Skip to main content

ProjectHook RAM Scrapper

ProjectHook RAM Scrapper


ProjectHook is a RAM scrapper malware that someone sent me on ICQ.
The malware cost 1k according to him, im not sure if its this guys:

MD5: a599836a7bbc68a5e712d48bb6319951
The original exe is packed with UPX and have a size of (447 Kb)
After unpacking the exe size is 1,36 Mb and the time date stamp is 5061B8CA (13:59:38 - 25 Sept 2012)
First seen in VirusTotal in December 2012:

Lets dissas it !
FastMM is a lightning fast replacement memory manager for Borland Delphi Win32 applications.

On the main procedure, at first it create a mutex MTXCTRL:
If the mutex cant be created then close the process.

It call GetModuleFileNameW to get the malware path and compare the end of the path with mmon32.exe
if this dont match we will enter in a procedure:

After it will take the string APPDATA and use the API GetEnvironmentVariableW to get the path and compute it with the string Memory Resource then he create the directory

Then take another string Memory Resourcemmon32.exe and copy our exe to %APPDATA% with the name mmon32.exe and the API CopyFileW:

Get the file attribute via GetFileAttributesW, then he retake %APPDATA% and compute it with Memory Resource tfd.dat and try to get the attribute via the same API and do an error because the file dont exist.

Then it call the C&C with an hardcore Delphi classe who can be identified by C:BuildsTPindysocketslibProtocolsIdHTTP.pas

After calling the C&C the malware create ntfd.dat in %APPDATA%/Memory Ressource/

And show a dialog box Installed successfully!


But the installation is not yet finished, it will create a registry key WinMen at SoftwareMicrosoftWindowsCurrentVersionRun
 regedit:

And edit 1806 at SoftwareMicrosoftWindowsCurrentVersionInternet Settings ones3
1806 is the key about launching applications and unsafe files in internet explorer.
The value can be zero, one, or three, typically, a setting of zero sets a specific action as permitted, a setting of one causes a prompt to appear and a setting of three prohibits the specific action.

Set a zero value:
regedit:

Then it create a Timer of 40 seconds (40000 ms):

Determine if IsWow64Process function exists in the OS were running under:

Just after it will go on this jump:

If you dont take it like normaly it do it will load the GUI:

Whats normaly he do:

Well now everything is deployed for the infection, the malware will look specific APIs:

Retrieves information about the first process encountered in a system snapshot:

Open process:

Dont take the jump to verify for x64
Ive not checked why but its surely a flag earlier when he have checked if the system was x64.
Ive passed on process till he go on something i also want to be scanned (look EDX at 0x5208E5)
Ive took magstrip.exe a custom exe file who receive my credit card swipe


At first it take the exe path and check the process name like he have do earlier but this time to be sure he dont scan hes own process:
If he scan he detect his own process it will take a conditional jump later avoiding others procedures and do directly a CloseHandle.
So after this verification do, he will retrieves information about a range of pages within the virtual address space of  my magstrip.exe process:

And a classic ReadProcessMemory:

Once done the indentification start:

And will look for the first part of a track2, if found, he will verify the luhn algorithm and if correct he will not take the jump at 0x520C14:

When a correct track2 is finaly identified he will check the second part of a track2 (service code):

You can refer to the ISO/IEC 7813 on Wikipedia about credit card magnetic tracks.

Ok cool, but what is a service code for ?
You can get the answer just by browsing carding forums.
101 service code are USA and is without chip
201 can be Europe, Canada... and have pin and chip

And about the luhn algorithm you can get valid test numbers via paypal. (http://www.paypalobjects.com/en_US/vhelp/paypalmanager_help/credit_card_numbers.htm)
For example, if you want to trigg ProjectHook you can try these track2:
MasterCard: 5431111111111111=13071010000000000666
Visa: 4111111111111111=13071010000000000666
on my physical blank card, this is what i use to trigger these malwares.

Now that he think the credit card is good, the program will check if the C&C dns is equal to LOCALHOST:
Anti analysis maybe.

Retreive some specific APIs of Ws2_32 like he did it earlier for scan running processes:

The track2 is sent to the C&C:
After ive not checked whats he do but he will probably search others track2 in the memory and do that in loop for each process.

For the panel, its very weak:
And about the huge size of this malware, its due to a lot of useless features in the HTTP classe and hash classe, for example the ntlm calls of 0x405FBD, 0x4B4D33, 0x5201CF, still dont get it why its here.

Also not related but these stupid carding shops become more and more boring.
Some sweet stats:





download file now

Popular posts from this blog

Ragnos1997 Low Specs Patches for low PC Download

Ragnos1997 Low Specs Patches for low PC Download Ragnos1997 Low Specs Patches for Low PC Full Download "Let your system breathe, and enjoy even the latest games on your low end hardware. Only with Low Specs Experience�" Which games are affected ? ALAN WAKE ALAN WAKE�S AMERICAN NIGHTMARE ALIEN: ISOLATION ALIEN: COLONIAL MARINES 7 DAYS TO DIE AMERICAN TRUCK SIMULATOR ANNO 2205 ARMA III ASSASSIN�S CREED ASSASSIN�S CREED II ASSASSIN�S CREED BROTHERHOOD ASSASSIN�S CREED REVELATIONS ASSASSIN�S CREED III ASSASSIN�S CREED III LIBERATION HD ASSASSIN�S CREED IV BLACK FLAG ASSASSIN�S CREED UNITY ASSASSIN�S CREED ROGUE ASSASSIN�S CREED SYNDICATE BATMAN ARKHAM ORIGINS BATMAN ARKHAM ORIGINS BATTLEFIELD BAD COMPANY 2 BATTLEFIELD 3 BATTLEFIELD 4 BATTLEFIELD HARDLINE BATTLEFIELD 1 BIOSHOCK INFINITE BORDERLANDS BORDERLANDS 2 BORDERLANDS THE PRE-SEQUEL CALL OF DUTY BLACK OPS CALL OF DUTY BLACK OPS II CALL OF DUTY BLACK OPS III CALL OF DUTY GHOSTS CALL OF DUTY ADVANCED WARFARE CALL OF DUTY INFIN...

TDATS fourth birthday festive greetings to you all!

TDATS fourth birthday festive greetings to you all! No music here....just a thanks to all the people who have been following this blog, four years down the line and I am still finding new ideas and receiving helpful pointers from readers who are often more informed than me....so thanks to you all. Please reply here or email me with any tips and ideas for the blog....you can also join in and contribute to TDATS news in the fb group.....I have some new ideas in the works....the next post in a few days, in time to be a Christmas present to you all, will be a revealing interview and story regarding a great band that I dont think has been spotlighted anywhere as yet.....and I have more plans to do that kind of thing next year....there are plenty more themes in the works....any advice that readers would like to offer on South-East Asia, East-European and latin american bands would be gladly followed up and if you can think of any other themes that will go down well here let me know! Happy ho...

Ramayana Soul Sabdatanmantra � �地獄 Scattered Purgatory God of Silver Grass

Ramayana Soul Sabdatanmantra � �地獄 Scattered Purgatory God of Silver Grass Reviewed by Nathan Ford There are few who read this rag who would doubt that we place Kikagaku Moyo at the very pinnacle of the current Japanese psychedelic scene. That being the case, its not unusual at all to discover that Guruguru Brain, the label run by Kikagaku Moyos Tomoyuki Katsurada is a veritable treasure trove of adventurous psychedelia, inhabited by names known to few in the Western world. Their first release was a wonderful and essential sampler of modern Japanese psychedelia which can still be downloaded for free here, but its two more recent releases that we concern ourselves with today. Ramayana Soul is first on the turntable, and while the band are actually Indonesian, its obvious why Katsuradas interest was peaked. "Sabdatanmantra" is a joyous wonder that perfectly illustrates the singular way in which Eastern psychedelia embraces free form spontaneity without sacrificing a tune, or in...