***Warning*** - Trojan File

Miscellaneous Forums/General Discussion/***Warning*** - Trojan File

Please see this topic:

http://www.blitzbasic.com/Community/posts.php?topic=82136

If you downloaded and ran this file, unfortunately we believe your computer has been infected with a trojan file, designed to capture your blitzbasic.com log-in details, and possibly other personal information.

Please immediately change all your personal passwords, and also consider a clean reinstall of your system, as can we cannot be certain how this file is hidden and whether it can be deteted and deleted via virus scanners.

Can anyone e-mail the download to me?

Do you have any other info about this? Such as registry name? Does it place itself in your startup processes?

If anyone wants a link to the file so they can inspect it further then email me.

Also, in addition, BRL are going to have to be careful about who they think is a Blitz account holder.

"RedShark" is not a new account, therefore did the original account holder post it, or has someone taken the account?

Technically speaking, this could snowball - if an account is taken, the imposter(s) can post a download that people think is from that user that also has a trojan

Yes puki this Account, my one, was taken!!!

Maybe it is possible to check my old ShareIt Orders and then transfer it to a "new,, Account and let the old one die (this), i dont know.

Edit:
I mean i give the old Order- Infos to the Support etc.

Thanks for the advice.

Initial scans of it show no signs of a known trojan.

Compiler.exe does attempt a connection but is is not heading to a particular IP as far as I can tell by dry-running it.

I ran it through Spybot, Ad-Aware, Kaspersky, NOD32 and A-Squared.

Only thing to do now is scan the system to see if anything unloaded.

Maybe this could help:
http://www.bugmenot.com/view/blitzbasic.com

Bugmenot is a site for free logins.
I don't know if they work.

We are previously aware of BugMeNot.

Known users had been messing around and adding people to the list.

The success rates posted on BugMeNot are tripe - as far as I know, none of the logins worked for anyone.

Its very rare that I even bother to download anything from here anymore, since Filax did a similar thing several years ago - getting a program to send him e-mails each time anybody ran it.

OK, in that case no sensitive info was stolen, but for me it highlighted just how easily it could be done.

Yes puki this Account, my one, was taken!!!

Maybe it is possible to check my old ShareIt Orders and then transfer it to a "new,, Account and let the old one die (this), i dont know.

Edit:
I mean i give the old Order- Infos to the Support etc.
Why would somebody take your account and not change your password?

Why are the only posts from you within the last few days when all the trouble started? How did you know this thread was here if you weren't bothering with the forums?

A little suspicious.

I agree with GFK, for now at least, I would not download
ANYTHING from RedShark, just to play it safe.

hey guys, my passwort was also not changed. It was just used to post some privat stuff from my machine on the german board (!).

so...cool down.

Maybe the link to the German site should be removed?

So, first it was RedShark, now the German Board ^(3900 Users)...why not close the www? ^^

I'm not saying close the German site. I'm saying there's no sense in linking to it from here if somebody there is trying to steal user accounts.

who says that? Who knows that? And btw. the most BM users from the german board are also here.

Heya,
thats right, the Password wasnt changed GfK.

Please read what i said before in this Thread:
My Blitz account was stolen.... - Post #11

Why the PW wasnt changed, sorry i dont know - why my Account was still usable by me (the real account holder) i was used like a puppet!
see Abrexxes post!

OffTopic:
btw im a Blitz User which isnt a active Board Member (may it German/English or Russian Community),

but i read every day (if i can coz of working) whats going on in the BlitzWorld...
*didnt know that only reading and not being active is a crime!*

Hope to get a word from BRL what i need to do next to get a old/new Acc...!

Hope to get a word from BRL what i need to do next to get a old/new Acc...!
Why bother? Change your password.

Maybe the link to the German site should be removed?

heh.... yeah, right... and ban .de from the internet while we're at it ?

good grief...

Hold on a second!
It was just used to post some privat stuff from my machine on the german board (!).

"Abrexxes" explain this a bit further.

Are you saying that someone would have to have access to your PC to post whatever it was on the German board?

This is important as it opens a new can of worms. Please clarify what you posted above.

heh.... yeah, right... and ban .de from the internet while we're at it ?

good grief...
For the SECOND time, where have I mentioned banning anybody from anywhere?

Wow clicking on the German flag took me indirectly to Don't Get Angry 2, seriously cool looking stuff.

heh :-)

Are you saying that someone would have to have access to your PC to post whatever it was on the German board?


Yes. Not whatever. A privat email from my gmail account. Dont ask me how. I dont now how this is possible.

So who the hell is this "YZnT" posting on Blitzbasic.de? He seems to be chirping on about buying/selling an account.

Hacking a gmail account is pretty common - this will be done without accessing your PC directly. Is there anything, other than this, that makes you think someone has accessed your PC?

One reason I suspect that passwords were not changed is so that there would be no suspicion. This tactic is also used by hijackers of steam accounts.

They don't change the password and just harvest details like emails and friends lists etc and when they have enough so they can go on a mass account hijack that's when passwords are changed and their scam emails sent to other members.

I think this may be a reason why the passwords on the stolen accounts werent changed. While accesing the board they could have harvested alot of emails.

I remember a member who quite blatantly used to use php hacks on bb.com and got a list of all members. I'll name this member as I have never trusted him.

When the whole fiasco about the Gallery started he posted on the forum something along the lines of this "oops sorry, hope it wasn't me. I used a php script to upload more than 1 picture at a time.

This guy was called DevilsChild.

I apologise to him if he has nothing to do with all this but I'm just pointing out the other stuff he's done before e.g admitting to the Gallery upload hack.

[edit] Edited out funny type. Missed out an m on mass. :)

The same time i was in IRC, so no problem to get my current IP.

When i try to search the forums using Devilchilds name I get the following error appearing at the top of the page.


Warning: mysql_fetch_row(): supplied argument is not a valid MySQL result resource in /home/rvadmin/public_html/Community/bbs.php on line 61


Also it doesn't seem it's finding DevilsChild. He may have changed his name.

Technically, we have our suspect.

The suspect posted both here and on Blitzbasic.de

Here the post was made under the account of "RedShark", on Blitzbasic.de it was "YZnT".

I suggest the mods of both sites liaise regarding the IP for each post. Or, failing that, both sites report the IPs individually.

I suggest the Germans start talking about this "YZnT".

Has anyone been able to get the ISP of the attacker?

Devils Child. You likely didn't find it because you missed a space. Also, I ran that and my account wasn't hacked.

Devils Child. You likely didn't find it because you missed a space. Also, I ran that and my account wasn't hacked.

It would rely on being able to connect to the internet or accept an incoming connection.

I've yet to run it live; however, in a dry-test it does initially try an ISP DNS through Port53 - which can be interpreted as trojan/worm behaviour - unless this is a side-effect of a Blitzmax exe under certain conditions.

