Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Browsers and Ransoms

Fred Gutierrez
July 24th, 2009
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Emerging Threats, Malicious Code, Malicious Code, Online Fraud, Online Fraud, Security, Security Response
Facebook Twitter

We have already written about threats that can encrypt files or lock victims out of their computers in order to extract a ransom. Today I want to talk about yet another similar threat. It uses scare or nuisance tactics—similar to rogue antivirus programs—in an attempt to demand ransom from its victims.

Once infected with Trojan.Ransompage, a victim’s browser will display a persistent inline ad on every page that the victim visits. The ad will cover part of the original Web page, as shown below.

imagebrowser image

The ad will stay on the screen even if the page is scrolled:

imagebrowser image

This ad is written in Russian and states that in order to remove the ad (and to gain access a porn site) the victim must send a premium rate text message to the number provided, and the user will receive a code to remove the ad.

imagebrowser image

Rough translation:

“If you installed an advertising module has been, but you have chosen to unsubscribe, you send the MC to short number specified below. Code allows you to remove the received news ticker.
1 Informer removed automatically after 30 days.
2 Free porn video archives.
3 Technical support service.

To remove the informer, send SMS message with text [5-digit number] to number [4-digit number].
Enter the code, received in response, MC“

Obviously this is very annoying ad and the victim may just decide to use a different browser. The malware author thought of this too (see below) and actually targets the following three browsers:

Internet Explorer
Firefox
Opera

imagebrowser image

So switching to another targeted browser will not necessarily solve the problem. (Actually the code that the attacker uses is not compatible with the latest version of Firefox, so there is one easy escape at the moment.)

imagebrowser image

Similar to Trojan.Ransomlock and Trojan.Ransomcrypt, this Trojan attempts to make money by utilizing a premium rate telephone number. The premise is that the victim will become so frustrated or embarrassed by the ad that they will succumb to the pressure and send the SMS text message. This threat is also interesting from a technical point of view, so I will follow up with more details in another posting.

+3 (3 votes)
  • Fred Gutierrez's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com