Aug28 |
6:54 pm (UTC-7) | by
Det Caraig (Technical Communications) |
Trend Micro threat analysts were alerted to the discovery of a spyware (detected as TSPY_EBOD.A) purporting to be an Adobe Flash Player update. Upon execution, the spyware creates a Firefox add-on called “Adobe Flash Player 0.2,” the installer of which uses JavaScript (detected as JS_EBOD.A) and appears to spread via forum posts.
|
|
The said add-on injects ads into the user’s Google search results pages. More disturbing, however, is its capability to monitor the user’s browsing activities, particularly his/her Google search queries using the Firefox browser. It then sends the information it gathers to http://{BLOCKED}jupdate.com.
We have seen a lot of malware target Internet Explorer in the past. This is probably one of the reasons why a huge number of users are opting to use alternative browsers such as Firefox, Chrome, Safari, and Opera instead. Though this used to be considered a safe computing practice, it seems it no longer is with the proliferation of malware targeting the most popular alternative Internet browser—Firefox.
Users should be wary, as always, of downloading updates from unknown sources. They should also note that no browser is safe from malicious attacks, as cybercriminals will do just about anything to infect users with their malicious code.
The Trend Micro Smart Protection Network already detects and consequently blocks the malicious code from running and the malicious add-on from being downloaded so Trend Micro product users need not worry.
Share this article |
|






Pingback: FirefoxにFLASH Playerを装うスパイウェア | S^3 国内外のデジタルニュースをナナメ読み
Pingback: Los Cuatro Ojos » Spyware Posing as Flash Update Hits Firefox… Beware!
Pingback: PixMedial — Design & Geek » Troyano en Firefox disfrazado como plugins de Adobe Flash Player
Pingback: actualización Adobe Flash para Firefox es un troyano | Incubaweb
Pingback: Otro blog » Trust No One
Pingback: Adobe Flash Player 0.2, un troyano para Firefox | DevNote
Pingback: Cuidado con Adobe Flash Player 0.2, un troyano para Firefox | DevNote
Pingback: Cuidado con Adobe Flash Player 0.2, un troyano para Firefox | guanche.com
Pingback: “Adobe Flash Player 0.2″ es un troyano para Firefox | Infinito Punto Alfa
Pingback: Bloggism.net - Beware of Firefox Add-On Adobe Flash Player 0.2
Pingback: Cuidado con Adobe Flash Player 0.2, un troyano para Firefox | Bitelia
Pingback: Tech Thoughts Daily Net News – September 3, 2009 « Bill Mullins’ Weblog – Tech Thoughts
Pingback: Firefox Spyware Add-On Adobe Flash Player 0.2 « Hanady’s Blog
Pingback: im Windowsblog | Am Puls der Microsoft Betriebssysteme
Pingback: Firefox Spyware Add-On Adobe Flash Player 0.2 | TechZond
Pingback: Scoperto uno spyware camuffato da add-on per Firefox. | TuttoVolume
Pingback: Trend Micro alerta para malware que ataca o Firefox | Tudo sobre tecnologia!
Pingback: Firefox Spyware Add-On Adobe Flash Player 0.2
Pingback: Firefox add-on spies on Google usage, search results | Zero Day | ZDNet.com
Pingback: Trend Micro alerta para malware que ataca o Firefox « Domínio TI
Pingback: Trend Micro alerta para malware que ataca o Firefox « Windows System
Pingback: TSPY_EBOD.A – a trojan on Firefox Add-On
Pingback: Mozilla Firefox attacked by a spyware extension « Ryan’s Blog
Pingback: Trend Micro alerta para malware que ataca o Firefox | New Info
Pingback: Firefox add-on 'Adobe Flash player' is spyware | Beveiligingslog
Pingback: Mozilla Firefox Attacked By Rogue Extension « The BAT Channel
Pingback: Mozilla Firefox Attacked By Rogue Extension « AccessTech News
Pingback: Mozilla Firefox Attacked By Rogue Extension » Tech With Us
Pingback: Mozilla Firefox Attacked By Rogue Extension ~ The Blade by Ron Schenone MVP
Pingback: UnderForge of Lack » Blog Archive » 2009.08.31 月曜日
Pingback: Bogus Firefox Add-on Poses As Flash Player
Pingback: Twitter Trackbacks for Firefox Plugin Spies on Google Search Results | Malware Blog | Trend Micro [trendmicro.com] on Topsy.com
Pingback: Firefox Plugin Spies on Google Search Results | Malware Blog | Trend Micro « Jared Rimer’s Technology blog and podcast