I assume that running it live and activating it will either lead to the IP or a firewall will show an incoming connection.

Still, at least two IPs (possibly the same IP) posted the link.

Not sure if I will be running it live tonight though - as I want to scan it fully before doing so.

I think you're playing with fire.

We'll look after you though. If your account suddenly starts stops posting childish, incoherent nonsense, we'll be sure to alert a moderator post haste. :D

Stuff-it. I got bored of waiting.

I let it connect to the internet - I see a German connection.

Now let's take a closer look.

All seems too eloborate to me. Seemed to go via smtp-ha.web.de:smtp

This type of set-up could steal a gmail account (which is what "Abrexxes" claimed) and other data as well (such as Blitz logins).

I am going to bed now.

Personally... I think the scumbags that are doing all that hacking, should be put up against a wall and shot !

>Personally... I think the scumbags that are doing all
>that hacking, should be put up against a wall and shot!

Or better yet, get locked up until such time as they have ported Linux to Algol.

We'll look after you though. If your account suddenly starts stops posting childish, incoherent nonsense, we'll be sure to alert a moderator post haste. :D


well if i start posting exe's and stuff its either
A an account theif
B hells frozen over ;)

Btw. asking to remove the link to the german site is nonsense in more than one way:
- the link directs to blitzbasic.de, a site owned by an author who wrote a german book about blitzbasic. Although this author has an account in the german board, he does not run it or has any influence on the work of administration there.
-removing this link won't keep the bad guys from stealing anyones account as they posted their trojan on this board. Want to close it to be safe?
-Ok, this idiot is from germany. So the complete german board tries to steal accounts? Sorry, but this is ridiculous.

I am moderator at www.blitzforum.de and we are doing our best to help brl getting this dumbhead, and as far as the german laws allow it we will sue him, if there is only a little chance to do so.

Also we informed our members about the thefts and asked them to change their passwords. We will further ask them not to buy/sell any third Party accs as long as there is no safety for both seller and buyer.

We will further ask them not to buy/sell any third Party accs as long as there is no safety for both seller and buyer.
That's sensible. They'll only get their stolen account taken off them and return to the rightful owner, and lose their money anyway.
and as far as the german laws allow it we will sue him, if there is only a little chance to do so.
It would teach him a lesson if you did. But realistically, what's it going to cost to do that?

What's going to cost letting him running around and stealing more accounts?
Think realistic. :p

Regarding the fact that he commited a crime by stealing the accounts the german court would act as accuser and all costs would be beared by state. I am no lawyer and therefore I can't tell if this case would be of an interest big enough for the state's attorney, but I am willing to give it a try.

Don't know how the chances stand to act, but if we can, we will shurely do.

THIS THING APPEARS HIGHLY DANGEROUS

After spielerrie.exe was allowed an internet connection it created Compiler.exe (548 KB) in the Window's System32 folder; along with attack_normal.exe (871 KB) - Attack_normal.exe appears to be a Bmax.exe

Compiler.exe also appears in Local Settings\Temp as tmp112.exe
Spielerrei.exe, attack_normal and compiler.exe go into Windows' Prefetch


Now we are into Local Settings\Temp - I see it probably trying to steal Windows Messenger log-ins - or maybe attempting to use Messenger.

Next it is in my ISP dialler.

Next it attempts the Blitzbasic login.


All of that happened at the same time when I granted it internet access. There are .tmp files left behind

4 Minutes later I see the Firefox signons being accessed, but not sure if that was just me using Firefox. Basically, FF signons is a list of all your websites and passwords. So, it would be advisable to start changing passwords on everything in there. However, I am not totally sure if this thing did access it.

On another PC, where it was refused internet access, it did not create any files in System32 and I do not see any temporary files being created in Local Settings\Temp.

What's going to cost letting him running around and stealing more accounts?
Think realistic. :p
I am being realistic - put things in perspective.

The best solution would be a class action from everyone that's had their accounts tampered with over this, but even then you'd have to find enough willing participants who would rather hunt this guy down rather than just change their password and move on.

I don't know enough about law to have any idea where the funding would come from. We have the Legal Services Commission (AKA Legal Aid) in the UK but I wouldn't know if a case like this would qualify for funding.

Don't get me wrong - if you had this guy up against a wall then I'd be happy to pull the trigger for you. I'm just trying to keep it real as to what you can/should do about it.

It would be interesting to see if anyone has any of the tmp files in their Local Settings \ Temp folder.

They will be sequential, probably with an exe called tmpXXX.exe - the XXX being a numerical value - the file size will be 584 KB - the tmp files will probably be 1 KB.

On my system, it accessed them in this order - these are edited copies of the contents of the tmp/txt files:

==================================================
Software : Windows Live Messenger
Protocol : MSN Messenger
User : your e-mail address
Password : your Messenger password
==================================================


==================================================
Entry Name : Your ISP dialler
Phone / Host :
User Name :
Password :
Domain :
Owner : System
User Profile : Whatever
==================================================

==================================================
Entry Name : the name of the dialler
Phone / Host : MSDUN
User Name :
Password : password
Domain :
Owner : System
User Profile : Whatever
==================================================


==================================================
Entry Name : http://www.blitzbasic.com/account/login.php
Type : AutoComplete
Stored In : Registry
User Name : puki
Password :
==================================================



The tmp file for the Blitz one did not have my password filled in- it was null - either it failed to get the password or it did this separately.

It may try to grab more than this - this is just all I found. Possibly, it did not clean up properly after itself.

It could be set to sweep for other log-ins such as Blitzbasic.de, gmail, hotmail, whatever. I don't use gmail, hotmail or have a Blitzbasic.de account (as far as I remember), so it may just skip these and not create blank files.

Which is why I am hoping other people who ran it can check their Temp folder for any traces of what it tried to harvest.

You ran this on your computer??

Most likely from a sandbox environment like a Virtual Machine, even puki isn't that crazy (I hope).

No, I ran it live - I wanted to see what would happen. It had to be tested fully to see if it was or was not a threat.

So have other people in the orginal thread: http://www.blitzbasic.com/Community/posts.php?topic=82136

I won't let other Blitzers stand alone.

I say the rodent should die.

Scary stuff.

I'm really considering a clean install of the system.. But I want to wait until we identify what the virus drops... I've deleted attack_normal and compiler.exe in system32 file... I've cleaned out my temp folders... Now what? This is quite a piece of work.. Whoever made it clearly thought it through.

The idiot is probably purely after Blitz log-ins. However, I am going to claim he stole my bank log-ins and everything else.

In fact, I can claim as much as I like.

The way to catch the culprit is to attract attention to them - tell a few lies - make a few allegations.

/me throws puki some smarties and sausages for his hard work

What would he do with blitz logins though? All it takes is a email to simon to get it sorted. And with everyone knowing a virus is about, if someone randomly goes on a spamming rampage then obviously it may not be them.

I doubt he's only after Blitz log-ins. Likely email as well, and maybe more.


No, I ran it live


:O

"KillerX" has reported it basically grabs all the passwords it can get.

I spotted the access to FF Signons about 4 minutes after the program was given internet access.

So, we do not need to make any stories up.

It stole banking log-ins, Paypal, e-bay - anything it could get it's hands on.

I will be e-mailing BRL and the admins of Blitzbasic.de tomorrow as this will need to involve the authorities.

Regardless of the above, I will personally pursue the culprit.

The person should be arrested and prosecuted. As far as I can see, it will probably involve a prison sentence.

Edit [removed]

Come on, VIP3R :D

Abrexxes speaks German and the trojan-fags do too. In German "password" is written "passwort".

Don't get paranoid ;)

Isn't "Password" "Passwort" in German? If my old German classes serve me correct.


So the culprit is from Germany.

Oh good, I'll remove the post :)

Not paranoid, I didn't download it anyway ;)

There are currently multiple suspects.

We can tell them apart via the ISP and IP - it will be down to the authorities to tell who is who.

We have to bare in mind that we cannot be sure that a Blitzer has posted something themselves or if it is the culprit using their account like a puppet-master.

Whoever it is may have tried to throw the scent in different directions - maybe they are not even German?

Wow this is more serious then I thought.

I'm just lucky I didn't download this!


My hats off to Puki for all his hardwork too!
(*Throws Puki a sausage*)

I really hope they nail this guy!

It is bloody great though.

Banks and authorities all over the world are pursuing people that steal banking log-ins. This idiot has left themselves wide open for prosecution - coz they didn't do it it quite as remotely as they thought they had.

In fact, let's think about this. To be harvesting the bank log-ins for Blitzers, the individual must be passing the info on. This makes them a bigger target for prosecution.

If I was this person reading this now, I would be absolutely crapping myself. This person must be scared out of their wits - everytime the phone rings, or there is someone at the door they will be panicking.

I will speak to my bank tomorrow - I tell them that the culprit has captured banking details for an unknown amount of people - I know that 47 downloads of the file were made prior to me downloading it. We know where they uploaded and we know where the posted - we even know where the passwords went.

WHAT A COMPLETE LOSER! THEY ARE GOING TO PRISON!

this sucks, thanks for the warning, did run the crapola file as suggested in the thread, a trojan hunting we will go....

You may not find a trojan - don't rely on tracking it down - I have yet to detect it, other than I predicted its behaviour and watched what it did and where it went.

As far as I can tell, it is only dangerous when it is granted internet access - launching it on another PC and denying internet access didn't produce the same results.


I heard you can get raped in prison.

McAfee didn't detect crap. I set my firewall to ask promission for incoming and outbounding connections to the internet. I thought it was already set like this. I also checked all my ports to see if any were opened... they're still closed.

>I heard you can get raped in prison.

No/Yes.. But there is a prison in the USA where they make you wear pink clothes and watch the Disney channel.

I'm one of those 'intelligent' people downloaded that program - and run it...
I've checked all my credentials on different sites (of course I changed all the passwords).
The only thing is I can't access anymore to my Gmail account...someone has changed the password :D (Great son of....) and I can't get working the automatic recovery with secondary email (I suppose they/him changed it too).
I'm still looking for informations for locking (forever) my gmail account (I dont' want to be considered a 'spammer' thanks to these people...)

Well, look on the bright side: whatever the culprit tries to take control of just makes them a bigger target for the authorities.

They probably think they won't get caught. I think they will.

People need to keep notes - dates and times of anything you spot that has changed.

I just hope that BRL and Blitzbasic.de don't forget the IPs that posted on the forums. "YZnT" posted many times on Blitzbasic.de as a new user. BRL and Blitzbasic.de need to make sure they don't suddenly 'lose' any information regarding the poster(s).

I'm also one of the intelligent people who downloaded and trialled the t**ts software. I've still got a copy of the textfile with my passwords populated in it. Thankfully it was on an older computer that gets used for next to nowt.

I will speak to my bank tomorrow - I tell them that the culprit has captured banking details for an unknown amount of people - I know that 47 downloads of the file were made prior to me downloading it. We know where they uploaded and we know where the posted - we even know where the passwords went.

WHAT A COMPLETE LOSER! THEY ARE GOING TO PRISON!


if this is true, result.

A bit more evidence to pass on to BRL, or whoever chases the numpti down (obviously with the passwords changed).

The UK Metropolitan Police have a useful website for reporting this whole affair. Looks like the FBI will step in as well.

The culprit falls into multiple catagories that are reported/investigated separately.

This guy is basically involved in fraud - there is a suspicion (apparant evidence, according to sources) of Blitz accounts being stolen and sold. They are also fraudulant, by using other peoples' email/messenger accounts to pose as someone else.

They are stealing log-ins and passwords which include banking and other financially related (e-bay, PayPal) logins. These all branch into separate lines of enquiry.


If the idiot had simply been stealing Blitz accounts it would never have been investigated - nobody would have taken it seriously. Basically, they have dug themselves into one huge hole. Let's hope that the prosecution of this person(s) ends all future types of these incidents ever happening again.

Baring in mind that other forums are at risk - Leadwerks, Squeaky Duck, etc. People could now be downloading Leadwerks Engine, Cobra and god knows what else and selling them on. The scope of access that they have is probably quite wide.

@Puki have any AV's recognized the files as problems after the this crap has gained Internet access?
I did run this but any unknown application that ask for net access right away never gets it from me. And I can't see any of these files on my system.

EDIT: I think this problem should be the top news item in the Blitz home page.

If you did not grant permission then it probably did not unload the files. I found that it only unloaded when granted access.

It basically does it all very quickly. Probably, the author expected a lot of people would refuse the connection request, so the author didn't want it doing anything out of the ordinary unless it was going to send the info.

As far as I can tell, this is a custom job - I think at least one Blitzer said his AV detected it after the event - I've thrown two AV and multiple anti-malware packages at it and nothing was found before or after.

The original exe splits into the bmax exe and a compiler exe, the bmax exe calls the compiler which will then try to phone home.

If the AV's aren't finding it in the original exe then once it has a net connection it must be downloading the nasties. Is it effecting both Vista and XP in the same way?

Dunno, I only have XP.

I don't think anything came in - I believe compiler.exe does everything and then sends it. The Bmax exe is the cover - it is what the user thinks is running, whilst compiler operates in the background - it's basically to distract the victim.

The trojan may be based on this:

Trojan steals passwords FireFox users
http://www.guru3d.com/news/trojan-steals-passwords-firefox-users/

hmmm... I downloaded this on vista and ran it a couple of times and deleted it... no sign of anything dangerous.

how can i tell if its on my computer?

check in "C:\Documents and Settings\<insert username here>\Local Settings\Temp" and see if you find tmp112.exe. If its there, it means that it submitted your personal information already.

