(); window.onbeforeunload = null; window.document.body.onbeforeunload = null;”>

[/box_alert]

At this point, the basic functionality of the new version of the virus is identified.

We see that as soon as the user submits the page, the javascript functioncheck();

This function first checks if the user has filled in the paysafecard values ​​correctly. If this has happened then it redirects the user.
Note the line:
https://p16n42.com/processing.php?step=1

The above line led the researcherto the hypothesis that there may be other… steps! And indeed!!

When step=1 €300 is requested.

Apparently, the malicious program then leads to Step 2 (https://p16n42.com/processing.php?step=2) where €500 is requested and finally there is step 3, where €700 is requested.

A total of €1500 for online fraudsters per unsuspecting user!

The program, as mentioned, has some type of "intelligence" regarding the behavior it displays depending on the victim's country of origin:

  • When you call from countries where information about the police authorities exists (e.g. Greece, Italy, etc.), the malware comes into operation and demands from the user a sum of money in 3 stages totaling €1500.
  • When you call from countries where there is no information about the police authorities (e.g. Romania), it redirects the user to pornographic websites.

The researcher made this finding using proxies from different countries.

Images of malware

The Attack is in stage 1. The user is asked for €300. The banner is red and… threatening!
The Attack is in stage 1. The user is asked for €300. The banner is red and… threatening!
The Attack is in stage 2. The user is asked for €500. Notice the banner that has changed color and become… blue (less threatening). Psychologically, the user here believes that by paying he has reduced the… damage!
The Attack is in stage 2. The user is asked for €500. Notice the banner that has changed color and become… blue (less threatening). Psychologically, the user here believes that by paying he has reduced the… damage!
The Attack is in stage 3. The user is asked for €700. Notice the banner that has changed color and is now green and not at all threatening. The sentence “Your case has ended” is mentioned. Psychologically, the user believes that he has now escaped with the payment of €700!
The Attack is in stage 3. The user is asked for €700. Notice the banner that has changed color and is now green and not at all threatening. The sentence “Your case has ended” is mentioned. Psychologically, the user believes that he has now escaped with the payment of €700!
It is worth noting that the logos of well-known Greek companies appear as points of sale for Paysafe cards. The logos are taken from the official Paysafe page. If we observe the corresponding message via Italy, the points of sale change (again through the official Paysafe website).
And stage 1 from… Italy!
And stage 1 from… Italy!
At this point, it is worth noting that the analysis provided by the Security expert has been limited to the user level and not the security specialist. It is not an extensive analysis of the Ransomware nor an extensive analysis of the server data.
The researcher conducted extensive analysis on this malware and identified different behavior of the software (at the implementation code level) depending on the victim's web browser and the source IP address. In addition, extensive analysis carried out with vulnerability testing tools in web services revealed specific findings that may not be that interesting.
[box_info]
We must mention the above so that there are no criticisms of the researcher's report as "simplistic" . The researcher's goal is to inform the reading public to protect themselves in the event of infection with malware and in no case to over-analyze it technically.
[/box_info]
According to information, the Cybercrime Directorate and the authorities are investigating the electronic traces of origin, that is, whether the spread of the new version of the malware or whether these are isolated incidents.
SecNews thanks Andreas Venieris for the timely, valid and detailed information.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS