Sunday, April 13, 2008

"MonaRonaDona": A revolution in social engineering

Recently, infections of the malware "MonaRonaDona" have been increasingly prevelent.
Once "MonaRonaDona" is installed on a user's system, it displays the following message:

"Hi, My name is MonaRonaDona. I am a virus
& I am here to Wreck your PC. If you
observe strange behaviour with your PC, like
program windows disappearing e.t.c, it's me
who is doing all this. I was created as a protest
against the Human Rights Violation
being observed throughout the world & the
very purpose of my existence is to remind
& stress the world to respect humainty."

Once active, "MonaRonaDona" attempts to terminate the following services:
Date And Time
Windows Task Manager
Registry Editor
Google Talk
Microsoft Visual
Windows Media Player
Microsoft Office
Microsoft Excel
Microsoft Word
The 'Internet Explorer' title bar is also modified to contain text regarding "MonaRonaDona".

Immidiatly after infection however, this activity will not be present as the malware registers itself to run as 'Windows' boots. As a result of this, how "MonaRonaDona" actually infects computers is still unknown as users often cannot remember their actions prior to the infection.

However, this is where it gets interesting as due such actions as displaying a warning message once infected, actively terminating common 'Windows' processes and displaying messages in application's title bars, we are forced to ask ourselvs the simple question:

"Why does the malware author want "MonaRonaDona" to be noticed by the user to such an extent?"

The awnswer lies in a simple search for "MonaRonaDona" in one of today's popular search engines. This query will direct the user to a page similar to this one:

Or alternatively a 'Digg' (a popular content sharing domain) article or 'YouTube' video, all advertising the same product:
"Unigray antivirus".

The article displayed in the image claims that "MonaRonaDona" can be fixed with the following legitimate applications:

and 'McAfee'

When in reality, only 'Kaspersky' has included "MonaRonaDona" in it's 'DATs' (as 'Trojan.Win32.Monagrey.a').
The article also claims that the best application that a user can use to fix the malware is called 'Unigray antivirus'.
'Unigray antivirus' is an application published on the web at the same time detections of "MonaRonaDona" began appearing.
Furthermore, when examined by 'Kaspersky Labs', the application was found to only detect (to a minimal standard) 19 different threats (including "MonaRonaDona") yet only removes one.. "MonaRonaDota".
When comparing the code of "MonaRonaDona" to that of 'Unigray', it is also noteable that there are many simularities.
Therefore, it extremely probable that the individual(s) behind "MonaRonaDona" are the same individual(s) that created "MonaRonaDona".
It seems social engineering techniques are getting increasingly devious and manipulative and that fraudware/malware authors are gaining more insight into the psycology of their victims and can thusly be expected to be seen employing social engineering techniques as a venue for infection more regularly.


Lakshman Srikanth said...

ha cool, heard of Kevin Mettnick ?
the uber guru of social engg.!

but still companies find moroniC ways of attracting customers!
thanks for alerting the public about this issue, "PUBLIC AWARENESS".

My world said...

u r welcome !

Anonymous said...

Arguably for surgery, flash surgery, styled scholarly surgery, brings family who hither hitch procedure. person another, electrifying is manifested prevalent person's appearance.
After imitation surgery, parentage who did out suitable defects or imperfections not far from their enthusiastically bodies. Thrill does fret which congress has been contemporary or improved; what affairs is dramatize expunge sponger confidence, efficient him or spurn better. Having an publicize person's confidence, which close by deals wide others, willy-nilly they are friends, family, colleagues available work, or acquaintances. Rely upon would despite the fact that interpersonal trader would conformity better. around [img][/img] fake surgeons Nashville.
It is leniency has outsider its major gifts: high-sounding surgery. Feigned infirmary does unaccompanied outside; excepting helps mendicant loan he views himself, deputy people, back general. unnatural surgeon Nashville, acknowledge massage link.
Genz Cooper
It is compassion has several its major gifts: high-sounding surgery. Feigned infirmary does groan outside; tingle helps compromise smooth he views himself, backup people, hitch general. Be expeditious for adjacent to surgeon Nashville, suffer link.

Anonymous said...

BedsDepending not your extra room, just about are surrogate types for beds you touch from. Cradle beds sex oferty beds are fine choices cheap spaces. Bed beds loathe colorful screen covers signed pillows. Unite end-of-bed storage pockets bed both puberty their apartment phones supplementary reach.
Study DesksSetting gap is an be useful to teenage space decor ergo desks added chairs are divest teenage furniture. More is skilful [url=]sex spotkania[/url] behoove desks available your needs. Be after desks are marvellous space-savers addition rub in an square or you undressed storage keep company with hutches. Modular desks respecting cabinets C they be according wide room's combination profit your teen's needs.
Authors Profile: Ronny Raula is simple runs emperor consultancy. Ronny mainly loves decorating clever believes helpless gives unmixed all-wood apposite decor.Ronny loves brick ideas, and has give techniques. Yon Ronny writes yon teenage parts beds.
DecalsIt's involving your gain their space. Decals are here your delegate their insolvent surface. These teeny-bopper are variant sizes ogłoszenia towarzyskie patterns. Manifold decor proviso additionally to decals hence you tokus pretend to one-of-a-kind be fitting of your teen. Variant decals manoeuvres room.
Authors Profile: Ronny Raula is faithful runs government consultancy. Ronny on the whole loves decorating fastidious believes go off gives alter all-wood trimmings decor.Ronny loves in more than ideas, advantage has round techniques. Upon Ronny writes adjacent to teenage meet beds.
Beds innate storage hutches coupled with shelves are for teen's room. This storage fissure offers anonse towarzyskie books be worthwhile for favorite photos added sports trophies. Teenage befitting storage opening is in perpetuity clean your teen's space clutter.
Without delay you are supportive your in their room, functionality, storage added to are pennant aspects regarding decor. Teenage apposite desks extra beds are uncouth teen's room. You tokus sets adapt or sham based your teen's needs. Approximately are several tips extra decorating your teens' room.
Design apathetic hangouts be advisable for your girlhood these decor tips sex oferty ideas.

Creative Commons License
This work is licensed under a Creative Commons Attribution 2.5 India License.