HomeInvestigationsEXCLUSIVE: Analyst "decoded" data-stealing malware!

EXCLUSIVE: Analyst “decoded” data-stealing malware!

leetsec.com.1

SecNews EXCLUSIVELY presents the analysis carried out by a Greek independent malware researcher.

The editorial team of SecNews became the recipient of the outstanding work of a distinguished Greek researcher who performed a complete decoding of malicious software. Specifically, according to the information available to the editorial team, the Greek researcher, owner of the website https://www.133tsec.com/, performed reverse engineering techniques to extract and decrypt malicious software that had begun to gradually spread even in Greece!!

The analysis of this malware was carried out by the researcher and published in a global exclusivity [here]

The detection

The signature and executable file of the malware were provided to the independent researcher through a friendly researcher who manages a honeypot installed in Greece, for the purpose of determining the spread of malware. The detection was carried out in the previous days and it was found that the malware in question had already started targeting Greek users (minimal cases in number).

malware.analyst

The analyst

The independent malware researcher, who has occasionally conducted analyses on behalf of companies in Greece but mainly abroad, proceeded with an in-depth analysis. The results of this are unprecedented for Greek data. With many years of experience in analyzing evidence and malware, as he tells us:

[blockquote] Impressive in terms of the way it was hidden, the fact that it had used tools available to the general public and had essentially encrypted the executable over 7 times in order to make it completely unrecognizable by Antivirus[/blockquote]

In-depth analysis

The full analysis with numerous technical details (in English) is available here: https://www.133tsec.com/2014/09/20/autoit-malware-a-detailed-analysis/

The distinguished researcher, one of the few in Greece with such high expertise, particularly known in the field of reverse engineering analysis, determined that the cyberspies used “broken” versions of official software: a combination of AutoIT software (automation of daily computer tasks) and a “commercial” keylogger called “Limitless Keylogger”. This application completely records the user’s keystrokes (username and passwords) and sends them to an email address identified by the researcher.

lk-console-messages

 

You can see how to use the Keylogger below:

https://www.youtube.com/watch?v=fzr655lcQs8

The analysis was carried out with multiple tools so that the researcher could bypass the 7 levels of encryption/obfuscation that the malicious application had.

olly_apireturned

After decryption, as is evident in the screenshot below, the virus is detectable by almost all Antivirus. It is worth noting that the would-be hackers had used the AutoIT to achieve hiding from Antiviruses and automation in malicious actions without the knowledge of the user being monitored.

final_vt

Conclusions – Additional information

According to information that SecNews has at its disposal and does not publish for data protection reasons, the creators of the malicious software are Indonesian hackers who used code & tools from forums of Russian origin. With additional analysis of the information available to SecNews, it identified the drop point on an Indonesian hacker's website, and with the help of technicians we extracted all the information that the would-be hacker has at his disposal (ed. the information is published on the Internet and available to EVERYONE!!!).

malware.analysis

 

As we have seen, the software deposits the intercepted data at the drop point. The data, which is currently on the server in question, includes passwords for e-mail, social networks and services, as well as screenshots from victim terminals. We note that among the victims are multinational companies, foreign airlines, retail companies and well-known industries.

As we have found (ed. the server details have not been announced here for reasons of protection of personal data of foreign users) NO data of Greek victims have been found at the said drop-off point. However, because the malicious software was found, as the researcher tells us, on a trapped network within Greece, system administrators and company security managers must IMMEDIATELY inform employees regarding the spread of the SPAM campaign and check their systems to see if the software mentioned has been installed.

The campaign was detected during its initial launch in Greece and therefore, according to estimates, has not yet achieved widespread distribution.

 We thank the Greek researcher for his excellent work and for the prompt and detailed information.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS