« The unluckiest of days | Main | Changing of the Guard »

The attack of Lucky5.exe

It's been ages! Perhaps a more chatty post will follow, but I want to get this information out there as quickly and as cleanly as possible.

In December, the server that hosts Sentry Outpost was attacked by a virus that we now know to be Lucky5.exe. The attack irreparably damaged all of the files that we had hosted there while leaving directories and files on unused ports.

In mid-April, our forum saw a dramatic increase in registered users who claimed to have discovered the website not because of the network security focus but because a psychic in Florida had sent them a distributed puzzle via snail mail that contained the url to this website. Additionally, the packages that they received pointed them to Craigslist where the psychic appears to post her "dreams." It was through these "dreams" that we discovered the passwords to the directories left by the virus. It is still a matter of debate as to her intent and knowledge regarding the virus and Sentry Outpost.

Until just a few weeks ago, we were still in the dark about what happened to the website and how it was attacked. While searching for the virus that may have been responsible for the attack, the owner of ronomi.comdiscovered the Lucky5.exe malware. The program contains pieces of text that are similar to the text discovered in the hidden directories of our two websites as well as at least one other known infected server.That text seems to be an Arabic prayer to Yog Sothoth. Our research on this malware is still ongoing, but at this time it appears to be quite dangerous despite its extremely low viral potential.

The malware makes repeated attempts to contact various IPs selected through an algorithm that takes pieces from an Arabic prayer to Yog Sothoth. Upon a successful connection, information will be exchanged which will change the algorithm and initiate an attack on a web server similar to what occurred at Sentry Outpost in December. The purpose of this communication is not yet known.

It's notable that this malware is packaged with an installer and it will force you to agree to a rather long, convoluted, and poorly translated EULA. This EULA not only includes text about user responsibility and implications that this program will interact with your computer and the internet, but also health warnings that include symptoms such as headaches, blurred vision, light sensitivity, abnormal changes to moods and behavior, hallucinations, lucid dreaming, anxiety, and an increase in suicidal thoughts.

While the program does not seem to harm your computer, when considering the recent suicide of Kevin Cosby (aka GetMeOut) and institutionalization of Bryce Doher (aka TheMagician) as well as the bizarre dreams of "B.A. St. Feline", it is our recommendation that, if you find Lucky5.exe on your computer, you uninstall it immediately. Please note that while it seems that Lucky5.exe is a Windows malware, the compromised servers that we know of have all been UNIX variants.

If you have any information or would like to become involved in the research, please join us on the forums. We would love to hear from you!

TrackBack

TrackBack URL for this entry:
http://www.sentryoutpost.com/MT/sentry_mt-tb.pl/14