^ The temp folder paths are different in Vista.

Try these...

C:\Users\<insert username here>\AppData\Local\Temp
C:\Windows\Temp

the easiest way to find the temp folder on any computer is to just browse to %temp% from within Explorer.

It will put you in that user's temp folder, regardless of where it's been moved to.

@Nate the Great
Did you have UAC turned on?
In puki's earlier post above

After spielerrie.exe was allowed an internet connection it created Compiler.exe (548 KB) in the Window's System32 folder; along with attack_normal.exe (871 KB) - Attack_normal.exe appears to be a Bmax.exe

Compiler.exe also appears in Local Settings\Temp as tmp112.exe
Spielerrei.exe, attack_normal and compiler.exe go into Windows' Prefetch


Now we are into Local Settings\Temp - I see it probably trying to steal Windows Messenger log-ins - or maybe attempting to use Messenger.

Next it is in my ISP dialler.

Next it attempts the Blitzbasic login.

If it tried to access any of the system files UAC would have be triggered.

EDIT: I just read what Naughty Alien posted on Graphics Show Case about posting screen shots only instead of links to zip files. May be there should be another section where requests to post links/file can be made or email a mod with with a request so that the file it can be vetted for malware.


EDIT: I just read what Naughty Alien posted on Graphics Show Case about posting screen shots only instead of links to zip files. May be there should be another section where requests to post links/file can be made or email a mod with with a request so that the file it can be vetted for malware


The problem is neither AVG, Antivir and Spybot relevead the malware...

The problem is neither AVG, Antivir and Spybot relevead the malware...

Well non of them work 100% of the time, but a better word than malware would have been suspicious activity.

just finished resetting passwords, can get on the internet again - just got to report this password harvester now - as puki suggests lots of way to inform the relevant bods. last time I try anything out though... lesson learned. So, does anyone know the detination where the file that had been generated was being sent specifically, if so I'd sure be pleased to see the person who (possibly) received my logins & passwords listed. Scum of the earth to say the least.

@Puki & all, thanks for finding out and listing where the guilty files were/are - good work to say the least. Happy New Year!

@ "Abrexxes"

From initial thread:
i found a trojan in my windows folder in 3 files. I have killed them with Antivir after a restart. (Bitdefender has found nothing)


"Abrexxes" - just to clarify - are you saying that Avira AntiVir detected it? If so, was it the free version? Also, I assume you only found it after you had run the file?


In the meantime, I am going to start submitting the file to various people to look at.

Hi,

have someone of you uploaded the file/s to VirusTotal(.com)? That's a realy nice service :)
If someone could upload the files there, please post the links here. (Till now I have not the files, maybe one could send me a download link?)
Btw: As I know, if you upload the files to VirusTotal.com, the files are also send to all of the AntiVirus-Developers, so they could add it to there lists. :-)

greetings
#Reaper

(edit: and sorry for my baad english...)

Someone has already uploaded it there.

This was the result:
File spielerrei.exe received on 12.17.2008 18:01:14 (CET)
Current status: finished
Result: 2/38 (5.26%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.12.17.3 2008.12.17 -
AntiVir 7.9.0.45 2008.12.17 -
Authentium 5.1.0.4 2008.12.17 -
Avast 4.8.1281.0 2008.12.17 -
AVG 8.0.0.199 2008.12.17 -
BitDefender 7.2 2008.12.17 Trojan.Dropper.RQU
CAT-QuickHeal 10.00 2008.12.17 -
ClamAV 0.94.1 2008.12.17 -
Comodo 771 2008.12.17 -
DrWeb 4.44.0.09170 2008.12.17 -
eSafe 7.0.17.0 2008.12.17 -
eTrust-Vet 31.6.6265 2008.12.17 -
Ewido 4.0 2008.12.17 -
F-Prot 4.4.4.56 2008.12.17 -
F-Secure 8.0.14332.0 2008.12.17 -
Fortinet 3.117.0.0 2008.12.17 -
GData 19 2008.12.17 Trojan.Dropper.RQU
Ikarus T3.1.1.45.0 2008.12.17 -
K7AntiVirus 7.10.556 2008.12.17 -
Kaspersky 7.0.0.125 2008.12.17 -
McAfee 5466 2008.12.16 -
McAfee+Artemis 5466 2008.12.16 -
Microsoft 1.4205 2008.12.17 -
NOD32 3699 2008.12.17 -
Norman 5.80.02 2008.12.17 -
Panda 9.0.0.4 2008.12.17 -
PCTools 4.4.2.0 2008.12.17 -
Prevx1 V2 2008.12.17 -
Rising 21.08.22.00 2008.12.17 -
SecureWeb-Gateway 6.7.6 2008.12.17 -
Sophos 4.37.0 2008.12.17 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.17 -
TheHacker 6.3.1.4.190 2008.12.17 -
TrendMicro 8.700.0.1004 2008.12.17 -
VBA32 3.12.8.10 2008.12.16 -
ViRobot 2008.12.17.1523 2008.12.17 -
VirusBuster 4.5.11.0 2008.12.17 -
Additional information
File size: 1609862 bytes
MD5...: 8442d9e4582ae6ffc4dd67039b4015d2
SHA1..: bbf871b4f4332a186f89804287bd1968fac0a823
SHA256: e4f3031339c629c263ab823cb888f7ae80a00e6998e75cfb96fafe27ea4081f1
SHA512: 450d7e75837392239c9d68f461fc48298fa31062afb499c05388aca49efd32d6
cfa47aa56a38f083f376d5cb4718e616418dbcdb3a4b804029b0d43b54e3026b
ssdeep: 49152:+nE2RU9Bxq/dSCClxYbZQyD4Rprc2uSZJYD:+nd4x2vClxhycRdY
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4097cd
timedatestamp.....: 0x4947ebbc (Tue Dec 16 17:56:12 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1a000 0x1a000 6.48 b057f422730a06f6545d7ff80e9b09da
.myspace 0x1b000 0x9000 0x9000 3.67 160c98b684349894784db7aa4843bf76
.rsrc 0x24000 0x2000 0x165086 6.97 0360604dbdb06f03879e67fb503f12c1

( 3 imports )
> KERNEL32.dll: CreateFileA, GetCurrentDirectoryA, lstrcatA, GetTempPathA, lstrcpyA, ReadFile, GetEnvironmentVariableA, GetShortPathNameA, WriteFile, GetModuleHandleA, Sleep, GetWindowsDirectoryA, GetSystemDirectoryA, GetCurrentProcess, CloseHandle, lstrlenA, GetProcAddress, GetModuleFileNameA, lstrcmpA, LoadLibraryA, ExitProcess, InterlockedIncrement, InterlockedDecrement, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetLastError, HeapFree, DeleteFileA, RtlUnwind, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RaiseException, HeapAlloc, GetCommandLineA, GetVersionExA, GetProcessHeap, GetStartupInfoA, LCMapStringA, WideCharToMultiByte, MultiByteToWideChar, LCMapStringW, GetCPInfo, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetHandleCount, GetStdHandle, GetFileType, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, HeapSize, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, GetLocaleInfoW, CreateFileW, SetEndOfFile
> USER32.dll: wsprintfA
> ADVAPI32.dll: RegCreateKeyExA, RegSetValueExA, RegCloseKey, RegOpenKeyExA, RegDeleteKeyA

( 0 exports )


The thing is - I suspected that, based on the new FF exploit, the Bit Defender would identify it (as above); however, "Abrexxes" claims it didn't and that AntiVir did - this contradicts the above.


