HardwareLogic

Go Back   HardwareLogic > General Discussions > General Computing
Home Forums Rules All AlbumsBlogs Donate Subscriptions Register Mark Forums Read vBExperience

General Computing Need help with recommendations? Want to discuss general technology issues? This is the place.

Reply
 
LinkBack (1) Thread Tools
Old April 8th, 2007   1 links from elsewhere to this Post. Click to view. #1
Beer Drinking Association
Points: 2,000, Level: 26
Points: 2,000, Level: 26 Points: 2,000, Level: 26 Points: 2,000, Level: 26
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
 
Banditman's Avatar
 
Join Date: Feb 2007
Location: Longview, Texas
Posts: 200
Default New trojan found-not good for AVG users.

Russian Windows Trojan Discovered, May Point to Identity Theft Ring

By Scott M. Fulton, III, BetaNews

March 23, 2007, 4:52 PM

The Atlanta-based security services firm SecureWorks discovered, by way of an inquiry from one of its Windows customers, what appears to be a very sophisticated Trojan horse program. Under intense analysis, the program was discovered to be attempting to deliver users’ certificates and other identifying data to a variety of IP addresses found to be hosted in Russia.
The Trojan trips only a handful of anti-virus programs using heuristic analysis, an in-depth SecureWorks report states, including Sophos, Symantec, F-Prot, and CA’s VET. But it just slips by most other protection programs; and evidence trails uncovered by SecureWorks indicate that specifically-targeted users may have been infected as far back as December 2006.

Surprisingly, a few of the Trojan’s discovered delivery mechanisms are not uncommon, including hiding JavaScript code within an embedded frame of a Web page (using the IFRAME tag) that is itself embedded, and triggering an executable file to run by registering it in the Run tag of the System Registry. The downloading of the executable may take place using XMLHTTP and ActiveX Data Objects components which were found years ago to be security risks, and which Microsoft has long since superseded – even though the components themselves may be in use in many systems for compatibility purposes.An in-depth examination of the Trojan running on a VMware virtual machine using tools such as SysInternals found that it may actually be using a Registry key as a conduit for transferring data between the infected system and its IP address contact. Older Windows components were deemed security risks for having the ability to read and write values from the System Registry without any pre-authorization – or, more accurately, without any specific authorization since the components themselves were almost automatically considered authorized.
More importantly, SecureWorks discovered that the Trojan tries to log in to a California bank’s servers, initially using false data, apparently in a sequence of attempts to determine the bank’s protocols. SecureWorks believes it uses the information gleaned from these attempts to concoct a way to pass itself off as a layered service provider - a low-level network component – as a means of bypassing SSL encryption.
In the firm’s tests, SecureWorks was able to supply the Trojan with phony certificates and identifying data, not directly but through typical-style communication with real-world Web sites. It was then able to siphon through the Trojan’s communications with its home server, and detect where it had wrapped fake data such as ATM numbers, the last four digits of a Social Security Number, and access PINs within encrypted packets.
If you think this story is wild enough, it does not stop there. In his report, SecureWorks researcher Don Jackson writes about how he posed undercover online as a potential customer searching for a malware kit. Posting solicitations to certain forums with which he was familiar, Jackson uncovered sources in Russia that may be selling this Trojan and others as malware kits, for prices ranging from $500 to $2,000.
Jackson notes that governments thus far have been unable (or perhaps, more accurately, unwilling) to take action to take down the Trojan’s home server, which he says remains active at this time.
As far as what potential victims of this attack may be able to do, Jackson’s prognosis does not look promising. He believes the malware industry in Russia has become so sophisticated that it has successfully commoditized utilities that can modularize and re-package malicious code faster than today’s anti-virus industry can get a handle on its signatures.
“Malware code is so modularized,” Jackson writes, “that AV vendors often misclassify executables, making them difficult to remedy. The product has been commoditized. In all of the code analyzed by SecureWorks Research, no useful utility for encrypting new options data for the Trojan client was found. It's just not distributed. How to customize IP addresses, ports, and URLs for these types of Trojans is a secret reserved by those who manufacture them as part of a service.”
Late yesterday, the US-CERT office of the Dept. of Homeland Security acknowledged SecureWorks’ research, though it could offer no advice to users for protecting themselves and their businesses against this or similar attacks.



