![]() |
TG Soft researchers recognized a new variant of Trojan.Win32.FakeGdF (ransomware), that pretends to be the italian intelligence agency "Agenzia informazioni e sicurezza interna" (AISI) and uses a rootkit module to hide and to be executed at the PC startup. Agenzia informazioni e sicurezza interna (AISI) is an italian intelligence service that was called SISDE (Servizio per le Informazioni e la Sicurezza Democratica) before 2007. |
![]() |
![]() |
![]() |
f7490712 8bff mov edi,edi
f7490714 e9b2b44192 jmp 898abbcbf7490719 088b48288339 or [ebx+0x39832848],cl f749071f 00ff add bh,bh f7490721 750c jnz f749072f f7490723 50 push eax |
f748c852 8bff mov edi,edi f748c854 e972f34192 jmp 898abbcb f748c859 8b450c mov eax,[ebp+0xc] f748c85c 53 push ebx f748c85d 56 push esi f748c85e 57 push edi |
898abbcb 55 push ebp 898abbcc 8bec mov ebp,esp 898abbce 51 push ecx 898abbcf b818c28c89 mov eax,0x898cc218 898abbd4 8945fc mov [ebp-0x4],eax 898abbd7 ff750c push dword ptr [ebp+0xc] 898abbda 8b45fc mov eax,[ebp-0x4] 898abbdd ff7508 push dword ptr [ebp+0x8] 898abbe0 8b4008 mov eax,[eax+0x8] 898abbe3 ff501c call dword ptr [eax+0x1c] |
f7a6e438 e9b4a4d291 jmp 897988f1 f7a6e43d 6828e4a6f7 push 0xf7a6e428 f7a6e442 8d45f8 lea eax,[ebp-0x8] f7a6e445 50 push eax f7a6e446 ff1504e3a6f7 call dword ptr [f7a6e304] f7a6e44c 8d45f8 lea eax,[ebp-0x8] |
892dc806 55 push ebp 892dc807 8bec mov ebp,esp 892dc809 51 push ecx 892dc80a b8d0f84689 mov eax,0x8946f8d0 892dc80f 8945fc mov [ebp-0x4],eax 892dc812 8b45fc mov eax,[ebp-0x4] 892dc815 8b4020 mov eax,[eax+0x20] 892dc818 83b86402000000 cmp dword ptr [eax+0x264],0x0 892dc81f 7414 jz 063ec87d 892dc821 8b4510 mov eax,[ebp+0x10] |