| View previous topic :: View next topic |
| Author |
Message |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
Posted: Fri Jun 22, 2007 3:28 am Post subject: Onlinegames keyloggers and fake Software for Worldofwarcraft |
|
|
Well for starters, these guys just never stop.
I have been tracking them for almost two months now.
I'm doing my best to make their criminal life harder though.
There are three malware authors/groups that I have been following.
Well, I assume these groups are separate. I distinguish them by their
methods and websites.
The first one is:
| Code: |
http://wor1dofwarcraft.com/ = 64.20.35.98
|
Originally, their malware and exploit code was only at the above address,
and they counted on people mistyping worldofwarcraft.com or clicking
a link but not noticing the difference.
Now their exploit and malware code is linked from the above website to here:
| Code: |
http://www.mabios.com/flash.js
http://www.mabios.com/1.exe = 70.85.244.82
http://www.gameones.net = 70.85.244.82
http://www.gameones.net/1.exe
http://www.gameones.net/mos.exe
|
Since I have been tracking them, I have seen three different versions of
their malware, the most recent of which is here:
/t192936-MD5_051576122df8cf77c335a02158f74a82_1_exe.html
/t192946-MD5_339cde39f79140894b8858e05b9a28cf_servett_exe.html
Whenever I see a new version, I get that sent out via our listserv.
Emails and Takedown notices to the Chinese domain host have had no
success, however the actual servers are located in the US.
I will be trying to get them taken down again. _________________ Analyzing, reporting and removing Malware. Fight the Scourge!
Last edited by tacktick on Fri Jun 22, 2007 6:34 am, edited 1 time in total |
|
| Back to top |
|
 |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
Posted: Fri Jun 22, 2007 3:50 am Post subject: |
|
|
The second one is:
| Code: | http://world0fwarcraft.net = 222.187.105.196
|
Their malware and exploits are hosted:
| Code: |
http://world0fwarcraft.net/world.htm
http://world0fwarcraft.net/1.htm
http://world0fwarcraft.net/ani.css
http://world0fwarcraft.net/yahoo.asp
http://world0fwarcraft.net/123.js
http://world0fwarcraft.net/admin.asp
http://world0fwarcraft.net/test.exe
|
Recently these urls have popped up on wow forum spam.
All of them redirect to the main website above.
| Code: |
http://qwe1.cn/sex.htm (Dead)
http://sex.doganddoctor.com/world.htm = 222.187.105.196
http://bc0.cn/sex.jpg = 222.187.105.196
http://bc0.cn/world.htm
|
In the time I have been watching them I have seen 4 versions of their malware. Their website code and exploits havent changed though.
Most recent malware:
/t192937-MD5_dba938da217e84374b4328240ddf9af5_test_exe.html
Both the domain and network hosts are in china for these sites.
I have sent emails but got no action or reply whatsoever.
Whois info:
http://centralops.net/co/DomainDossier.aspx?addr=world0fwarcraft.net&dom_whois=true&dom_dns=true&net_whois=true&x=21&y=11
Maybe they are a criminals haven or they are paid off. Any ideas on pursuing this further are appreciated. _________________ Analyzing, reporting and removing Malware. Fight the Scourge!
|
|
| Back to top |
|
 |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
Posted: Mon Jul 16, 2007 1:04 pm Post subject: Thankyou for the information |
|
|
Hi, I'll be honest curiosty got the better of me here, and I clicked on the link via WoW forums,
bc0.cn/sex.jpg (DO NOT GO HERE PLS) linked for your information
I have installed only AVG (latest def) and spybot SnD 1.4 (latest def) windows vista home premium
AVG poped up telling me I had.
A) Trojan Horse Downloader
B) Exploit
They could not be heald or removed to vault, so I choose to delete the files,
I then unplugged my pc from my router and done a scan with Windows defender avg and spybot, wich all showed up clean, removed all temp files withen internet options, I reconnected to the internet and changed my warcraft password with an Onscreen Keybord to avoid been keylogged,
Allthough the 3 programs say my pc is clean am I still at risk here of having my warcraft account hacked?
