Categorized | DrWeb

Fake torrent-trackers and other tricks of virus-makers in April 2010

May 1, 2010

In April 2010 cyber-criminals focused on new SMS fraud schemes. This time they targeted users of torrent trackers and file sharing resources whom they tried to lure to fake web-sites supposedly providing such services. April also saw discovery of new malicious programs targeting smart phones while fake anti-viruses maintained their leadership among malware found in e-mail traffic.

Fake torrent-trackers and file sharing sites

Doctor Web’s virus analysts uncovered an entire network of fake torrent-trackers and file sharing resources located in different parts of the globe and yet targeting Russian-speaking users. Criminals exploited wide popularity of such resources and carelessness of many people who search for necessary information using search engines and posted links to music, books, moves and other contents on such web-sites.

Fake torrent-trackers and file sharing resources appeared at the top of search results lists returned to users by search engines. Apparently criminals performed search engine optimization and perform other preliminary activities to improve efficiency of their schemes.

A user obtaining a download link on such a web-site downloaded a 16 megabyte executable file instead of a supposed archive with desired content. Dr.Web detects such files as Tool.SMSSend.2.

Launching the file brings up a window prompting the user to send several paid short messages that will allow him to gain access to a downloaded archive. In truth such malicious files do not contain any useful data. Similar schemes are known to target users from other countries where instead of an SMS would-be victims are offered to use their credit cards to pay for their downloads before they actually download anything.

Currently Doctor Web’s statistics server registers around 6 000 instances of detection of Tool.SMSSend.2 per 24 hours.

Copyright protection virus

Apart from techniques listed above criminals also attempted to intimidate torrent users.Trojan.Fakealert.14886 (as classified by Doctor Web) spread in quite large numbers over the Internet in April. In an infected system the Trojan displayed a message warning a victim that illegally obtained content protected by copyright was detected on the computer which would result in prosecution.

Trojan.Fakealert.14886 spreads as a software installer. If a user doesn’t remove the program using standard Windows tools for adding and removing software and simply reboots the system, the Trojan will block access to the system similarly to Trojan.Winlock malware. The highest number of detections of this program was registered in Europe.

A new modification of Trojan.Winlock that warned a user of his violation of copyright law also emerged in April. It offered users to send a paid SMS-message in order to continue downloading files via torrent through a backup communication channel.

Fake anti-viruses

Fake anti-viruses enhanced with new or updated look and feel continued there broad-scale offensive in English-speaking countries. Their spreading techniques didn’t change while the number of their detections registered by Doctor Web’s statistics server declined and reached 750 000 against an approximate 1 000 000 in March.

Trojan.Fakealert gallery

Windows blockers

The rate of spreading of Trojan.Winlock in Russia also went down in April and reached 720 instances of detection per 24 hours compared with 1 300 registered in March. However, the number of new modifications of Trojan.Winlock increased. Doctor Web’s technical support received requests related to such Trojans on a daily basis.

Trojan.Winlock gallery

Dialler for smart phones

Virus analysts registered spreading of the WinCE.Dialer.1 malicious program, that targeted pocket PCs running Windows Mobile. Once installed, it started making calls at paid phone numbers registered in different countries.

The program springs into action in 48 hours following a successful infection of the system. WinCE.Dialer.1 spreads as a supposed game for pocket PCs.

The share of malicious programs in e-mail traffic scanned by Dr.Web software in April 2010 increased by 28 %. The share of malicious files among all files scanned on user machines increased by 2.12. The figures show that in April criminals mainly focused on spreading malware over infected web-sites, using PDF, Flash and browser exploits and other techniques rather than e-mail.

Malware detected in mail traffic in April

 01.03.2010 00:00 – 01.04.2010 00:00 
1

Trojan.DownLoad.41551

11193316 (13.64%)

2

Trojan.DownLoad.37236

9927963 (12.10%)

3

Trojan.DownLoad.47256

7320678 (8.92%)

4

Trojan.Botnetlog.zip

5865274 (7.15%)

5

Trojan.MulDrop.40896

5147022 (6.27%)

6

Trojan.Fakealert.5115

5100040 (6.22%)

7

Trojan.Packed.683

4148051 (5.06%)

8

Trojan.Fakealert.5238

3808296 (4.64%)

9

Trojan.DownLoad.50246

2921645 (3.56%)

10

Trojan.Fakealert.5825

2484216 (3.03%)

11

Trojan.Fakealert.5437

1834890 (2.24%)

