The following are the attack vector
- they created a site called,
coronavirusapp.site
- they have a banner encouraging people to download the malicious code for real time updates
- after a few days, they change their websites to using DoMobile - provider of legit Android Applications
Actual Image So once you have installed the
Covidlock malware, it will infect your mobile thru the following:
- check whether if the user is running on administrator if not, will request permissions
- will do a DNS lookup and HTTP communication to a ‘bit.ly’ shortened URL.
- dynamically generated ransomware note that is sent to the users lock screen.
- combined with the data from the Pastebin URL, it will generate the image below
- asking you to pay ransom of
$100 in
BTC- btc address is still empty, thanks to our researchers, but we really don't know maybe someone in the
next coming weeks will fall for this trick.
I also found some homograph attacks, so the original site may have been taken down already, but those criminals are ready with many websites waiting to be deploy again.
ćoronavirusapp.site (xn--oronavirusapp-9sb.site)
ƈoronavirusapp.site (xn--oronavirusapp-v9c.site)
ċoronavirusapp.site (xn--oronavirusapp-vub.site)
coronaviruŝapp.site (xn--coronaviruapp-ysc.site)
coronavirușapp.site (xn--coronaviruapp-5xe.site)
coronaviruṡapp.site (xn--coronaviruapp-5o1g.site)
coronavirušapp.site (xn--coronaviruapp-kuc.site)
coronavirusapṗ.site (xn--coronavirusap-8k1g.site)
coronavirusapṕ.site (xn--coronavirusap-gk1g.site)
coronavirusapƿ.site (xn--coronavirusap-8wd.site)
coronavirusapƥ.site (xn--coronavirusap-umd.site)
coronavirusaṗp.site (xn--coronavirusap-7k1g.site)
coronavirusaṕp.site (xn--coronavirusap-fk1g.site)
coronavirusaƥp.site (xn--coronavirusap-tmd.site)
coronavirusaƿp.site (xn--coronavirusap-7wd.site)
coronavirusąpp.site (xn--coronaviruspp-ssb.site)
coronavirusȧpp.site (xn--coronaviruspp-s3e.site)
coronavirusăpp.site (xn--coronaviruspp-zrb.site)
coronavirusǎpp.site (xn--coronaviruspp-62d.site)
coronavirusạpp.site (xn--coronaviruspp-sf2g.site)
coronavirusɑpp.site (xn--coronaviruspp-llf.site)
coronavirusåpp.site (xn--coronaviruspp-zfb.site)
coronavirusäpp.site (xn--coronaviruspp-lfb.site)
coronavirusãpp.site (xn--coronaviruspp-6eb.site)
coronavirusápp.site (xn--coronaviruspp-eeb.site)
coronavirusâpp.site (xn--coronaviruspp-seb.site)
coronavirusàpp.site (xn--coronaviruspp-zdb.site)
coronaviruṣapp.site (xn--coronaviruapp-yp1g.site)
coronaviruśapp.site (xn--coronaviruapp-5rc.site)
coronaviruʂapp.site (xn--coronaviruapp-54f.site)
coronavirȗsapp.site (xn--coronavirsapp-cxe.site)
coronavirụsapp.site (xn--coronavirsapp-x62g.site)
coronavirȕsapp.site (xn--coronavirsapp-jwe.site)
coronavirűsapp.site (xn--coronavirsapp-x0c.site)
coronavirůsapp.site (xn--coronavirsapp-4zc.site)
coronavirųsapp.site (xn--coronavirsapp-q1c.site)
coronavirưsapp.site (xn--coronavirsapp-4qd.site)
coronavirūsapp.site (xn--coronavirsapp-jyc.site)
coronavirŭsapp.site (xn--coronavirsapp-czc.site)
coronavirʉsapp.site (xn--coronavirsapp-x7f.site)
coronavirüsapp.site (xn--coronavirsapp-4ob.site)
coronavirũsapp.site (xn--coronavirsapp-qxc.site)
coronavirúsapp.site (xn--coronavirsapp-cob.site)
coronavirᴜsapp.site (xn--coronavirsapp-4y7f.site)
coronavirûsapp.site (xn--coronavirsapp-qob.site)
coronavirǔsapp.site (xn--coronavirsapp-j5d.site)
coronavirùsapp.site (xn--coronavirsapp-xnb.site)
coronaviṙusapp.site (xn--coronaviusapp-wl1g.site)
coronaviɾusapp.site (xn--coronaviusapp-i3f.site)
coronaviṛusapp.site (xn--coronaviusapp-pm1g.site)
coronaviṟusapp.site (xn--coronaviusapp-bo1g.site)
coronaviȓusapp.site (xn--coronaviusapp-pve.site)
coronaviȑusapp.site (xn--coronaviusapp-wue.site)
coronaviřusapp.site (xn--coronaviusapp-brc.site)
