Jan18
1:48 pm (UTC-7)   |   by Jake Soriano (Technical Communications)

Earlier this week, we blogged about the range of Web threats that would take advantage of Barack Obama’s inauguration on the 20th. We mentioned fake news as a possible social engineering ploy and cybercriminals did not disappoint. They were a little early in fact: Trend Micro Advanced Threats Researcher Paul Ferguson discovered bogus websites with headlines like Barack Obama has refused to be a president and links that lead to malicious executables.


Figure 1. This fake news website leads to malware.

Trend Micro detects some of the binaries (with file names like barack.exe and baracknews.exe for maximum effect) as WORM_WALEDAC variants – the same malware family that featured prominently in a spamming and malware operation just after New Year’s and which researchers believe is associated with bot giant Storm. WORM_WALEDAC variants are also notorious for their information-stealing routines.

Some of our detections include WORM_WALEDAC.KAX, WORM_WALEDAC.AE, WORM_WALEDAC.AH, WORM_WALEDAC.AG, WORM_WALEDAC.AD, WORM_WALEDAC.AL, TROJ_AGENT.DOZZ, TSPY_BANKER.BFE, TROJ_DLOADER.XGZ, BKDR_KRYPTIK.AB.

These malware are mostly hosted on domains that contain Obama-related key words. We found crafted web sites where all links lead to malware.

Users are advised to just trust known legitimate news websites for information.

Our engineers are still analyzing this threat further. We will post updates as soon as more information becomes available.

Update as of 18 January 2009, 8:00 PM PST

The following spammed email messages contain links that lead to fake Obama websites and ultimately to the download of WORM_WALEDAC.KAX:

Figures 2 & 3. These email messages also contain fabricated news reports.

WORM_WALEDAC.KAX steals email addresses by searching for these in files found in fixed, network, and RAM drives. It saves and encrypts a file containing its stolen information, and sends this file to several IP addresses using HTTP post. This worm also has backdoor capabilities. It opens random ports in an affected system to listen for commands from a remote user.

Update as of 20 January 2009, 9:00 PM PST

More malicious URLs purporting to be related to Barack Obama host another WALEDAC variant detected by Trend Micro as WORM_WALEDAC.AI. This worm has identical propagation and stealing routines as WORM_WALEDAC.KAX. Like the other worm, it also compromises system security by opening random ports, giving malicious users remote access.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




23 Responses to “Fake Obama News Sites Abound”

  1. buy phenteramine Says:

    All that I read on your blog is very interesting and causes arguments and disputes. For this I love to read you

Trackbacks

  1. Downadup/Conflicker: the Storm on the Horizon « Of Bytes and Badges
  2. bryan_michael (bryan_michael)
  3. ddpkts (tomas)
  4. Free Gadget News » Fake Obama news sites, emails being used to spread malware
  5. Evitez de télécharger Obama.exe - Gizmodo - Tant d'amour pour ces fabuleux nouveaux gadgets, c'est surnaturel.
  6. SPammer using Fake obama news site to spread virus and malware
  7. Gusano Barack.exe « Prisma Digital
  8. Epidemia de virus y malware relacionados con Obama | Materia Geek
  9. arunsub (Arun Subramanian)
  10. Day 1 of the new era [Link Cache] | Patriot Missive
  11. jellyfish_jvss (jellyfish_jvss)
  12. mbimotmog (Aaron K)
  13. Rich_at_Dell (Richard Bernier)
  14. plancaster (Patrick)
  15. iStylesdotcom (iStyles.com - MK)
  16. (铁球) 和 (而皮) » Blog Archive » 驱动器的面包圈拥有Shmeer数据周边
  17. Gadget» Blog Archive » Do Not Download Obama.exe [Obama]
  18. blog test via un flux rss google reader » Archives du Blog » Evitez de télécharger Obama.exe
  19. Information Security CG » Blog Archive » Beware the malware
  20. Do Not Download Obama.exe [Obama] | Techno Portal
  21.   Do Not Download Obama.exe [Obama] by Techno News Feed
  22. Of Bytes and Badges » Downadup / Conficker: the Storm on the Horizon

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice