Hello all,
I've been monitoring the releases made lately, especially the one made by MohcenMaher [[Only registered and activated users can see links. Click Here To Register...]] closely.
I've made an analysis of it on a "disposable" server, and the results are ugly. Very ugly.
[Only registered and activated users can see links. Click Here To Register...]
As you can see from the video, the CaptainHerlockServer.exe file is a trojan horse, for two files (1. A clean captainherlockserver.exe, 2. a file that is downloaded from the internet via a VB Script, from a file on a website on a file /captainhook.txt)
Once the said CaptainHook.exe is downloaded, it is executed and it doesn't need a rocket scientist to determine what it does then.
For anyone asking for other proofs, I'll leave links to virustotal scans made by Mohcen prior to him settling on the released on, they all connect to the same domain name and to a dynamic DNS (supposedly for the RAT connection?).
You can check the communicating files from this scan, in addition to its registry information, and determine who's involved :)
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
It is very sad how low people with talent and good skills can go, that goes to say that you should always speculate whenever download things from the internet.
Finally, I'd advise anyone who downloaded it to delete the files immediately, and clean their temp directory, in addition to performing a system-wide scan to remove any potential persistent files.
- Musta.
I've been monitoring the releases made lately, especially the one made by MohcenMaher [[Only registered and activated users can see links. Click Here To Register...]] closely.
I've made an analysis of it on a "disposable" server, and the results are ugly. Very ugly.
[Only registered and activated users can see links. Click Here To Register...]
As you can see from the video, the CaptainHerlockServer.exe file is a trojan horse, for two files (1. A clean captainherlockserver.exe, 2. a file that is downloaded from the internet via a VB Script, from a file on a website on a file /captainhook.txt)
Once the said CaptainHook.exe is downloaded, it is executed and it doesn't need a rocket scientist to determine what it does then.
For anyone asking for other proofs, I'll leave links to virustotal scans made by Mohcen prior to him settling on the released on, they all connect to the same domain name and to a dynamic DNS (supposedly for the RAT connection?).
You can check the communicating files from this scan, in addition to its registry information, and determine who's involved :)
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
It is very sad how low people with talent and good skills can go, that goes to say that you should always speculate whenever download things from the internet.
Finally, I'd advise anyone who downloaded it to delete the files immediately, and clean their temp directory, in addition to performing a system-wide scan to remove any potential persistent files.
- Musta.