Athlon 64 4000+ 2.4 ghz 2 ghz HT
2 x 1GB PC3200 RAM
LG Lightscribe DVD/CD write 18x/48x read 16x/48x
Windows XP Pro SP 2 & Windows 2000 pro sp4
BFG Geforce 7800 GS OC 256mb running dual displays
Zalman CNPS9500 CPU Cooler
K8 Triton GA-K8U-939 Mobo w/ULI M1689 Chipset
Xion 600W PSU w/dual 12v rails


Last edited by Banditman; April 8th, 2007 at 03:57.
Banditman is offline   Reply With Quote
Old April 8th, 2007   #2
..
Points: 2,434, Level: 29
Points: 2,434, Level: 29 Points: 2,434, Level: 29 Points: 2,434, Level: 29
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
 
Join Date: Mar 2007
Posts: 452
Default Re: New trojan found-not good for AVG users.

I am curious why AVG users was specifically pointed out in the thread title?



Computer Ed
Core2 Duo E6600 | Gigabyte 916P-DS3 | 4 Gig Corsair XMS2 | ATI HD 2900XT
X Fi Xtreme Gamer | WD SE16 32 Gig |Liteon 20X DVDRW SATA | Bose Companion 2.0
Antec Nine Hundred | Thermaltake Toughtpower 1KW | BenQ FP202W | Vista Ultimate 64
Computer-Ed is offline   Reply With Quote
Old April 8th, 2007   #3
Beer Drinking Association
Points: 2,000, Level: 26
Points: 2,000, Level: 26 Points: 2,000, Level: 26 Points: 2,000, Level: 26
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
 
Banditman's Avatar
 
Join Date: Feb 2007
Location: Longview, Texas
Posts: 200
Default Re: New trojan found-not good for AVG users.

Because AVG is NOT one of those listed as being able to detect the trojan. And as we all know it, AVG is a commonly used anti-virus.



Athlon 64 4000+ 2.4 ghz 2 ghz HT
2 x 1GB PC3200 RAM
LG Lightscribe DVD/CD write 18x/48x read 16x/48x
Windows XP Pro SP 2 & Windows 2000 pro sp4
BFG Geforce 7800 GS OC 256mb running dual displays
Zalman CNPS9500 CPU Cooler
K8 Triton GA-K8U-939 Mobo w/ULI M1689 Chipset
Xion 600W PSU w/dual 12v rails

Banditman is offline   Reply With Quote
Old April 8th, 2007   #4
Colonel Calamity
Points: 16,047, Level: 81
Points: 16,047, Level: 81 Points: 16,047, Level: 81 Points: 16,047, Level: 81
Activity: 100%
Activity: 100% Activity: 100% Activity: 100%
 
screwballl's Avatar
 
Join Date: Oct 2006
Location: Sandy South
Posts: 5,893
Blog Entries: 6
Default Re: New trojan found-not good for AVG users.

but why was AVG mentioned? there are hundred of other AV programs out there and the paid ones are more prevalent than the free ones are (due to OEM installs) so I believe it should say Mcafee instead of AVG


someone needs to edit the title to read:

New Trojan found - not good for many AV apps







Thanks HL and Corsair!

My opinions are my own and not representative of this site or its members.


Last edited by screwballl; April 8th, 2007 at 08:29.
screwballl is offline   Reply With Quote
Reply

  HardwareLogic > General Discussions > General Computing


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

LinkBacks (?)
LinkBack to this Thread: http://forums.hardwarelogic.com/f47/new-trojan-found-not-good-avg-6353.html
Posted By For Type Date
Long Data Type at The Number 1 Long Data Type source This thread Refback April 8th, 2007 10:39

Similar Threads
Thread Thread Starter Forum Replies Last Post
any mac users here? looking for a laptop okron1k Mobile Computing 39 February 29th, 2008 13:29
Looks like AGP users still have upgrade options. fps justin Graphics 10 February 16th, 2007 18:06
I found a good use for my stock Core 2 Duo heatsink Zambini Cooling 15 December 22nd, 2006 07:48
Anti-Trojan Elite 3.7.8 News Feeder Software & OSs 0 September 17th, 2006 07:00
Trojan Remover 6.5.2 News Feeder Software & OSs 0 August 28th, 2006 07:00


All times are GMT -8. The time now is 00:33.


Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
© HardwareLogic 2005 - 2008. All Rights Reserved


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45