Author Topic: nice story - Sneaky rat - hackers mine using your pc  (Read 456 times)

Offline paradis_pal

  • Comodo Family Member
  • ***
  • Posts: 66
nice story - Sneaky rat - hackers mine using your pc
« on: January 30, 2019, 05:08:37 AM »
This is a nice story, Comodo you are up to it:


A service under the name "Windows Cache Services", in the description it says: "Helps the computer run more efficiently by optimizing Cache services.". C:\Windows\INF\usbhub\0031\wcservices.exe

The files are in the hidden folder C:\Windows\INF\usbhub\0031

the first file is: C:\Windows\INF\usbhub\0031\wcservices.exe virustotoal https://www.virustotal.com/#/file/4b244fcb0dfca1d11ff622de2d881c24973370cdbddef84bbf104b3b7d91e342/detection

the second file is C:\Windows\INF\usbhub\0031\boot\config.exe virustotal https://www.virustotal.com/#/file/19690177b920096181a0ff8f9579842f7b645a15988814b145e96befbdd9c665/detection

Will use the "Background Intelligent Transfer Service" to download this zip https://www.virustotal.com/#/file/2086fac888295b69e15d6f24b0a759c887851be8a46b4826ebe8140891acc1a4/detection file with the extension tmp and random names (3 times)  to the location C:\Windows\servicing and then rename it to CbsMsg1.zip and then extract it to the same location C:\Windows\servicing.

The zip file contains lots of viruses that use your PC to mine cions for hackers

it will run OneDrive.exe https://www.virustotal.com/#/file/a8492dd306235eed796f2c78fe2eb40ea0f9799b98aafb2dc84607188c5f6c2d/detection and MsMpEngs.exe https://www.virustotal.com/#/file/5e6d5304f4a51f2902380ab12dfef555f9488551fa10e9a14bac1754df6e6d4c/detection


The main problem is that Antivirus does not scan the hidden location C:\Windows\INF\usbhub\0031

And Comodo please add these files
https://www.virustotal.com/#/file/4b244fcb0dfca1d11ff622de2d881c24973370cdbddef84bbf104b3b7d91e342/detection
https://www.virustotal.com/#/file/19690177b920096181a0ff8f9579842f7b645a15988814b145e96befbdd9c665/detection
https://www.virustotal.com/#/file/4b244fcb0dfca1d11ff622de2d881c24973370cdbddef84bbf104b3b7d91e342/detection
https://www.virustotal.com/#/file/f8f4ee418b70c5a8477ecacb56734c68caddbb12c6e663cceda58643e7444003/detection
« Last Edit: January 30, 2019, 10:38:55 AM by paradis_pal »

Offline abinaya

  • Comodo Staff
  • Newbie
  • *****
  • Posts: 24
Re: nice story - Sneaky rat - hackers mine using your pc
« Reply #1 on: January 30, 2019, 08:47:32 AM »
Hi paradis_pal,

Thank you for your submission.
We'll investigate and add detection for the malware.

Best regards
Abinaya R

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek