{"id":1317,"date":"2017-10-13T15:38:51","date_gmt":"2017-10-13T15:38:51","guid":{"rendered":"https:\/\/blog.gridinsoft.com\/?p=1317"},"modified":"2021-12-06T08:08:56","modified_gmt":"2021-12-06T08:08:56","slug":"new-times-new-threats-adware-amonetize-investigation","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/new-times-new-threats-adware-amonetize-investigation\/","title":{"rendered":"New Times, New Threats: Adware.Amonetize investigation"},"content":{"rendered":"<p align=\"justify\"><em>Lately, our Team faced with complaints about Adware.amonetize virus. It hits most of the countries of Europe, the biggest quantity of infections is in China, Azerbaijan, Iran, Italy, Turkey, Saudi Arabia and Indonesia. It doesn&#8217;t matter Internet Explorer, Firefox, Google Chrome, Safari or other browsers do you use: you will see ads anyway. We investigated this virus and found that it spreads via a method we call bundling. It means that adware.amonetize sneaks into your system alongside with free software.<\/em><\/p>\n<h2>How adware.amonetize works?<\/h2>\n<p align=\"justify\">So what are main symptoms of this adware? Ads, ads and once more ads. You will see disturbing pop-ups, annoying banners, redirects in your browser. It is not a secret that every virus was created to gain profit, adware.amonetize is one of them. It gets pay-per-click revenue, so that is why you see so many ads. Every click and redirects on the sponsored website are coins in the money box. What is more interesting, we&#8217;ve noticed that adware.amonetize collects personal information of its victims! Browsing history, emails, messengers, name, locations and even banking credentials can fall into the hands of hackers.<\/p>\n<h2>Where it is installed?<\/h2>\n<p>Our Analysts Team found out that Adware.Amonetize stored in %programfiles%, in a folder with a random name that contains 10 characters of the English alphabet + digits.<br \/>\nExamples:<br \/>\n<em>% programfiles% \\ 04gcs4ypv6 \\ 04gcs4ypv.exe (check on<a href=\"https:\/\/www.virustotal.com\/en\/file\/337b42fedd413703f5911a982ac253fa5ab08d42b75061c1ac87b3dac3143628\/analysis\/\" rel=\"nofollow noopener\" target=\"_blank\"> Virus Total<\/a>)<br \/>\n% programfiles% \\ 0gp81q2mg5 \\ d5wn9p9nf.exe (check on<a href=\"https:\/\/www.virustotal.com\/en\/file\/d396ef334f7becc08ca44d4dde02d282929d9a24bcd2f216dd04b8e46fb12341\/analysis\/\" rel=\"nofollow noopener\" target=\"_blank\"> Virus Total<\/a>)<br \/>\n% programfiles% \\ 39rossub2g \\ 39rossub2.exe (check on<a href=\"https:\/\/www.virustotal.com\/en\/file\/d396ef334f7becc08ca44d4dde02d282929d9a24bcd2f216dd04b8e46fb12341\/analysis\/\" rel=\"nofollow noopener\" target=\"_blank\"> Virus Total<\/a>)<\/em><\/p>\n<figure id=\"attachment_1329\" aria-describedby=\"caption-attachment-1329\" style=\"width: 963px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-1329 size-full\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/chart-1.jpg\" alt=\"Where it is installed?\" width=\"963\" height=\"522\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/chart-1.jpg 963w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/chart-1-300x163.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/chart-1-768x416.jpg 768w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><figcaption id=\"caption-attachment-1329\" class=\"wp-caption-text\">Where it is installed?<\/figcaption><\/figure>\n<p>These files are without a signature and add themselves to the startup list with random names:<\/p>\n<p><em>&#8220;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\<strong>UPCABJZUFTF7J48<\/strong>&#8221; &gt;&gt; &#8220;&#8221;%programfiles%\\04gcs4ypv6\\04gcs4ypv.exe&#8221;&#8221;<\/em><\/p>\n<p><em>&#8220;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\<strong>9A00GNV8DAW655S<\/strong>&#8221; &gt;&gt; &#8220;&#8221;%programfiles%\\39rossub2g\\39rossub2.exe&#8221;&#8221;<\/em><\/p>\n<p><em>&#8220;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\<strong>ZXFX5IAHM64HROQ<\/strong>&#8221; &gt;&gt; &#8220;&#8221;%programfiles%\\e0in79xcut\\e0in79xcu.exe&#8221;&#8221;<\/em><\/p>\n<p align=\"justify\">Adware.amonetize is a very tricky, as you may already notice. To hide files on the disc it use software from Nir Sofer &#8211; NirCmd (check on <a href=\"https:\/\/www.virustotal.com\/en\/file\/31b3b228382dc359f22ae97b2602eee81dc743fb21196061eacc6619533881f5\/analysis\/\" rel=\"nofollow noopener\" target=\"_blank\">Virus Total<\/a>).<\/p>\n<p align=\"justify\">Exe file under the name chipset.exe is in the folder with a random name from the letters + numbers in %appdata%, %localappdata%, %commonappdata% or %temp% and is written in the titles with the name GoogleUpdateSecurityTaskMachine_XX and Optimize Start Menu Cache Files-S-XX (XX stands for any uppercase character).<\/p>\n<p>For example:<br \/>\n<em>Task: &#8220;%system%\\Tasks\\<strong>GoogleUpdateSecurityTaskMachine_NL<\/strong>&#8221; &gt;&gt; &#8220;%localappdata%\\Temp\\02e22efae9e744b3a1fa6dae595a32e1\\chipset.exe exec hide GBCWKWPKVU.cmd &#8221; <\/em><\/p>\n<p><em>Task: &#8220;%system%\\Tasks\\<strong>GoogleUpdateSecurityTaskMachine_OO<\/strong>&#8221; &gt;&gt; &#8220;%commonappdata%\\5cd66b2d442541229cdaf3947384919f\\chipset.exe exec hide EIUHMIJWVC.cmd &#8220;<\/em><\/p>\n<p><em>Task: &#8220;%system%\\Tasks\\<strong>Optimize Start Menu Cache Files-S-GZ<\/strong>&#8221; &gt;&gt; &#8220;%appdata%\\92dcc1e5f2854a97b66db725d3492ecf\\chipset.exe exec hide IDGSTZEJUB.cmd &#8220;<\/em><\/p>\n<h2>Why is adware.amonetize dangerous?