Urausy improving its localization - A (the\?) Gaelic Ransomware with Interpol impersonation as default landing

From Botnets.fr
Jump to navigation Jump to search

(Publication) Google search: [1]

Urausy improving its localization - A (the\?) Gaelic Ransomware with Interpol impersonation as default landing
Botnet Urausy
Malware
Botnet/malware group
Exploit kits
Services
Feature
Distribution vector
Target
Origin
Campaign
Operation/Working group
Vulnerability
CCProtocol
Date 2012 / 2012-09-15
Editor/Conference Blogspot
Link http://malware.dontneedcoffee.com/2012/09/UrausyGaelicInterpol.html (Archive copy)
Author Kafeine
Type

Abstract

Urausy first appear at the end of July. It was just another Reveton "Me too" with a yellow square filled with a # instead of the "Camera" and targetting few countries : DE, ES, FR, UK, US (PT? see at the end)

Based on what i was able to see of the distribution, I had the feeling at that time, that it was a Reveton distributor trying to run his own business.

Bibtex

 @misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR1225,
   editor = {Blogspot},
   author = {Kafeine},
   title = {Urausy improving its localization - A (the\?) Gaelic Ransomware with Interpol impersonation as default landing},
   date = {15},
   month = Sep,
   year = {2012},
   howpublished = {\url{http://malware.dontneedcoffee.com/2012/09/UrausyGaelicInterpol.html}},
 }