조회 수 102 추천 수 0 댓글 0

from: https://blogs.technet.microsoft.com/mmpc/2017/03/15/ransomware-operators-are-hiding-malware-deeper-in-installer-packages/?platform=hootsuite

 

Ransomware operators are hiding malware deeper in installer packages

avatar of msft-mmpcmsft-mmpcMarch 15, 2017

 

We are seeing a wave of new NSIS installers used in ransomware campaigns. These new installers pack significant updates, indicating a collective move by attackers to once again dodge AV detection by changing the way they package malicious code. These changes are observed in installers that drop ransomware like CerberLocky, and others.

Cybercriminals have been known to hide malware in Nullsoft Scriptable Install System (NSIS) installer files. As antivirus software effectively detect these installer files, cybercriminals are once again updating their tools to penetrate computers.

The new malicious NSIS installers visibly attempt to look as normal as possible by incorporating non-malicious components that usually appear in legitimate installers:

  • More non-malicious plugins, in addition to the installation engine system.dll
  • A .bmp file that serves as a background image for the installer interface, to mimic legitimate ones
  • A non-malicious uninstaller component uninst.exe

The most significant change, however, is the absence of the usual randomly named DLL file, which was previously used to decrypt the encrypted malware. This change significantly reduces the footprint of malicious code in the NSIS installer package.

TAG •

List of Articles
번호 분류 제목 글쓴이 날짜 조회 수
공지 설 연휴 고객지원 휴무일을 안내드립니다. file gratolab 2022.01.28 134
공지 추석 연휴 고객지원 휴무 안내(9/20~22) gratolab 2021.09.17 119
공지 일반 [공지] 그라토 유료화에 대한 공지 1 gratolab 2017.10.02 5581
공지 일반 그라토 프리미엄 인증 순서 file gratolab 2017.08.01 12674
239 일반 What makes you move? 현대자동차 하반기 채용공고 file 맥도널드 2016.08.30 295
238 일반 Want to know what's new in iOS 10? gratolab 2016.06.17 152
237 일반 VR porn to be offered as room service in Las Vegas (http://www.engadget.com/) 썬영 2016.05.03 995
236 일반 Unpatched Western Digital Bugs Leave NAS Boxes Open to Attack gratolab 2017.03.09 216
235 일반 Top Five Best Programming Languages For Beginners To Start With 유림 2017.03.10 224
234 일반 Top 6 Programming Languages for Game Designing 유림 2017.03.14 358
233 일반 Top 10 Best Hacking Movies To Watch 썬영 2017.03.02 48
232 일반 SSD 교체로 새윈도우 설치 사용대수 초과 2 까치대장 2018.01.15 210
231 일반 Someone Hacked Video Board in Mexico and Played porn 4 Hours!! file 유림 2017.03.13 493
230 일반 SNS 외국인의 팩트폭행 file 유림 2017.05.12 77
229 일반 Server software poses soft target for ransomware gratolab 2016.04.11 231
228 Q&A santivirus 항목이 계속 검출되고 치료는 되지 않습니다. 1 또다른나 2021.12.14 43
227 redirect 바이러스 제어판사진자료 올림 (수정) 1 리키이시 2015.10.26 1296
226 Q&A REDIRECT 라는 광고성사이트가 자꾸 뜹니다.. 1 탯뇽 2017.05.28 137
225 Q&A redirect 광고해결.. 2 Gpple 2017.03.26 373
224 Q&A redirect 광고창 안없어져요 ㅠㅠ 1 아름언니 2017.09.28 346
223 Q&A redirect 광고 1 oreo 2017.11.19 152
» 일반 Ransomware operators are hiding malware deeper in installer packages 썬영 2017.03.17 102
221 일반 Pre-installed Backdoor On 700 Million Android Phones Sending Users' Data To China gratolab 2016.11.17 180
220 Q&A plus network 삭제할려면... 1 file 소나기2017 2017.01.26 397
Board Pagination Prev 1 ... 50 51 52 53 54 55 56 57 58 59 ... 66 Next
/ 66