{"id":57508,"date":"2021-06-18T09:01:13","date_gmt":"2021-06-18T09:01:13","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=57508"},"modified":"2021-06-18T09:01:13","modified_gmt":"2021-06-18T09:01:13","slug":"mysterious-malware-blocks-the-pirate-bay-and-other-pirate-sites","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=57508","title":{"rendered":"Mysterious Malware Blocks The Pirate Bay and Other Pirate Sites"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/06\/stopblock.jpg\" alt=\"stop\" width=\"277\" height=\"189\" class=\"alignright size-full wp-image-176924\">For a few years now, copyright holders have warned that people who use pirate sites risk running into malware and other malicious content. <\/p>\n<p>These warnings are meant to dissuade people from using these sites. However, a new type of malware already does that in a more direct way. <\/p>\n<p>In an article published this week, British security company Sophos <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/06\/17\/vigilante-antipiracy-malware\/\">highlights<\/a> a malware campaign that actively targets pirates. Not to harm their computers, but to block them from accessing pirate sites in the future.<\/p>\n<h2>Disguised as Pirated Software<\/h2>\n<p>The malware in question is disguised as pirated software and is shared on regular torrent sites and other places. The packages look like regular \u2018cracked\u2019 releases but those who try to install the software are in for a surprise. <\/p>\n<p>Instead of installing a cracked version of the software users were looking for, the malware triggers a fake error message which mentions that a DLL file is missing. <\/p>\n<p>\u201cThe program can\u2019t start because MSVCR100.dll is missing from your computer. Try reinstalling the program to fix this problem,\u201d the error reads while executing the malware in the background.<\/p>\n<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/06\/pirate-error.png\" alt=\"pirate error\" width=\"426\" height=\"176\" class=\"alignnone size-full wp-image-205832\"><\/center><\/p>\n<p>Once executed, the malware tries to contact the 1flchier[dot]com domain, which is a typo variation of the file-sharing site 1fichier. When successful, it downloads a new payload titled \u2018ProcessHacker.jpg,\u2019 while sharing the filename of the pirated software the victim was planning to use. <\/p>\n<p>It is unclear if this data is being used for anything but at the moment, the malicious domain is no longer accepting requests. However, it appears that the malware has been in use for <a href=\"https:\/\/www.hybrid-analysis.com\/sample\/f8beb912038cbd43d151cedcd4c0e6d3ec463b64b30941da68419af868d267bb\/5fa7852067e4c9345479f18e\">several months<\/a> at least, so this may have been different in the past.<\/p>\n<h2>Blocking Hundreds of Pirate Sites<\/h2>\n<p>Where the malware really shines, is when it actively modifies the \u2018hosts\u2019 file on users\u2019 computers. This file can be used to override how domain names resolve. The attackers use it to link a few hundred to over a thousand pirate domain names to the localhost address, 127.0.0.1.<\/p>\n<p>This change effectively blocks victims from accessing the sites, which includes The Pirate Bay and many of its proxies.<\/p>\n<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/06\/piratehosts.jpg\" alt=\"\" width=\"500\" height=\"515\" class=\"alignnone size-full wp-image-205833\"><\/center><\/p>\n<p>Interestingly, this isn\u2019t the first time we\u2019ve seen malware do this. More than a decade ago a similar threat was widely shared on torrent sites. This also modified the \u2018<a href=\"https:\/\/torrentfreak.com\/trojan-blocks-the-pirate-bay-and-mininova-090104\/\">hosts file<\/a>\u2018 to block The Pirate Bay. In addition, it also triggered popups that played a sound file saying that \u201cdownloading is wrong\u201d.<\/p>\n<p>Sophos has no idea who is behind the malware and neither have we. While it could be an interesting anti-piracy strategy, it\u2019s unlikely that the malware comes from that angle. It could just as easily come from a rival pirate site that is not on the blocklist.<\/p>\n<h2>Easily Fixed<\/h2>\n<p>In any case, Sophos reports that its software blocks the threat, so its users are safe. Also, people whose computers are compromised can easily fix the problem themselves too. <\/p>\n<p>\u201cUsers who have inadvertently run one of these files can clean up their HOSTS file manually, by running a copy of Notepad elevated (as administrator), and modifying the file at c:WindowsSystem32Driversetchosts to remove all the lines that begin with \u201c127.0.0.1\u201d and reference the various ThePirateBay (and other) sites,\u201d Sophos writes.<\/p>\n<p>From: <a href=\"https:\/\/torrentfreak.com\/\">TF<\/a>, for the latest news on copyright battles, piracy and more.<\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For a few years now, copyright holders have warned that people who use pirate sites risk running into malware and other malicious content. These warnings are meant to dissuade people from using these sites. However, a new type of malware already does that in a more direct way. In an article published this week, British [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":57509,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[308],"tags":[],"class_list":["post-57508","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-torrent"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/57508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=57508"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/57508\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/57509"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=57508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=57508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=57508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}