HomeInvestigations Researcher Uranos achieves complete malware analysis!

[EXCLUSIVE] Researcher Uranus achieves complete malware analysis!

afghan-compressed

Another success for the Greek independent security researcher, who in recent weeks has been making continuous announcements, analyzing malware he receives from a multitude of sources, including corporate honeypots  both from Greece and mainly from abroad! We could even say that the researcher has declared an “informal” war on malware creators and especially on those who use ready-made tools to steal information from unsuspecting victims and publish their personal data on the internet.

Greek malware analyst Panagiotis Ouranos not only performs in-depth analysis using reverse engineering techniques, he also goes a step further, identifying malware creators and in some cases even identifying/informing companies/organizations or individuals that have been targeted by hackers-industrial spies.

malware

Mr. Ouranos' researchis not limited to Greece but also to malware that targets companies/organizations abroad. It is no coincidence that there are already reports abroad from foreign news agencies about the prominent way of working of the Greek researcher.

According to communication sought and achieved by SecNews ,Mr. Ouranos achieves his highly impressive results, as he stated, by using the following work environment:

[blockquote]The analysis is performed in a controlled VM environment with or without Internet gateway as appropriate, in combination with monitoring tools and reverse engineering tools such as IDA and OllyDbg. In addition, Python is used to automate the processes and inline ASM dynamically in OllyDbg for the hooks.[/blockquote]

And of course... endless hours and unlimited patience, the author of the article will add...

The new malware

The new malware analyzed by the researcher  has not shown widespread distribution as of this writing. It arrives via email to the unsuspecting user's mailbox. More specifically, it displays a PDF icon while in reality it is an executable file (.exe file).  The unsuspecting user receives the message with an address indicating the origin of a person they know. The targeted user believes that it is an attached PDF and executes it with disastrous consequences.

At this time, the sample and the code of the malicious executable have already been submitted to threat detection engines and are detectable by the majority of Antiviruses.

afghan.pass.stealer.4
Malware scan result with multiple antiviruses.

 

The analysis

Mr. Ouranos , using specialized tools, proceeded to fully decrypt the malware. You can see the full analysis [here]

As he found, the malicious campaign was built on pre-existing tools that had been purchased from hacking forums at low prices of $30-50 (crypters/fudders).

Stealer_dump11
Extensive malware analysis phase

These tools were then used to encrypt a Stealer, i.e. software that intercepts e-mail passwords, Social networks passwords, keystrokes (keylogger), browser passwords, etc. The Stealer software in question spreads itself via e-mail to other victims and also sends the findings from each target terminal to the e-mail address of the perpetrator-electronic spy.

Hacking the Hackers or in other words... identifying the perpetrator

Mr. Ouranos took his analysis one step further.  He precisely identified the perpetrator/user from whom the attack originated and gained access to the email account he was using to gather information from his targets!!!

During software analysis and after bypassing all kinds of encryptions that the perpetrator had implemented using reverse engineering techniques, he identified (encrypted) the passwords he was using to send the emails.

afghan.pass.stealer.5
Detecting and decrypting passwords

Using additional techniques, he decrypted the AES encrypted hashthat he identified in the software code and now had at his disposal the credentials (username+password) of the e-mail to which the interception data was sent by the unsuspecting victims of the industrial spy.

The attacker's mailbox was accessed, as the researcher informs us, via a Proxy in PAKISTAN. This is because it appears that the perpetrator is most likely located in that country and Google did not allow access from a country other than that.

afghan.pass.stealer.1
Access to attacker's dropbox

Not enough evidence of an attack was found within the Mailbox, which particularly piqued the researcher's curiosity. With a closer look, he found that the e-mails were being forwarded to another Yahoo e-mail account for final disposal and difficulty in identifying the perpetrator.

afghan.pass.stealer.2
Forwarding stolen data to an external Yahoo account as a non-detection measure

Nevertheless, the researcher identified a number of targeted companies and individuals in the deleted e-mails of the account in question.

afghan.pass.stealer.3
Identification of targeted companies & individuals

 Final remarks

It is evident that with the multi-level analysis carried out by the independent researcher Mr. Panagiotis Ouranos, it offers first-class information for Antivirus companies and security experts (it security experts). According to cross-checked information by SecNews, this malicious software has not yet been widely distributed in Greece, while its creators appear to come from the United Kingdom and Pakistan/Afghanistan. The companies that were targeted, as we are able to know, involved commercial companies, pharmaceutical companies and government public utility organizations.

As the researcher states in his conclusions , the creators used "off-the-shelf" tools that are widely available and can be purchased by anyone on open forums for a small fee.

We hope that other security experts and analysts, who we know are active in Greece, will follow such examples as Mr. Ouranos . Such specialized analyses, with international visibility , will promote our country in the field of electronic systems security, clearly proving that we are NOT the laggards in the adoption of technologies.

The editorial team of SecNews thanks Mr. Panagiotis Ouranos for the exclusive, authoritative and analytical information

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS