Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By muckracker1 (Reporter)
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

Professionals Suspect ISIS On A Hacking Spree pictures

% of readers think this story is Fact. Add your two cents.


Professionals Suspect ISIS On A Hacking Spree

January 5th, 2015 | by Anon.Dos
Politics
4
 
 

ISIS is not willing to just sit there and listen to all of the negative things people are saying about them. They’ve taken it to the extent that their computer programmers have created malware that is allegedly able to detect insulting, anti-ISIS material posted in forums, websites, blogs and various other web channels.

Researchers from Citizen Lab in Toronto, Canada were the first to detect the malware whose sole purpose is to find those groups or people who oppose ISIS and its laws.  The malware was purportedly first targeted at only one anti-ISIS group, Ar-Raqqah, and now Raqqah is being slaughtered silently for their speaking out.

This malware is usually sent via an email, Citizen Lab tells us. The sender of the email claims to be from a Canada-based group that will help support the fight against ISIS. Once the reader is convinced and chooses to join the group, they simply need to click on a link in the email and it redirects them to TempSend servers which then automatically initiates the download of a file called “slideshow.zip”.

 

The downloaded “slideshow.zip” file (MD5: b72e6678e79cc57d33e684528b5721bd) contains “slideshow.exe” (MD5: f8bfb82aa92ea6a8e4e0b378781b3859) which is the software itself. The file is a self-extracting executable with an icon to fool the victim into believing that it is a slideshow.

 

When clicked on, the file opens a slideshow of Google Earth and shows the location of ISIS Headquarters, amongst other images, including images of the US airstrikes that have been recently carried out.

 

 

However, when you look at the details of what the zip and executable files are actually doing when opened, we can see that they write and execute several other files – below are the details:

 

C:Users[Username]AppDataLocalTempIXP000.TMPAdobeR1.exe
C:Users[Username]AppDataLocalTempIXP000.TMPpictures.exe

 

AdobeR1.exe is a malicious file, while pictures.exe is a real presentation. The funny thing is when the slideshow is closed both the “AdobeR1.exe” and “pictures.exe” files delete themselves.

AdobeR1 writes a series of executable files that are programmed to collect information from within the following locations:

C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpAdbrRader.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpAdobeIns.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpGoogleUpate.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpGooglUpd.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpnvidrv.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpnvisdvr.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmprundl132.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpsvhosts.exe
C:Users[Username]MicrosoftWindowsZ0xapp8T.tmpnvidrv.exe

 

Once they are saved, the nvidrv.exe adds itself to the Windows ‘autorun’ command located at: HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun under name “UpdAdbreader” – creating a series of registry keys about programs that communicate:

 

DefaultKeyboardUserF124-5KK83-F2IV9-FDN293JIPC7-K2ODP-OFnD3-FJCC3J1K6F-DKV8J-FKVJI-GVKBU6nvisdvr.exe:

DefaultKeyboardUserF124-5KK83-F2IV9-FDN293JIPC7-K2ODP-OFnD3-FJCC3J1K4F-DKV8J-FKVJI-GVKBU4GoogleUpate.exe:

DefaultKeyboardUserF124-5KK83-F2IV9-FDN293JIPC7-K2ODP-OFnD3-FJCC3J1K3F-DKV8J-FKVJI-GVKBU3AdbrRader.exe:

DefaultKeyboardUserF124-5KK83-F2IV9-FDN293JIPC7-K2ODP-OFnD3-FJCC3J1K2F-DKV8J-FKVJI-GVKBU2nvidrv.exe:

DefaultKeyboardUserF124-5KK83-F2IV9-FDN293JIPC7-K2ODP-OFnD3-FJCC3J1K1F-DKV8J-FKVJI-GVKBU1

 

 

 

 

 

 

 

Categories

 

 

 

 

 

ANONYMOUS

RECOMMENDS:

 

 



Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.


LION'S MANE PRODUCT


Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules


Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.



Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.


Report abuse

    Comments

    Your Comments
    Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

    MOST RECENT
    Load more ...

    SignUp

    Login

    Newsletter

    Email this story
    Email this story

    If you really want to ban this commenter, please write down the reason:

    If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.