Saturday, March 21, 2009
[Lockergnome] Computer Security ~ March 21, 2009
TrendLabs | Malware Blog - by Trend Micro - 3 new articles
"TrendLabs | Malware Blog - by Trend Micro" - 3 new articles
WALEDAC Spamming MadnessAside from spamming our mailboxes with dire news of bombings in our local cities, WALEDAC is also very busy filling our mailboxes with more unwanted emails. This time, peddling various pills, meds, and male enhancements. Here’s a gallery of pharma vendors advertised in Waledac spam mails. Figure 1. Canadian Pharmacy, a known long time advertiser in spam.
All of the shown spam messages above are already blocked by the Trend Micro Smart Protection Network. Other users are advised to delete any similar spam messages that may happen to land in their inbox. Here are previous reports related to WALEDAC:
Post from: TrendLabs | Malware Blog - by Trend Micro Ichitaro Exploits ProgressOn March 11, Regional TrendLabs in Japan found a zero-day exploit attack that targeted Just System's well-known Japanese word-processor, Ichitaro. The malware exploting the vulnerability was noticed to arrive via spam and via malicious websites using the Ichitaro file extension name, .JTD. The malware ( TROJ_TARODROP.BA) drops a file {random letters}.tmp ( TROJ_DROPPER.PAO) that in turn drops another file named beer80.exe ( TROJ_AGENT.KLQW). Notable of this scheme is that after TROJ_TARODROP.BA and TROJ_DROPPER.PAO have executed their routines, the last dropped Trojan (TROJ_DROPPER.PAO) creates non-malicious files using them to overwrite itself and the initial TROJ_TARODROP.BA. Thus, when the user checks the files after the infection is completed, all the user will see are legitimate Ichitaro files (this is considered to be a stealth technique applied by the malware). Unknown to the user at that point is that the final payload TROJ_AGENT.KLQW is already and still in the system. This Trojan (TROJ_AGENT.KLQW) gathers the following information from the affected system then sends the data to a remote site:
Figure 1. the sleight of hand is performed by the second malware in line, TROJ_DROPPER.PAO. According to Trend Micro researchers, the initial attack on Ichitaro happened in August 2006. Since then, every time a new Ichitaro vulnerability is found, cybercriminals are expected to attempt to exploit it–and they do so with increasing social engineering savvy. Past attacks followed the same straightforward drill: the first malware exploits the vulnerability and the second one conducts the main routines such as autostart and dropping files, etc. It is only recently (in 2008) we have begun to see the additional overwriting trick meant to fool users. Previous Ichitaro-related attacks include the following: New Ichitaro zero-day exploit discovered Information on this vulnerability, as well as the patch provided by Just System, can be found on their website. Read the Japanese writeup of this attack from the Japanese Malware Blog. Post from: TrendLabs | Malware Blog - by Trend Micro Complex Malcode Behind ILOMO ReinfectionLast week, Trend Micro was alerted to the increasing number of ILOMO infections. ILOMO Trojans (some examples are TROJ_ILOMOB.,TROJ_ILOMO.F, and TROJ_ILOMO.L) arrive on