<\/h2>\n<p align=\"justify\">As we already said, it collects your personal information. This reason should be enough to delete adware.amonetize ASAP. Also, it attracts other viruses to your pitiful system: malware, trojans, adware etc.<\/p>\n<h2>Get Adware.Amonetize closer<\/h2>\n<p align=\"justify\">This is what 255335e18ca3b54c7872f31603de52d527da69c93b485c5aa1e70f2052192ac5.exe (Sx3qqqq.exe) looks like.<\/p>\n<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/1.png\" alt=\"\" width=\"1517\" height=\"855\" class=\"aligncenter size-full wp-image-1338\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/1.png 1517w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/1-300x169.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/1-1024x577.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/1-768x433.png 768w\" sizes=\"auto, (max-width: 1517px) 100vw, 1517px\" \/><\/p>\n<p>Loads the specified manifest resource from this assembly.<br \/>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/2.png\" alt=\"\" width=\"279\" height=\"64\" class=\"aligncenter size-full wp-image-1339\" title=\"\"><br \/>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3.png\" alt=\"\" width=\"1603\" height=\"752\" class=\"aligncenter size-full wp-image-1340\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3.png 1603w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3-300x141.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3-1024x480.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3-768x360.png 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/3-1536x721.png 1536w\" sizes=\"auto, (max-width: 1603px) 100vw, 1603px\" \/><\/p>\n<p>Take a look at this command more detailed.<br \/>\n<em>Assembly assembly = Assembly.Load(Convert.FromBase64String(Encoding.Default.GetString(new TripleDESCryptoServiceProvider(). CreateDecryptor(Convert.FromBase64String(gr8AA.vferv58rv85rvrvrvergv),<br \/>\n                    Convert.FromBase64String(gr8AA.scsce8f7er)).TransformFinalBlock(inputBuffer, 0, inputBuffer.Length))));<\/em><\/p>\n<p>To make understanding more easy lets disassemble in parts.<br \/>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/4.png\" alt=\"\" width=\"630\" height=\"141\" class=\"aligncenter size-full wp-image-1341\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/4.png 630w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/4-300x67.png 300w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><br \/>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/5.png\" alt=\"\" width=\"1324\" height=\"96\" class=\"aligncenter size-full wp-image-1342\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/5.png 1324w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/5-300x22.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/5-1024x74.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/5-768x56.png 768w\" sizes=\"auto, (max-width: 1324px) 100vw, 1324px\" \/><br \/>\nstring st = Encoding.Default.GetString(new TripleDESCryptoServiceProvider().CreateDecryptor(KEY, IV).TransformFinalBlock(inputBuffer, 0, inputBuffer.Length));<\/p>\n<p align=\"justify\">It creates a symmetric TripleDES decryption object with the <em>specified key (Key)<\/em> and the <em>initialization vector (IV)<\/em>. With the help of <em>TransformFinalBlock <\/em> it converts the previously read block of data from the manifest. At the end, it converts everything into a string. The result is an executable file.<\/p>\n<h2>How adware.amonetize slipped into your system?<\/h2>\n<p align=\"justify\">As we already said the most popular way of spreading it is installing alongside with free software. We recommend to be careful and read Terms of Agreement before clicking on &#8220;Next&#8221; button in a hurry.<\/p>\n[contact-form][contact-field label=&#8221;Name&#8221; type=&#8221;name&#8221; required=&#8221;true&#8221; \/][contact-field label=&#8221;Email&#8221; type=&#8221;email&#8221; required=&#8221;true&#8221; \/][contact-field label=&#8221;Website&#8221; type=&#8221;url&#8221; \/][contact-field label=&#8221;Message&#8221; type=&#8221;textarea&#8221; \/][\/contact-form]\n","protected":false},"excerpt":{"rendered":"<p>Lately, our Team faced with complaints about Adware.amonetize virus. It hits most of the countries of Europe, the biggest quantity of infections is in China, Azerbaijan, Iran, Italy, Turkey, Saudi Arabia and Indonesia. It doesn&#8217;t matter Internet Explorer, Firefox, Google Chrome, Safari or other browsers do you use: you will see ads anyway. We investigated [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1332,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[17],"tags":[32,21],"class_list":{"0":"post-1317","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-labs","8":"tag-adware","9":"tag-virus"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2017\/10\/Picture12-1.png","author_info":{"display_name":"Vladislav Baglay","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/baglay\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/1317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=1317"}],"version-history":[{"count":1,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/1317\/revisions"}],"predecessor-version":[{"id":6566,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/1317\/revisions\/6566"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/1332"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=1317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=1317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=1317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}