coronaviɍusapp.site (xn--coronaviusapp-wjf.site)
coronaviŗusapp.site (xn--coronaviusapp-iqc.site)
coronaviɽusapp.site (xn--coronaviusapp-32f.site)
coronaviɼusapp.site (xn--coronaviusapp-p2f.site)
coronaviŕusapp.site (xn--coronaviusapp-ppc.site)
coronaviʀusapp.site (xn--coronaviusapp-b4f.site)
coronavīrusapp.site (xn--coronavrusapp-v7b.site)
coronavȋrusapp.site (xn--coronavrusapp-hse.site)
coronavịrusapp.site (xn--coronavrusapp-hw2g.site)
coronavɨrusapp.site (xn--coronavrusapp-ouf.site)
coronavỉrusapp.site (xn--coronavrusapp-ov2g.site)
coronavĭrusapp.site (xn--coronavrusapp-o8b.site)
coronavǐrusapp.site (xn--coronavrusapp-v3d.site)
coronavɩrusapp.site (xn--coronavrusapp-2uf.site)
coronavırusapp.site (xn--coronavrusapp-99b.site)
coronavïrusapp.site (xn--coronavrusapp-vjb.site)
coronavìrusapp.site (xn--coronavrusapp-oib.site)
coronavírusapp.site (xn--coronavrusapp-2ib.site)
coronaⱴirusapp.site (xn--coronairusapp-8u2k.site)
coronaᶌirusapp.site (xn--coronairusapp-u88f.site)
coronaṿirusapp.site (xn--coronairusapp-101g.site)
coronaṽirusapp.site (xn--coronairusapp-8z1g.site)
coronaⱱirusapp.site (xn--coronairusapp-1t2k.site)
coronąvirusapp.site (xn--coronvirusapp-msb.site)
coronȧvirusapp.site (xn--coronvirusapp-m3e.site)
coronăvirusapp.site (xn--coronvirusapp-trb.site)
coronǎvirusapp.site (xn--coronvirusapp-02d.site)
coronåvirusapp.site (xn--coronvirusapp-tfb.site)
coronạvirusapp.site (xn--coronvirusapp-mf2g.site)
coronɑvirusapp.site (xn--coronvirusapp-flf.site)
coronãvirusapp.site (xn--coronvirusapp-0eb.site)
coronävirusapp.site (xn--coronvirusapp-ffb.site)
coronávirusapp.site (xn--coronvirusapp-7db.site)
coronâvirusapp.site (xn--coronvirusapp-meb.site)
coronàvirusapp.site (xn--coronvirusapp-tdb.site)
coroꞑavirusapp.site (xn--coroavirusapp-z120c.site)
coroňavirusapp.site (xn--coroavirusapp-ekc.site)
coroņavirusapp.site (xn--coroavirusapp-ljc.site)
coroñavirusapp.site (xn--coroavirusapp-lkb.site)
coroǹavirusapp.site (xn--coroavirusapp-6ke.site)
coroṉavirusapp.site (xn--coroavirusapp-ef1g.site)
coroṇavirusapp.site (xn--coroavirusapp-le1g.site)
coroṅavirusapp.site (xn--coroavirusapp-sd1g.site)
corońavirusapp.site (xn--coroavirusapp-sic.site)
corönavirusapp.site (xn--cornavirusapp-kmb.site)
corónavirusapp.site (xn--cornavirusapp-dlb.site)
corơnavirusapp.site (xn--cornavirusapp-ykd.site)
corỏnavirusapp.site (xn--cornavirusapp-yx2g.site)
corọnavirusapp.site (xn--cornavirusapp-5w2g.site)
corȯnavirusapp.site (xn--cornavirusapp-r6e.site)
coṙonavirusapp.site (xn--coonavirusapp-ql1g.site)
coṛonavirusapp.site (xn--coonavirusapp-jm1g.site)
coȑonavirusapp.site (xn--coonavirusapp-que.site)
coṟonavirusapp.site (xn--coonavirusapp-4n1g.site)
coȓonavirusapp.site (xn--coonavirusapp-jve.site)
coɍonavirusapp.site (xn--coonavirusapp-qjf.site)
coɾonavirusapp.site (xn--coonavirusapp-c3f.site)
cořonavirusapp.site (xn--coonavirusapp-4qc.site)
coŗonavirusapp.site (xn--coonavirusapp-cqc.site)
coŕonavirusapp.site (xn--coonavirusapp-jpc.site)
coɽonavirusapp.site (xn--coonavirusapp-x2f.site)
coɼonavirusapp.site (xn--coonavirusapp-j2f.site)
coʀonavirusapp.site (xn--coonavirusapp-43f.site)
cöronavirusapp.site (xn--cronavirusapp-imb.site)
córonavirusapp.site (xn--cronavirusapp-blb.site)
cơronavirusapp.site (xn--cronavirusapp-wkd.site)
cỏronavirusapp.site (xn--cronavirusapp-wx2g.site)
cọronavirusapp.site (xn--cronavirusapp-3w2g.site)
cȯronavirusapp.site (xn--cronavirusapp-p6e.site)
ĉoronavirusapp.site (xn--oronavirusapp-2tb.site)
čoronavirusapp.site (xn--oronavirusapp-ovb.site)
çoronavirusapp.site (xn--oronavirusapp-hgb.site)
For a more detailed technical analysis,
https://www.domaintools.com/resources/blog/covidlock-update-coronavirus-ransomware#Related:
New Corona Virus Crypto Ransomware