systems via Web-based exploits and use different infection routines for the payload. Notable with these variants is that even when users have deleted the malicious file from the hard disk, its code remains actively injected in system memory. In effect, users are continuously annoyed of the reinfection symptoms. Analysis of TROJ_ILOMO’s spaghetti-like code reveal several things. Once running in an infected system, a variant updates its own Gates-List which is probably part of the infected nodes that forms its peer-to-peer botnet. This model is quite similar to the one used by the Storm botnet. The malware saves this list in the registry. Figure 1. Registry list. Entries on the list have the format {IP address}/{certain strings} and they are considered to be a list of compromised machines. With an updated Gates-List, the ILOMO malware then attempts to access the sites and download binary encrypted data. It stores the values in the local registry in values named M00, M01, and M02. The ILOMO Trojan decrypts then the data, which in fact forms an malicious executable code that is later injected to certain Internet Explorer processes. Figure 2. Injected code. Once found, it injects the downloaded and now decrypted code and executes this remote thread. This said thread enables ILOMO to perform additional malicious activities on the infected system. TROJ_ILOMO variants have also been found to send and receive information from certain IP addresses, thereby compromising system security. Confidential or private information may find its way to cybercriminals in this attack too. Trend Micro Smart Protection Network already detects and blocks TROJ_ILOMO and its adjacent droppers, preventing them from executing in systems. Post from: TrendLabs | Malware Blog - by Trend Micro Complex Malcode Behind ILOMO Reinfection More Recent Articles |
Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings
Unsubscribe from all current and future newsletters powered by FeedBlitz
| Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498 |
Subscribe to:
Posts (Atom)
Blog Archive
-
►
2012
(71)
- 02/12 - 02/19 (8)
- 02/05 - 02/12 (11)
- 01/29 - 02/05 (10)
- 01/22 - 01/29 (12)
- 01/15 - 01/22 (9)
- 01/08 - 01/15 (12)
- 01/01 - 01/08 (9)
-
►
2011
(706)
- 12/25 - 01/01 (3)
- 12/18 - 12/25 (12)
- 12/11 - 12/18 (14)
- 12/04 - 12/11 (10)
- 11/27 - 12/04 (10)
- 11/20 - 11/27 (3)
- 11/13 - 11/20 (10)
- 11/06 - 11/13 (15)
- 10/30 - 11/06 (10)
- 10/23 - 10/30 (11)
- 10/16 - 10/23 (11)
- 10/09 - 10/16 (8)
- 10/02 - 10/09 (14)
- 09/25 - 10/02 (7)
- 09/18 - 09/25 (14)
- 09/11 - 09/18 (11)
- 09/04 - 09/11 (10)
- 08/28 - 09/04 (11)
- 08/21 - 08/28 (11)
- 08/14 - 08/21 (9)
- 08/07 - 08/14 (12)
- 07/31 - 08/07 (14)
- 07/24 - 07/31 (9)
- 07/17 - 07/24 (11)
- 07/10 - 07/17 (13)
- 07/03 - 07/10 (10)
- 06/26 - 07/03 (9)
- 06/19 - 06/26 (12)
- 06/12 - 06/19 (13)
- 06/05 - 06/12 (18)
- 05/29 - 06/05 (10)
- 05/22 - 05/29 (14)
- 05/15 - 05/22 (11)
- 05/08 - 05/15 (12)
- 05/01 - 05/08 (10)
- 04/24 - 05/01 (13)
- 04/17 - 04/24 (17)
- 04/10 - 04/17 (25)
- 04/03 - 04/10 (18)
- 03/27 - 04/03 (18)
- 03/20 - 03/27 (21)
- 03/13 - 03/20 (21)
- 03/06 - 03/13 (23)
- 02/27 - 03/06 (20)
- 02/20 - 02/27 (15)
- 02/13 - 02/20 (15)
