Archive for September 18th, 2006


Sep18
by Ryan Flores (Advanced Threats Researcher)

For the past few days, the AV team has been analyzing a set of files and URL’s that is related to a certain Linkoptimizer Trojan.


Earlier this day, Jovs posted about the site js.gbeb.cc which uses a unique way of obfuscating code. Now this particular site connects to other sites when accessed. The sites it connects to are the following:



  • http://js.pcweb.cc
  • http://xearl.com
  • http://cvoesdjd.com
  • http://lah3bum9.com
  • http://gromozon.com
  • http://td8eau9td.com
  • http://mioctad.com

These sites in turn download TROJ_RKDICE.H with its rootkit component TROJ_LINKOPTIM.G.


TROJ_LINKOPTIM.G is a Browser Helper Object (BHO) that connects to these sites:



  • http://www.flashkin.net/sl.php
  • http://www.flashkin.net/common/template.php
  • http://www.flashkin.net/sh.php
  • http://www.flashkin.net/bs.php
  • http://www.flashkin.net/wl.php
  • http://www.flashkin.net/wlink.php
  • http://www.flashkin.net/ws.php
  • http://www.flashkin.net/gc.php
  • http://washerner.com/
  • http://chongchua.com/
  • http://livingcert.com/
  • http://fogcu.com/

For now, the sites mentioned above are blank (but our URL blocking now blocks these sites nevertheless).


The point of this blog entry is to emphasize that the infection cycle used by this trojan is an example of how malware use multiple components for propagation, obfuscation, and detection avoidance.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!

 
Posted in Uncategorized |

Sep18
by Jonell Baltazar (Advanced Threats Researcher)

Trend Micro recently released an urgent OPR due to the increase in infection count from PE_LOOKED variants on Trend Micro’s Business Units. There is also a notification delivered which recommends blocking of the following IP addresses:



  • h t t p://218.83.155.72
  • h t t p://218.85.132.212
  • h t t p://220.247.158.178
  • h t t p://221.231.138.85
  • h t t p://221.231.140.223
  • h t t p://59.34.197.251
  • h t t p://60.190.222.233
  • h t t p://61.152.116.22
  • h t t p://61.162.230.130

These are the download addresses found from the variants of PE_LOOKED. A simple Whois query of the said addresses reveals that these IP addresses are hosted mostly in China and in Taiwan ISP. Well, that leads us to, in a way; conclude that there are several zombie machines in China and Taiwan compromised by malicious hackers, probably from China.


It is also noted that the PE_LOOKED file infector downloads spyware trojans which aims to spy on user credentials on the on-line game, LINEAGE. The stolen credentials can be used by the malicious hacker to access the compromised users’ game and do whatever he wants… Well IMO, taking over someone else’s game is not the main objective of having this spyware trojan created. In this game, there are items and other things that make someone’s game character strong and these are the target of the malicious hacker. The hacker can then profit from these compromised users by selling to other lineage players what he got. Yes, it all boils down to money. :) Below is a snipped example of a website which offers Lineage items,accounts and others for a certain price.




This PE_LOOKED malware is not just for file infection but is also being used as a means for gaining profit. From a general view, it is now evident that malware authors aims for money these days and compared to the old malwares where they were created to probably achieve fame or for fun.

 
Posted in Uncategorized |

Sep18
by Trend Micro

Micorsoft has recently released a security advisory in response to the latest Internet Explorer 0-day reported a few days ago.


For more information you may visit the Microsoft website.


This is related to our two previous articles:


 
Posted in Uncategorized |

Sep18
by Jonell Baltazar (Advanced Threats Researcher)

Mozilla released critical updates to its web browser, Firefox, and email client, Thunderbird, addressing several security vulnerabilities. Users may visit the Mozilla Security Advisories for information about the fixed vulnerabilities.


Download the latest release of Firefox 1.5.0.7 and Thunderbird 1.5.0.7 from the following links:



Update now to avoid possible attacks which exploits these vulnerabilities patched by Mozilla.

 
Posted in Uncategorized |


© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice