Script Engines Being Used to Distribute New Strain of Spora Ransomware

in #ransomware7 years ago (edited)

We’ve recently been covering scripting attacks in more detail on the Malware Research blog. These types of attacks have the ability to be completely fileless, as explained in a previous post. However, scripts also sometimes do come in files or accompany file-based malware. The new strain of Spora malware does just this. It uses a file called “pdf.wsf” (seen here and at the time of this writing, no other antivirus software is listed as blocking the file since it’s a script), which will appear as simply “pdf” if the user has the enabled-by-default option of “hide extensions for known file types” on. As demonstrated in another previous blog post, the icon of the file can be easily spoofed to look like a legitimate pdf file. If the victim double-clicks this file, Windows Script Host (wscript.exe) will execute code which will download the rest of the ransomware and attempt to run the executable file either right away or at some future time.

Malware authors primarily use this method of malware distribution in order to evade detection. For example, if a user receives an email with an attachment as a .wsf or .js file, the file will clear most antivirus systems on both their own machine as well as email autoscan systems, as being good since it is not an “executable” .exe file. In this way, the malware author can try to get the executable payload onto the user’s system without them knowing by using the script. The good news is that PC Matic SuperShield will prevent this ransomware from running, just as it has in the past, due to the hooking technology that is used in the product as well as by blocking the malicious script engine commands. As always, don’t open unknown files, use SuperShield, and if you are concerned about file extensions, be sure to turn them on by following these instructions.
https://techtalk.pcpitstop.com/2017/07/12/avoid-deceptive-malware-tricks/

Sort:  

This is the way of the future. No longer will someone go into the bank with a gun demanding money. They will simply have your laptop, television, cell phone, home security system, etc. and demand a ransom.
Thanks for posting this. I'll be weary of those pdf

you're welcome.

Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
http://techtalk.pcpitstop.com/2017/08/07/script-engines-used-distribute-new-strain-spora-ransomware/

Congratulations @cyberwatch666! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the number of upvotes received

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!