What other steps can i take to ensure Im not at risk anymore, other than changing my Warcraft password.
any help will be much apreciated, as Im a new user on these forums I intend on sticking close by , alot of good information here, Thanks
|
|
| Back to top |
|
 |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
Posted: Mon Jul 16, 2007 8:41 pm Post subject: |
|
|
They are still at it omg
http://forums.worldofwarcraft.com/thread.html;jsessionid=082EF20C93DDCE5AB3E74C3C10BC752C?topicId=330915364&sid=1
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
Posted: Tue Jul 17, 2007 3:07 am Post subject: |
|
|
Thankyou very much Tacktick, using both those free antivirus websites my pc shows up clean, I have used avg for many years now and once again it proved itself usefull My World of warcraft account hasnt been touched,
|
|
| Back to top |
|
 |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
Posted: Tue Jul 17, 2007 5:11 am Post subject: |
|
|
Glad to know everything is fine.  _________________ Analyzing, reporting and removing Malware. Fight the Scourge!
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
Posted: Tue Jul 17, 2007 10:30 am Post subject: |
|
|
Some information may help you if ur not onto it yet, these keylogger scamers are smart. and there is quite a number of well geard players who seem to be falling into there trap
I mean how sneeky is this one, Using an already hacked account they post on all Wow realm forums
Guide to movie making and basic effects using
And they gointo quite some detail about making wow movies
linking (DO NOT GOTO ANY OF THE SITES LISTED BELLOW) they may contain Malware
hxxp: // okgame8.com/downloads/movies/movieview.zip
hxxp: // koti.mbnet.fi/daemo/Vegas/ss.JPG
hxxp: // wowvault.ign.com/View.php?vie...s.Detail&id=40
best of luck if they are infected may help you track them down, Well I hope so anyway.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
Posted: Tue Jul 17, 2007 11:18 pm Post subject: |
|
|
| Code: |
http://okgame8.com/downloads/movies/movieview.zip - Very new malware. I'll add it to the malware listserv
http://koti.mbnet.fi/daemo/Vegas/ss.JPG - Clean
http://wowvault.ign.com/View.php?vie...s.Detail&id=40 - URL isn't valid
|
_________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
Posted: Thu Jul 19, 2007 12:28 pm Post subject: |
|
|
Recently posted on wow forums more from .CN
Is this old or new Malware,
:: DO NOT GOTO THIS LINK CONTAINS MALWARE ::
hxxp: // bc0.cn/watch?v=vRbDhLcGFR8
NB: Only trying to help u guys in the hunt for whoever is behind this.
I herd from a trusted friend in game, that russian sites Sell these keylogging programs , however he would not go further into details about these sites when I confronted him, was gonna let u guys know. (if I found out about such a site)
|
|
| Back to top |
|
 |
Kivi07
Cadet

 Joined: Jul 16, 2007 Posts: 6 Location: Austrailia
|
|
| Back to top |
|
 |
tacktick
MIRT Hunter Premium Member
 Joined: May 19, 2007 Posts: 624 Location: USA
|
Posted: Fri Jul 20, 2007 11:02 pm Post subject: |
|
|
First one is a rss news listing.
Second one links to a russian game mod site, but I didnt see anything malicious. _________________ Analyzing, reporting and removing Malware. Fight the Scourge!
|
|
| Back to top |
|
 |
Centuron
Guest IP: 62.31.*.*
|
Posted: Fri Jul 27, 2007 12:10 am Post subject: |
|
|
I support this 100%!
It's not fair at all on unsuspecting users to have their account stolen by this idiots and no doubt the whole WoW community will support your efforts to track em' down and make life difficult - Keep up the effort!
|
|
| Back to top |
|
 |
Tadrith
Guest IP: 130.85.*.*
|
Posted: Sat Aug 04, 2007 3:45 pm Post subject: |
|
|
More links popped up in the Rogue forums today posing as screenshots from an epic alliance Halaa raid.
Whether this will contain a new version or not, I don't know.
DO NOT CLICK THESE they likely contain malware.
| Code: |
http://world0fwarcraft.net/my.php?image=wowscrnshot015505zh5.jpg
http://world0fwarcraft.net/my.php?image=wowscrnshot014736pm9.jpg
http://world0fwarcraft.net/my.php?image=wowscrnshot014751fb6.jpg
http://world0fwarcraft.net/my.php?image=wowscrnshot062407014649iz8.jpg
|
Links disabled by moderator
|
|
| Back to top |
|
 |
|
|