Interestingly, this is Compiler.exe (which is what it splits into):

File compiler.exe received on 12.17.2008 14:58:16 (CET)
Current status: finished
Result: 0/37 (0.00%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.12.17.3 2008.12.17 -
AntiVir 7.9.0.45 2008.12.17 -
Authentium 5.1.0.4 2008.12.17 -
Avast 4.8.1281.0 2008.12.16 -
AVG 8.0.0.199 2008.12.17 -
BitDefender 7.2 2008.12.17 -
CAT-QuickHeal 10.00 2008.12.17 -
ClamAV 0.94.1 2008.12.17 -
Comodo 771 2008.12.17 -
DrWeb 4.44.0.09170 2008.12.17 -
eSafe 7.0.17.0 2008.12.16 -
eTrust-Vet 31.6.6265 2008.12.17 -
Ewido 4.0 2008.12.17 -
F-Prot 4.4.4.56 2008.12.17 -
F-Secure 8.0.14332.0 2008.12.17 -
Fortinet 3.117.0.0 2008.12.17 -
GData 19 2008.12.17 -
Ikarus T3.1.1.45.0 2008.12.17 -
K7AntiVirus 7.10.555 2008.12.16 -
Kaspersky 7.0.0.125 2008.12.17 -
McAfee 5466 2008.12.16 -
McAfee+Artemis 5466 2008.12.16 -
Microsoft 1.4205 2008.12.17 -
NOD32 3698 2008.12.17 -
Norman 5.80.02 2008.12.16 -
Panda 9.0.0.4 2008.12.17 -
PCTools 4.4.2.0 2008.12.17 -
Prevx1 V2 2008.12.17 -
Rising 21.08.22.00 2008.12.17 -
Sophos 4.37.0 2008.12.17 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.17 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.17 -
VBA32 3.12.8.10 2008.12.16 -
ViRobot 2008.12.17.1523 2008.12.17 -
VirusBuster 4.5.11.0 2008.12.16 -
Additional information
File size: 561152 bytes
MD5...: f0c0d51da0aba409ff28699b9ae0ecd9
SHA1..: eb8504537986e3f43565b9a6496bc33caa787055
SHA256: c1c4e37f533d5422c52ba9f4056535190c2bd4936fa0b010b8c0e97e13f0daa7
SHA512: 976fea8cadf4fa4aae427e221d32e905602d8cb8bff9f1518299128c9958bc24
f49bae9787af7f636eed7882b51d852be430f46b6c402f4d63020d10a0b3e26c
ssdeep: 12288:s8AU/+W7itTPGHRlRXwPgWoIiAFLTW39p3L:s8v/+jtaHRjXwZjT49Z
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x403b30
timedatestamp.....: 0x4947e9d3 (Tue Dec 16 17:48:03 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x97d5 0xa000 6.46 6ad0fa2197546221c63bd7cc59e1dfb3
.mappis 0xb000 0xa8ac 0xb000 6.53 a26d49b02e3ae589bdf1e2f104865c05
.rsrc 0x16000 0x725b4 0x73000 7.99 1952fbd23bcb8a755def2f0cae0e0efc

( 3 imports )
> KERNEL32.dll: lstrcatA, GetWindowsDirectoryA, GetProcAddress, LoadLibraryA, GetLastError, CreateMutexA, GetCurrentProcess, CreateFileA, lstrcpyA, GetFileSize, GetModuleHandleA, GetModuleFileNameA, ExitProcess, lstrcmpA, ReadProcessMemory, CloseHandle, Sleep, lstrlenA, RtlUnwind, GetCommandLineA, HeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, GetStartupInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, WriteFile, GetStdHandle, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, DeleteCriticalSection, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RaiseException, LeaveCriticalSection, EnterCriticalSection, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, InitializeCriticalSection, VirtualAlloc, HeapReAlloc, HeapSize, GetLocaleInfoA, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, LCMapStringA, LCMapStringW
> ADVAPI32.dll: GetUserNameA, RegOpenKeyExA
> SHELL32.dll: ShellExecuteA

( 0 exports )


This one is attack_normal.exe (the actual BMax exe) which is the second main part that spielerrei.exe splits into.

File attack_normal.exe received on 12.17.2008 14:22:36 (CET)
Current status: finished
Result: 0/38 (0.00%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.12.17.3 2008.12.17 -
AntiVir 7.9.0.45 2008.12.17 -
Authentium 5.1.0.4 2008.12.17 -
Avast 4.8.1281.0 2008.12.16 -
AVG 8.0.0.199 2008.12.17 -
BitDefender 7.2 2008.12.17 -
CAT-QuickHeal 10.00 2008.12.17 -
ClamAV 0.94.1 2008.12.17 -
Comodo 771 2008.12.17 -
DrWeb 4.44.0.09170 2008.12.17 -
eSafe 7.0.17.0 2008.12.16 -
eTrust-Vet 31.6.6265 2008.12.17 -
Ewido 4.0 2008.12.17 -
F-Prot 4.4.4.56 2008.12.17 -
F-Secure 8.0.14332.0 2008.12.17 -
Fortinet 3.117.0.0 2008.12.17 -
GData 19 2008.12.17 -
Ikarus T3.1.1.45.0 2008.12.17 -
K7AntiVirus 7.10.555 2008.12.16 -
Kaspersky 7.0.0.125 2008.12.17 -
McAfee 5466 2008.12.16 -
McAfee+Artemis 5466 2008.12.16 -
Microsoft 1.4205 2008.12.17 -
NOD32 3698 2008.12.17 -
Norman 5.80.02 2008.12.16 -
Panda 9.0.0.4 2008.12.17 -
PCTools 4.4.2.0 2008.12.17 -
Prevx1 V2 2008.12.17 -
Rising 21.08.22.00 2008.12.17 -
SecureWeb-Gateway 6.7.6 2008.12.17 -
Sophos 4.37.0 2008.12.17 -
Sunbelt 3.2.1801.2 2008.12.11 -
Symantec 10 2008.12.17 -
TheHacker 6.3.1.4.189 2008.12.16 -
TrendMicro 8.700.0.1004 2008.12.17 -
VBA32 3.12.8.10 2008.12.16 -
ViRobot 2008.12.17.1523 2008.12.17 -
VirusBuster 4.5.11.0 2008.12.16 -
Additional information
File size: 892416 bytes
MD5...: 6ec4ad0dad2f490e81bbadfc90271297
SHA1..: 094b3556ebecce0a7f313b066922c6b6479d97fb
SHA256: 9424e3b908e42b259345938eff08c8b2c668d2ab2090e11d15123cdfacf91700
SHA512: 65ccb58214b16e6bad978dbb48cadb05a94e390aa843b7c998cccdd81f379bd2
44303674948ec07225138a2b1bd049defd4c546d7cb89f6f1c23a37135fe7da7
ssdeep: 12288:Adxif4k5Y1sfyT7d4SnYVwuPnFwPDPNAPFmNxZTPxPnF58p+DikV9qZH:R
Q11sqRnYV7PnGPDP+IPxPn
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.1%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x4012b0
timedatestamp.....: 0x4845abfa (Tue Jun 03 20:39:22 2008)
machinetype.......: 0x14c (I386)

( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x6f24 0x7000 6.32 d34dad9562f62f4897b6d5b990179bc3
code 0x8000 0x4425b 0x44400 5.93 7cff53c852345c29e2c5474f285df2e9
.data 0x4d000 0x420 0x600 1.38 8b963ae54e68d179ff9f4820d0e96505
data 0x4e000 0x8c1cc 0x8c200 5.36 2cac7c8d0a102f6314cb5c12e9cf3902
.rdata 0xdb000 0x450 0x600 4.38 93967891752a961c68a426b4e2b1384e
.bss 0xdc000 0x83e0 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0xe5000 0x17a0 0x1800 5.01 5da952257b849095ddfabcdebdebc3fc

( 11 imports )
> COMCTL32.DLL: _TrackMouseEvent
> COMDLG32.DLL: GetOpenFileNameA, GetSaveFileNameA
> GDI32.dll: BitBlt, ChoosePixelFormat, SetPixelFormat, SwapBuffers
> KERNEL32.dll: AddAtomA, CloseHandle, CreateProcessA, CreateThread, ExitProcess, FindAtomA, GetAtomNameA, GetCurrentThreadId, GetExitCodeProcess, GetFileAttributesA, GetFullPathNameA, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, LoadLibraryA, SetUnhandledExceptionFilter, Sleep, WaitForSingleObject
> msvcrt.dll: _chdir, _chmod, _getcwd, _mkdir, _putenv, _rmdir, _stat
> msvcrt.dll: __getmainargs, __mb_cur_max, __p__environ, __p__fmode, __set_app_type, _assert, _cexit, _errno, _findclose, _findfirst, _findnext, _fullpath, _iob, _isctype, _onexit, _pctype, _setmode, abort, acos, asin, atexit, atof, ceil, cosh, exit, fclose, fflush, fgets, floor, fmod, fopen, fprintf, fputs, fread, free, fseek, ftell, fwrite, localtime, log10, malloc, memcpy, memmove, memset, pow, printf, remove, rename, signal, sinh, sprintf, strchr, strcmp, strcpy, strftime, strlen, strrchr, tan, tanh, time, toupper
> OPENGL32.DLL: glAlphaFunc, glBegin, glBindTexture, glBitmap, glBlendFunc, glClear, glClearColor, glColor4ubv, glDeleteTextures, glDisable, glDrawPixels, glEnable, glEnd, glGenTextures, glGetDoublev, glGetIntegerv, glGetTexLevelParameteriv, glLineWidth, glLoadIdentity, glLoadMatrixd, glMatrixMode, glOrtho, glPixelStorei, glPopAttrib, glPushAttrib, glRasterPos2i, glReadPixels, glScissor, glTexCoord2f, glTexImage2D, glTexParameteri, glTexSubImage2D, glVertex2f, glVertex2i, glViewport, wglCreateContext, wglDeleteContext, wglGetCurrentContext, wglGetProcAddress, wglMakeCurrent, wglShareLists
> SHELL32.DLL: SHBrowseForFolderA, SHGetPathFromIDListA, ShellExecuteA
> USER32.dll: AdjustWindowRect, AdjustWindowRectEx, CallNextHookEx, ChangeDisplaySettingsA, ClientToScreen, CreateWindowExA, DefWindowProcA, DestroyWindow, DispatchMessageA, EnumDisplaySettingsA, GetActiveWindow, GetClientRect, GetCursorPos, GetDC, GetFocus, GetForegroundWindow, GetKeyState, GetParent, GetWindowLongA, IsDialogMessageA, IsIconic, LoadCursorA, MessageBoxA, MsgWaitForMultipleObjects, PeekMessageA, PostThreadMessageA, RegisterClassA, ReleaseCapture, ScreenToClient, SendMessageA, SetCapture, SetCursorPos, SetFocus, SetWindowsHookExA, ShowCursor, ShowWindow, TranslateMessage, ValidateRect
> WINMM.DLL: timeBeginPeriod, timeEndPeriod, timeGetTime
> WSOCK32.DLL: WSACleanup, WSAStartup, __WSAFDIsSet, accept, bind, closesocket, connect, gethostbyaddr, gethostbyname, getpeername, getsockname, getsockopt, htonl, htons, listen, ntohl, ntohs, recv, recvfrom, select, send, sendto, setsockopt, shutdown, socket

( 0 exports )



So, once the file has hatched nothing is detected by any major antivir products. There is only a tiny chance of detection with the original spielerrei.exe.

:o

oh no its there!

ugg I guess im infected too but I changed my password and I cant seem to find compiler.exe or attack_normal.exe


edit

hmmm... it wont let me delete it because it says I dont have admin priveleges but I know I have the highest admin privleges and it always does that when a program is using that file so what is the process that is using it called?

edit 2

never mind I found all 3 things and deleted them :) now I gotta change all my passwords :p

In addition, in case anyone is wondering - the tmp112.exe (previously discussed) is basically a copy of Compiler.exe that goes into the temp folder - it has already been checked.

"Nate the Great" - what can you not delete?

Compiler.exe (548 KB) and attack_normal.exe (871 KB) - will probably drop into the Window's System32 folder (in WinXP). On one system, whereby Compiler.exe did not gain internet access, the files weren't there - either they didn't deploy (due to no internet access) or the trojan deletes them to prevent detection prior to transmission. I'm not totally sure. As I have only ever run it live once.

puki

I can delete it now I just had to clean up my processes... must of been one of those random suspicious processes I ended :p

Hmm..
interesting: The results of VirusTotal are all from the 17. December 08.
spielerei.exe - http://www.virustotal.com/analisis/f3cb0195118db63d09b29b6664d7f9ec
compiler.exe - http://www.virustotal.com/analisis/6b6dcf35d6240f01631ec8ef722d1f27
attack_normal.exe - http://www.virustotal.com/analisis/cb2fdaa94a77b26ab42bd87ca0542345

Btw: spielerei(.exe) is a german word. :-/ (In english somethink like "gimmick")

Because the results are so old, could someone upload the files again?
Then just post the link here, which is avaible after you uploaded the files, so we can see the results easily. Thanks!

Okay, I'll do that now.

EDIT:
File spielerrei.exe received on 12.30.2008 16:09:06 (CET)
Current status: finished
Result: 8/39 (20.51%)
http://www.virustotal.com/analisis/116cba730e563b493c72208a52b191c9

I'll edit this post further with the other results when I get them in the next few minutes.

File attack_normal.exe received on 12.30.2008 16:14:48 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/39 (0%)

File compiler.exe received on 12.30.2008 16:17:04 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/39 (0%)


So, only the original spielerrei.exe is showing any signs of the trojan.



Currently, I am trying to find out what legal action can be taken against the culprit - baring in mind their nationality, the locations of the sites they posted to and the nationalities of the victims.

EDIT: I just read what Naughty Alien posted on Graphics Show Case about posting screen shots only instead of links to zip files. May be there should be another section where requests to post links/file can be made or email a mod with with a request so that the file it can be vetted for malware.
I think it would be better to just email them the source code, and then they would post an exe.

Also, my firewall says that it was one of these IPs that the information was sent to:
169.254.1.6
217.72.192.157
Could one of the website admin check if anybody logged on with either of those IPs.

This is the entry into the firewall log:
2008-12-30 13:08:51 OPEN TCP 169.254.1.6 217.72.192.157 1470 25 - - - - - - - - -

the second IP address appears to resolve to this:

IP Address: 217.72.192.157&submit=+Resolve+IP+Address+
Hostname: smtp-ha.web.de

All seems too eloborate to me. Seemed to go via smtp-ha.web.de:smtp

I concur.

would there be any benefit in informing my ISP of the activity regarding password harvesting then the potential for it being sent to the hostname: smtp-ha.web.de ?

"Blitzplotter"- You can do that if you want; however, you may want to hang fire.

I am already in talks with security specialists who have now got the trojan and are looking at it.

They have not yet answered my queries about legal proceedings - I think they want to look at the file and see exactly what it does.

It may be a slow process - could be months. Normally, these investigations move into survellience operations - they basically look at the persons' life history.

IP 169.254.1.6:
http://www.maps.google.com/maps?f=q&hl=en&geocode=&q=4676+admiralty+way,+suite+330,+CA&sll=37.0625,-95.677068&sspn=56.899383,114.257812&ie=UTF8&ll=34.651285,-115.3125&spn=14.960401,28.564453&z=6&iwloc=addr

IP 217.72.192.157:
http://www.maps.google.com/maps?f=q&hl=en&geocode=&q=brauerstrasse+48+d-76135+karlsruhe,+germany&sll=34.651285,-115.3125&sspn=14.960401,28.564453&ie=UTF8&ll=49.000211,8.384714&spn=0.046681,0.11158&z=14&iwloc=addr


According to the McAfee IP tracer.

hmmm the first one shows a parking garage lol

the second one shows some place in germany so I guess the second one is the important one although ip addreses can be faked very easily

One thing that is funny about this is the target-community that this guy choose to try his new trojan/keylogger/virus thing on. I mean the average computer knowledge is a tad higher here than on an average forum on the Internet ...

It sounds about as smart as trying to hijack cars (GTA style) on the parking of a gun-club in the USA :-)


One thing that is funny about this is the target-community that this guy choose to try his new trojan/keylogger/virus thing on. I mean the average computer knowledge is a tad higher here than on an average forum on the Internet ...



Not really, he was probably 100% positive he could get it downloaded and ran from here... And he was proven right... Hence this thread.


Not really, he was probably 100% positive he could get it downloaded and ran from here... And he was proven right... Hence this thread.



My point was: It is also possible to successfully carjack right beside a gun club, but why do it there?

Why not go to a normal mall where the risk of repercussion is very much lower?

Hmmm, the second one only lists five or six individuals - there we go then.

The donkey was probably trying to find out if people that 'may' have found out about his password harvester (it'd be nice if it was just a key logger...) could actually detect the fact he was password stealing. S'pose he has his answer then. But like Nate says, IP adresses can be faked.

Basically, I am linking the person(s) who posted the trojan file to these other incidents:

***Warning*** - Trojan File
http://www.blitzbasic.com/Community/posts.php?topic=82341
[Please Try FPS] Partikel Engine - trojan posted here and Blitzbasic.de
http://www.blitzbasic.com/Community/posts.php?topic=82136

My Blitz account was stolen....
http://www.blitzbasic.com/Community/posts.php?topic=82337

Steam account hack attempt - we know the IPs they used - they were all the same route
http://www.blitzbasic.com/Community/posts.php?topic=82274

Spam Email from 'Mark Sibly' - We know a fake website was set up and the supsect was emailing
http://www.blitzbasic.com/Community/posts.php?topic=82007

Can anyone think of anything else that is not covered here? This is especially aimed at Blitzers in different countries that have their own forums. We are aware of the trojan being posted on Blitzbasic.de; however, any further information from German Blitzers is welcomed.

Bare in mind that it may not all be the same person(s). However, every single case has been via Germany so we have to class them as related.

I would advise anyone who received e-mails, IP addresses, or has any information on the suspect(s), to keep the information safe.

ALSO BE AWARE THAT THIS PERSON(S) CAN POSE (PRETEND) TO BE PEOPLE YOU KNOW. They have stolen email logins, ISP logins, Messenger logins, social networking logins and a lot more.

There is another issue with the blitzmax.com/blitzbasic.com site though: It does not use SSL/Encrypted Pages for login pages etc. so security is Null anyway. Anyone that is able to look at the traffic (Open-WLAN + AirSnort/ISP-level etc) is able to read our usernames/passwords as plain-text as it is today anyway.


There is another issue with the blitzmax.com/blitzbasic.com site though: It does not use SSL/Encrypted Pages



And today SSL based on MD5 cryptographic algorithm is cracked...wow, what a fantastic world!
Link to the news

(Of course you need - today - 200 Ps3, but in the near future with GPU/Stream/Cuda this will more affordable).

I like this bit
“We’re also not going to release the special code that we used to do the MD5 collisions until later this year,” Sotirov added.

Well it looks like theyv'e got 5 hours 37 minutes left (UK TIME) to fix this problem. SO START WORRYING NOW PEOPLE. 8o

Just a heads-up - Ad-Aware is now detecting the trojan in the 'spyware' catagory - 'Win.32.TrojanPWS.Mapper'. It has been given a Threat Analysis Index rating of 10 - ie maximum.