- 02/06 - 02/13 (25)
- 01/30 - 02/06 (23)
- 01/23 - 01/30 (19)
- 01/16 - 01/23 (15)
- 01/09 - 01/16 (18)
- 01/02 - 01/09 (18)
-
►
2010
(1039)
- 12/26 - 01/02 (10)
- 12/19 - 12/26 (16)
- 12/12 - 12/19 (19)
- 12/05 - 12/12 (18)
- 11/28 - 12/05 (23)
- 11/21 - 11/28 (13)
- 11/14 - 11/21 (20)
- 11/07 - 11/14 (19)
- 10/31 - 11/07 (22)
- 10/24 - 10/31 (22)
- 10/17 - 10/24 (20)
- 10/10 - 10/17 (16)
- 10/03 - 10/10 (14)
- 09/26 - 10/03 (13)
- 09/19 - 09/26 (15)
- 09/12 - 09/19 (24)
- 09/05 - 09/12 (20)
- 08/29 - 09/05 (20)
- 08/22 - 08/29 (22)
- 08/15 - 08/22 (16)
- 08/08 - 08/15 (24)
- 08/01 - 08/08 (21)
- 07/25 - 08/01 (20)
- 07/18 - 07/25 (21)
- 07/11 - 07/18 (19)
- 07/04 - 07/11 (18)
- 06/27 - 07/04 (17)
- 06/20 - 06/27 (17)
- 06/13 - 06/20 (19)
- 06/06 - 06/13 (26)
- 05/30 - 06/06 (17)
- 05/23 - 05/30 (18)
- 05/16 - 05/23 (16)
- 05/09 - 05/16 (24)
- 05/02 - 05/09 (18)
- 04/25 - 05/02 (21)
- 04/18 - 04/25 (21)
- 04/11 - 04/18 (27)
- 04/04 - 04/11 (19)
- 03/28 - 04/04 (24)
- 03/21 - 03/28 (23)
- 03/14 - 03/21 (17)
- 03/07 - 03/14 (28)
- 02/28 - 03/07 (26)
- 02/21 - 02/28 (18)
- 02/14 - 02/21 (18)
- 02/07 - 02/14 (30)
- 01/31 - 02/07 (24)
- 01/24 - 01/31 (19)
- 01/17 - 01/24 (20)
- 01/10 - 01/17 (28)
- 01/03 - 01/10 (19)
-
▼
2009
(1033)
- 12/27 - 01/03 (10)
- 12/20 - 12/27 (18)
- 12/13 - 12/20 (20)
- 12/06 - 12/13 (24)
- 11/29 - 12/06 (19)
- 11/22 - 11/29 (15)
- 11/15 - 11/22 (19)
- 11/08 - 11/15 (23)
- 11/01 - 11/08 (23)
- 10/25 - 11/01 (22)
- 10/18 - 10/25 (20)
- 10/11 - 10/18 (23)
- 10/04 - 10/11 (21)
- 09/27 - 10/04 (23)
- 09/20 - 09/27 (21)
- 09/13 - 09/20 (18)
- 09/06 - 09/13 (23)
- 08/30 - 09/06 (18)
- 08/23 - 08/30 (21)
- 08/16 - 08/23 (23)
- 08/09 - 08/16 (20)
- 08/02 - 08/09 (28)
- 07/26 - 08/02 (30)
- 07/19 - 07/26 (25)
- 07/12 - 07/19 (27)
- 07/05 - 07/12 (26)
- 06/28 - 07/05 (17)
- 06/21 - 06/28 (26)
- 06/14 - 06/21 (20)
- 06/07 - 06/14 (30)
- 05/31 - 06/07 (19)
- 05/24 - 05/31 (9)
- 04/12 - 04/19 (7)
- 04/05 - 04/12 (25)
- 03/29 - 04/05 (25)
- 03/22 - 03/29 (27)
- 03/15 - 03/22 (25)
- 03/08 - 03/15 (29)
- 03/01 - 03/08 (22)
- 02/22 - 03/01 (23)
- 02/15 - 02/22 (24)
- 02/08 - 02/15 (22)
- 02/01 - 02/08 (26)
- 01/25 - 02/01 (20)
- 01/18 - 01/25 (19)
- 01/11 - 01/18 (34)
- 01/04 - 01/11 (24)
-
►
2008
(1133)
- 12/28 - 01/04 (19)
- 12/21 - 12/28 (19)
- 12/14 - 12/21 (27)
- 12/07 - 12/14 (39)
- 11/30 - 12/07 (25)
- 11/23 - 11/30 (16)
- 11/16 - 11/23 (20)
- 11/09 - 11/16 (27)
- 11/02 - 11/09 (37)
- 10/26 - 11/02 (29)
- 10/19 - 10/26 (29)
- 10/12 - 10/19 (29)
- 10/05 - 10/12 (25)
- 09/28 - 10/05 (18)
- 09/21 - 09/28 (28)
- 09/14 - 09/21 (23)
- 09/07 - 09/14 (29)
- 08/31 - 09/07 (22)
- 08/24 - 08/31 (18)
- 08/17 - 08/24 (23)
- 08/10 - 08/17 (33)
- 08/03 - 08/10 (23)
- 07/27 - 08/03 (33)
- 07/20 - 07/27 (25)
- 07/13 - 07/20 (27)
- 07/06 - 07/13 (30)
- 06/29 - 07/06 (23)
- 06/22 - 06/29 (21)
- 06/15 - 06/22 (25)
- 06/08 - 06/15 (30)
- 06/01 - 06/08 (36)
- 05/25 - 06/01 (24)
- 05/18 - 05/25 (21)
- 05/11 - 05/18 (25)
- 05/04 - 05/11 (25)
- 04/27 - 05/04 (20)
- 04/20 - 04/27 (22)
- 04/13 - 04/20 (38)
- 04/06 - 04/13 (35)
- 03/30 - 04/06 (28)
- 03/23 - 03/30 (16)
- 03/16 - 03/23 (17)
- 03/09 - 03/16 (23)
- 03/02 - 03/09 (14)
- 02/24 - 03/02 (10)
- 02/17 - 02/24 (7)