12

Trojan.Fakealert.5356

1659867 (2.02%)

13

Trojan.Fakealert.5784

1445121 (1.76%)

14

Trojan.Fakealert.5229

1338146 (1.63%)

15

Trojan.PWS.Panda.122

1332036 (1.62%)

16

Trojan.Fakealert.11956

1267041 (1.54%)

17

Trojan.Fakealert.5457

1162458 (1.42%)

18

Trojan.Siggen.18256

1106066 (1.35%)

19

Trojan.Packed.19694

1099122 (1.34%)

20

Trojan.MulDrop.46275

1058813 (1.29%)
Total scanned:

17,689,058,602

Infected:

82,042,532 (0.464%)

Malicious files detected on user machines in April

01.04.2010 00:00
- 01.05.2010 00:00

1

Win32.HLLW.Shadow

834227 (2.84%)

2

Trojan.AuxSpy.187

829685 (2.82%)

3

VBS.Sifil

525939 (1.79%)

4

Trojan.Starter.516

438173 (1.49%)

5

ACAD.Pasdoc

419684 (1.43%)

6

Win32.HLLW.Gavir.ini

364819 (1.24%)

7

Win32.HLLW.Shadow.based

339566 (1.16%)

8

Trojan.DownLoad.32973

330055 (1.12%)

9

Trojan.AuxSpy.111

283554 (0.97%)

10

Trojan.AntiAV.6

231204 (0.79%)

11

Win32.HLLW.Autoruner.9410

170593 (0.58%)

12

Win32.Dref

162827 (0.55%)

13

IRC.Apulia.1215

155887 (0.53%)

14

BackDoor.Tdss.2459

153602 (0.52%)

15

Trojan.PWS.GoldSpy.3382

148201 (0.50%)

16

Win32.HLLW.Autoruner.5555

143042 (0.49%)

17

HTTP.Content.Malformed

132141 (0.45%)

18

Win32.Alman.1

119085 (0.41%)

19

Win32.HLLW.Share

102652 (0.35%)

20

Trojan.PWS.Siggen.2674

85937 (0.29%)

 

Total scanned:

77,991,983,505

Infected:

22,880,659 (0.0293%)
Related Posts
  • Fake anti-viruses and other February 2010 threats
    March 1, 2010 Though short, February saw quite a number of viral threats. Along with traditional and online fake anti-viruses in the spotlight, new extortion schemes involving mobile devices appeare...
  • Emsisoft Anti-Malware score on VB100 April 2010 comparative
    It’s been the first time for Emsisoft Anti-Malware to participate at the Virus Bulletin VB100 comparative. They have tested Anti-Malware 5.0 Beta, which had some troubles during onAccess scan t...
  • Analysis: Spam evolution: April 2010
    The amount of spam detected in mail traffic averaged 83% in April 2010. A low of 79.2% was recorded on 20 April with a peak value of 89.8% being reached on 18 April. View full post on Securelist /...
  • Microsoft Patch Tuesday for April 2010: 11 bulletins
    According to the Microsoft Security Response Center, Microsoft will issue 11 Security Bulletins addressing 25 vulnerabilities on Tuesday. It will also host a webcast to addres...
  • Monthly Blog Round-Up – April 2010
    Blogs are a "stateless" media and people often only pay attention to what they see today. Thus a lot of useful security reading material gets lost.  These monthly round-ups is my way of...
  • April 2010 – Patch Tuesday’s Vulnerability Analysis
    April thus far has been a busy month for administrators tasked with applying updates. As announced, Microsoft released 11 bulletins today. 8 RCEs, 1 DoS, 1 spoofing and 1 privilege escalation. Microso...
  • Spam and Phishing Landscape: April 2010
    After the tragic earthquakes in Haiti and in Chile, there were no additional natural disasters for spammers to take advantage of. Instead, spammers continued to focus on seasonal and calendar events s...
  • Malicious Spam on the increase again
    Malware distribution via email is far from dead.  While we had a distinctly quiet period from October 2010 to March 2011, our stats show the bot herders are gearing up again with the proportion o...
  • The Royal Wedding and The Fake Antivirus
    The Royal Wedding of Prince William and Catherine Middleton that will be held tomorrow, on April 29, will attract the attention of many people around the world, and has become a trending topic on vari...
  • Fake AV for mobile platform
    We have seen countless number of rogue security products for Windows platform however this one is targeted to trick mobile users.The sample masquerades itself as a certain AV for mobile and ...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago