![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 1 Capture03_grcompress](https://www.secnews.gr/wp-content/uploads/2014/10/Capture03_grcompress.jpg)
Andreas Venieris, a prominent Greek systems security researcher and external collaborator of SecNews, is among the first in Greece to analyze the well-known “police virus”.
The malware became particularly well-known in Greece, especially in the last year, as it installed itself on unsuspecting users' terminals with messages of alleged criminal actions via PC, asking users to pay a sum to restore their systems. The Prosecution of Electronic Crime has even created a relevant subpage, which specifies the method of restoration in case you fall victim and detailed instructions regarding the "virus".
You can read Mr. Venieris's initial analysis in detail [here] . Andreas Venieris has returned in recent days with a new, additional analysis of the malware that SecNews is publishing EXCLUSIVELY today.
[blockquote]The research clearly demonstrates that the software continues to spread in Greece and abroad (with much lower overall infection rates, of course, since it is already detected by most common antivirus/antimalware).[/blockquote]
How does fraud happen?
The scam is carried out as follows: After the malware is installed, a popup appears, where the financial demand is specified. The amount of the alleged fine is €100. The unsuspecting user-victim is asked to pay the “alleged fine” with Paysafe or Ukash vouchers. Once the card is inserted into the mentioned popup, the browser, as the message states, is unblocked and all information will be decrypted within 24 hours.
![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 2 Andreas Venieris 2](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20191810/Capture01_gr.jpg)
If the card code entered is incorrect, the following message is displayed:
![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 3 Andreas Venieris 3](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20191809/Capture02_gr.jpg)
The Paysafe card or Ukash card import form.
![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 4 Andreas Venieris 4](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20191808/Capture03_gr.jpg)
The elements of the analysis
The researcheridentified the 3 new domains that spread the related malware. The domains are:
- seniorreversemortgage.com
- youngfadealer.com
- youngfaofwinterhaven.com
The domains have been created on the well-known Godaddy
[alert variation=”alert-info”]Domain Name: SENIORREVERSEMORTGAGEDFW.COM
Registrar URL: https://www.godaddy.com
Registrant Name: Anthony Adams
Registrant Organization: Name Server: NS69.DOMAINCONTROL.COM
Name Server: NS70.DOMAINCONTROL.COM
DNSSEC: unsigned[/alert]
The researcher tried to visit the website hxxp://tvv.seniorreversemortgagedfw.com (ed. we have changed the url with xx so that users are not redirected). The program redirects to msn.com (!)
After the first GET request as the researcher reports, it redirects to a different website where the malware (police virus) is spread. The URLs that are redirected are the following:
hxxp://mfdy.fiatalfadealer.com/reasonable-doubt/V6VtXawbKAwnRWpkHuVYGWwqUlcNZehSb3IKjsK8kV4Y4DncCfx pcgE7DjDf3ZjiYB/3WUsmZz9KLU_/Jb8MEIQg~~/NmMyN2RkYzJlZjRiZGRjYjM3MGE5OWQxOTJmOGZ/abuse-of-right.maff
or in
hxxp://htds.fiatalfaofwinterhaven.com/reasonable-doubt/V6VtXawbKAwnRWpkHuVYGWwqUlcNZehSb3IKjsK8kV4Y4Dn cCfxpcgE7DjDf3ZjiYB/3WUsmZz9KLU_/Jb8MEIQg~~/NmMyN2RkYzJlZjRiZGRjYjM3MGE5OWQxOTJmOGZ/abuse-of-right.maff
Both, as the researcher identifies in his network analysis, are hosted on the same IP address, specifically 217.172.185.150. The server is located in Germany at the following ISP:
[alert]IP Location Germany
Germany Hurth Intergenia Ag
ASN Germany AS8972 PLUSSERVER-AS intergenia AG,
DE (registered Oct 12, 2001)
Resolve Host static-ip-217-172-185-150.inaddr.ip-pool.com
Whois Server whois.ripe.net[/alert]
By reverse IP lookup of the domains corresponding to this IP, it is found that it serves the following domains:
- mfdy.fiatalfadealer.com
- naistekas.delfi.ee
- www.lebanonfiles.com
- www.tweetprocessor.com
![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 5 Andreas Venieris](https://www.secnews.gr/wp-content/uploads/2014/08/ransomware.jpg)
Andreas Venieris found that if a proxy server from another country is used, the program adapts accordingly. So if a user from Italy visits the website, it displays the Italian version of the malware website. If a user from the U.S. visits the website, it displays the English version of the website. The paradox, however, is that if a user with a Chinese IP address visits the website, it displays the Microsoft website (www.msn.com)!!!!.
![[EXCLUSIVE] Andreas Venieris reveals new evidence about the "police virus" 6 Andreas Venieris](https://cdnglobal.secnews.gr/wp-content/uploads/2014/10/20191806/Capture04_italia.jpg)
[blockquote]Making a guess, we can express the assessment that THIS MAY also be an indication of the origin of the perpetrators, who probably do not wish to spread the software to IPs in their country (ed. China). Of course, this is a guess, since it cannot be proven from the data provided by the researcher and made available to us.[/blockquote]
Immediate restriction of IP addresses at a national level
We suggest that Greek Internet Service Providers (ISP's) IMMEDIATELY block the IP addresses that the researcher disclosed and that we list in this article. These are used exclusively for the dissemination of malicious software. We believe that this should be done IMMEDIATELY in order to drastically limit the further spread of the malicious software that has affected thousands of Greek users in the past. In this case and with the relevant ongoing actions of the DIE regarding the phenomenon, the spread has been limited to a minimum. The malicious creators, however, try to use different servers each time to continue its spread.
SecNews promotes, supports and publishes EXCLUSIVELY, efforts/research/studies of Greek researchers (anonymous or named) in the field of information systems security. Furthermore, as you will see in research that will be published in the coming weeks, we show particular interest in specialized cases of detection of cybercrime incidents, complaints and analyses/research that lead to the identification of malicious users with the ultimate goal of protecting the wider society and Greek internet users.
We hope for other similar efforts by researchers, which we will be happy to make public.
We warmly thank Mr. Andreas Venieris for the timely, accurate and detailed information.
