Àâòîðñêîå ïðàâî © WWW : AV-School.com
Ïåðåïóáëèêàöèÿ ìàòåðèàëîâ,âîçìîæíà òîëüêî ñ óñòíîãî èëè ïèñüìåííîãî ðàçðåøåíèÿ Àäìèíèñòðàöèè ñàéòà !
Íàçâàíèå ñòàòüè , Published Articles » Security » Online games and fraud. Battle Trojan complex
24 December 2009 â 17:30

The number of online games is constantly growing and the amount of money of this market is growing too. It provokes criminals to improve the malicious software which is used to steal player's personal data. In this article Trojan family of Trojan-GameThief.Win32.OnLineGames will be explored. Thousands modifications of this family appear every day.


Figure 1. Detection statistics of Trojan-GameThief.Win32.OnLineGames: 2008.12.01 - 2009.08.23





Figure 2. Age groups online – players





Figure 3. Percentage of time spent on online-games a week







Figure 4. Scheme of cheating in online-games








    



    








Figure 5. Trojan complex Trojan-GameThief.Win32.OnLineGames.bkzf





Figure 6. Strings of modified file userinit.exe





Figure 7. Comparison of MD5 hashes of the original and modified file userinit.exe





Figure 8. List of terminated processes









Figure 9. Command line for the completion of service and process.



    

    
    



Figure 10. The injection of malicious code in the address space of the process svchost.exe





Figure 11. Definition of malicious flow in the process svchost.exe





Figure 12. Disassembling of the malicious thread





Figure 13. The display of service in the Registry Editor





Figure 14. Replacing of handler NtQuerySystemInformation







Figure 15. Sale of accounts to the game Eve Online (http://accountgear.com/buy/Eve-Online)





Figure 16. Google trends





Alexander Saprykin, Alexander Nepokupny
"Design and Test Lab", Ltd. 2009

/specially for /



Article from blog: Marina.
URL / WWW
http://www.av-school.com/article/a-23.html