Most people have Ad-Aware (as it is free). So make sure you run an update and then scan your system.

It also cleans System Volume Information infected by the trojan on other hard-drives/partions.

Puki, if I download Adaware now will it have been updated? I haven't had any issues because I never downloaded the trojan.

Hopefully they, plus all Anti-Virus companies, can update their heuristics so any variations of this Trojan will be spotted by a virus scanner immediately.

You should always run an update before scanning. If you download Ad-Aware, then definetley run an update before scanning.

Wait a minute!

I just realised that the first system I just ran it on has a registered version of Ad-Aware Plus.

I am currently running a scan on another system with Ad-Aware Free to see if it picks up the trojan.

The Plus version has anti-virus protection and extended threat detection. So the detection might be part of the built in AV, rather than the malware scan.

I'll post back later if the Free version picks up the trojan.

Well, I have been sitting here running the scan for 5 hours and the freeware version of Ad-Aware found nothing.

It could be that on this system, the trojan cleaned up after itself as this is the one that I gave it internet access; or, it could be that the freeware version of Ad-Aware does not yet detect the trojan.

I've given up hours of sleep over several days with this trojan.

Manouvering into prosecuting the trojan poster is proving difficult, due to the multi-national scope of this. However, it seems the easy way forward is via the FBI which is via The Internet Crime Complaint Center (IC3): http://www.ic3.gov/default.aspx

I like their website and the whole complaint process seems easy and well explained.

Technically, they seem to want the complainant (or the suspect(s)) to be a US citizen. However, they do not make this initially obvious - I found it in the FAQs:
If one of the two parties involved is located within the United States, please feel free to file a complaint.


However, we can probably get around this - more than likely there will be at least one US Blitzer who has been affected. Plus, baring in mind the scope of this, I think they will be interested in pursuing the case or at least advising us of who to contact.

The point is, all the evidence is in the trojan. It is not a case of proving what the suspect(s) stole - we already know exactly what they attempted to steal from every single person that ran the file. This particular trojan doesn't just open up a back door whereby a hacker MAY come and visit and steal something - or it MAY upload something at a later date; it grabs everything it can straight away and sends it on its way.


No contact will be made yet - this all just in the planning stage. I will not soldier on until various parties have been consulted. Baring in mind that some people may just want me to forget about this whole thing and just let it go.


What do we have to lose in turning in the suspect(s)? We cannot just lie down at let someone get away with this. It is not like we are telling tales or grassing on people - we are reporting serious crime(s) that have been carried out over many weeks. Soldiering on and reporting this is the right thing to do.

I took the risk of running the trojan live to find out what it did for the benefit of the 40+ people who had already downloaded and run it and didn't know what kind of damage it had done.

Looking at the FBI and US Department of Justice press releases, they are succesfully prosecuting people that spread trojans for criminal use. Under US law they have been putting them in prison.

If someone can get people prosecuted for cyber-bullying in a chat-room, then we can win this case.

I entered "Brauerstraße 48, 76135 Karlsruhe, Germany" in Google (without maps). This came out:

http://www.google.com/search?hl=en&q=Brauerstra%C3%9Fe+48%2C+76135+Karlsruhe%2C+Germany&btnG=Google+Search&aq=f&oq=

After many pages this result came out:
http://web2.cylex.de/firma-home/web-de-ag-2167020.html

web.de provides a mail-service ("FreeMail") and some more. I think they can help you.

But not least.. the trojan must be have any SMTP-Account-Data stored. I think the trojan does not send mail per client. In this hack-size; this would be realy stupid.

@Puki, good work you are an asset to this site. I have held off reporting it to my ISP in the first instance - I believe they may be my first port of call. In the UK it seems like the 1st port of call is your local police station according to the metropolitan site thingy. Can I point out my forum name is due to the fact I designed a graph plotting application with BBasic2.1 on an Amiga1200, its not cause I'm of the BRL persuasion - although I am a big fan.

@Shadow Turtle, the extra info is very helpful. I'll wait a bit more before reporting it to my ISP - luckily I downloaded the executable on a very old laptop that has never had passwords entered for banking information. It would be useful for everyone that has been affected by this malicious software to save a copy of the text file that the software produced - this is an important piece of evidence to disuade other individuals from pursuing similar exploitations.

Maybe it is worth considering guidance to individuals regarding using VMWare to download stuff to - a bit protracted but I dunno - there is a lot of talent on these forums and I for one do not want to neglect trying stuff out for folk for want of a process that will snare the undesirables executables. The only bother I see with VMWare is that as far as I am aware emulating graphics cards is nigh on impossible without a monster CPU.

I was put off by The Metropolitan Police Service Computer Crime Unit saying you should go to your local police station. It made me worry that they would not take it seriously.

In addition:
The international nature of the Internet means that any attempt to deal with Internet-related crime will always be complicated by questions of jurisdiction. Laws vary from country to country and UK police have no power to intervene directly against criminal material on computers in another country or against criminals operating in another country.


I like the FBI route as you can do it all online.

Of course, the German suspect(s) possibly do fall under UK jurisdiction regarding the Blitz scam involving http://biltzbasic.tk/ as it was hosted through Malo Ni Advertising Limited, 16 Peel Road, Douglas, IM1 4LR.

yeah the following bit is somewhat shoulder slumpy:

and UK police have no power to intervene directly against criminal material on computers in another country or against criminals operating in another country.


What do UK people think about a proposed amendment to this policy along these lines:

and UK police have no power to intervene directly against criminal material on computers in another country or against criminals operating in another country (new stuff) unless the individuals form a country other then the UK have exploited or intended to exploit residents of the UK.

I'll suggest this to my MP, along with any other suggestions that are forthcoming.

They had better take this seriously!

Whoever made that virus has likely been following this discussion, and
if so, is probably packing their bags right now!
They are not going to stick around for someone to catch them!


Do you think contacting the German police would do anything?
Because if the FBI isn't going to help out, nor the metropolitan police,
then we need Someone who is going to take some action here!


Anyways, I must say Pukemeister, that my opinion of you really has
improved due to all the hard work your doing. I always thought of you
as the weird little guy who liked sausages. Now I think of you as
Puki, P.I (Private Investigator)

You are really doing an outstanding job with this, along with the rest
of the BlitzBasic Community ^_^

If there is anything I can do to help, just let me know. Not stuff to do
with analyzing the virus, but if you need help with research about
jurisdiction laws, etc, then I'm in 100%.

If it's international wouldn't Interpol be involved?

I was put off by The Metropolitan Police Service Computer Crime Unit saying you should go to your local police station. It made me worry that they would not take it seriously.


especially as you said you were cautioned by the plod for stabbing the ground of your local park at night due to frustrations with GTA4 ;)

..