{"id":7107,"date":"2017-03-24T08:11:31","date_gmt":"2017-03-24T16:11:31","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/24\/news-898\/"},"modified":"2017-03-24T08:11:31","modified_gmt":"2017-03-24T16:11:31","slug":"news-898","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/03\/24\/news-898\/","title":{"rendered":"Advanis tech support screenlocker"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 24 Mar 2017 15:00:05 +0000<\/strong><\/p>\n<p>Recently we noticed a change on one of the domains that we monitor\u00a0because they are known to host files related to tech support scams and involved in browlocks, fake alerts, and screenlockers.<\/p>\n<h3><strong>The domain and the screenlocker<\/strong><\/h3>\n<p>At the moment the installer is being pushed by InstallCapital which is a pay-per-install network .<\/p>\n<p>The domain hosting the installer is called installreports[dot]com and this time\u00a0we found it was hosting a tech support screenlocker we dubbed Advanis after the folder it creates in the Windows directory and the entry it creates in the list of installed programs and features.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16941\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/warning4.png\" alt=\"\" width=\"750\" height=\"155\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/warning4.png 750w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/warning4-300x62.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/warning4-600x124.png 600w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p>MT is the name of the main executable. The one that shows the screenlocker. Here it is probably short for \u201cMarket Tools\u201d, which is the name of the Windows form.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16942\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/warning1-1.png\" alt=\"\" width=\"160\" height=\"27\" \/><\/p>\n<h3><strong>Resolution<\/strong><\/h3>\n<p><a href=\"https:\/\/twitter.com\/TheWack0lian\" target=\"_blank\">@TheWack0lian<\/a> found this code snippet \u2013<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16939\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/backspacecode.png\" alt=\"\" width=\"389\" height=\"126\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/backspacecode.png 389w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/backspacecode-300x97.png 300w\" sizes=\"auto, (max-width: 389px) 100vw, 389px\" \/><\/p>\n<p>&#8211;telling us that the screenlocker could be minimized by using the \u201cBackspace\u201d key. Once you have done that, removal is no problem. A full <a href=\"https:\/\/forums.malwarebytes.com\/topic\/197744-removal-instructions-for-advanis\/\" target=\"_blank\">removal guide for Advanis<\/a> can be found on our forums.<\/p>\n<h3><strong>File details<\/strong><\/h3>\n<p>SHA 256 of the installer 30a32cb629d2a576288b4536d241b6e90f0540c3275288bfd4982233e12d182f<\/p>\n<p>Malwarebytes web protection module blocks the domain and detects the installer as Trojan.TechSupportScam.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16938\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/protection1-1.png\" alt=\"\" width=\"422\" height=\"264\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/protection1-1.png 422w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/protection1-1-300x188.png 300w\" sizes=\"auto, (max-width: 422px) 100vw, 422px\" \/><\/p>\n<p>The advertised number on the lockscreen\u00a0leads back to the domain getfixpc[dot]net.<\/p>\n<h3><strong>Attribution<\/strong><\/h3>\n<p>Finding out who is behind a threat is not always easy, but we think we have a solid case for this one.<\/p>\n<p>Meet Baskar K.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16948\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/baskark.png\" alt=\"\" width=\"947\" height=\"391\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/baskark.png 947w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/baskark-300x124.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/baskark-600x248.png 600w\" sizes=\"auto, (max-width: 947px) 100vw, 947px\" \/><\/p>\n<p>He registered the domain installreports[dot]com with the email address:\u00a0<a href=\"mailto:brgs@outlook.in\" target=\"_blank\">brgs@outlook.in<\/a>.<\/p>\n<p>Using his own name and providing his phone number and physical address.<\/p>\n<p>The same personal data was used to register brmediahub.com<\/p>\n<p>That domain is listed as the homepage at the stackoverflow profile I posted a screenshot of.<\/p>\n<p>For the same physical address we also found an email address <a href=\"mailto:baskark****@outlook.com\" target=\"_blank\">baskark****@outlook.com<\/a> that has been used to register a host of dubious domains:<\/p>\n<ul>\n<li>latestnewsalert.us<\/li>\n<li>pruet.us<\/li>\n<li>homemaderecipes.us<\/li>\n<li>biou.us<\/li>\n<li>mijay.us<\/li>\n<li>unlimitedgames.us<\/li>\n<li>topchickenrecipes.us<\/li>\n<li>searchweathernow.us<\/li>\n<li>newsnowonweb.us<\/li>\n<li>healtyrecipesbyjones.us<\/li>\n<li>localnewsdaily.us<\/li>\n<li>topnewsnow.us<\/li>\n<li>mathgamesfree.us<\/li>\n<li>loginprotector.us<\/li>\n<li>todaynewsup.us<\/li>\n<li>topnewsguide.us<\/li>\n<li>womenshoppingstore.us<\/li>\n<li>onlineloginaccounts.us<\/li>\n<li>onlineloginaccount.us<\/li>\n<li>downloadsnow.us<\/li>\n<li>brglobalservices.com<\/li>\n<\/ul>\n<p>Those are all blocked now by <a href=\"https:\/\/www.malwarebytes.com\/premium\/\" target=\"_blank\">Malwarebytes Web Protection Module<\/a>.<\/p>\n<p>Safe surfing!<\/p>\n<p>Thanks to <a href=\"https:\/\/twitter.com\/TheWack0lian\" target=\"_blank\">TheWack0lian<\/a> and <a href=\"https:\/\/blog.malwarebytes.com\/author\/wtsing\/\" target=\"_blank\">William Tsing<\/a> for their additional research.<\/p>\n<p>&nbsp;<\/p>\n<p><em>Pieter Arntz<\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/advanis-tech-support-screenlocker\/\">Advanis tech support screenlocker<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/advanis-tech-support-screenlocker\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 24 Mar 2017 15:00:05 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/advanis-tech-support-screenlocker\/' title='Advanis tech support screenlocker'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/main-1.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We briefly show you the workings of a tech support scammers lockscreen and introduce you to the person behind the scenes.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/malware\/\" rel=\"category tag\">Malware<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/advanis\/\" rel=\"tag\">advanis<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/brgs\/\" rel=\"tag\">brgs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/installreports-com\/\" rel=\"tag\">installreports.com<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/screenlocker\/\" rel=\"tag\">screenlocker<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tech-support\/\" rel=\"tag\">tech support<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tech-support-scam\/\" rel=\"tag\">tech support scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tss\/\" rel=\"tag\">TSS<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/advanis-tech-support-screenlocker\/' title='Advanis tech support screenlocker'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/advanis-tech-support-screenlocker\/\">Advanis tech support screenlocker<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11731,11732,4503,11733,3764,11734,10536,10544,10545],"class_list":["post-7107","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-advanis","tag-brgs","tag-cybercrime","tag-installreports-com","tag-malware","tag-screenlocker","tag-tech-support","tag-tech-support-scam","tag-tss"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7107"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7107\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}