• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   Malware   »   Video of Gadhafi's Death Being Used for Spam

Video of Gadhafi's Death Being Used for Spam

  • Posted on:October 26, 2011 at 8:20 pm
  • Posted in:Malware, Spam
  • Author:
    Chloe Ordonia (Anti-spam Research Engineer)
2

We’ve been seeing a particular social engineering lure in spam runs in the past, where spammers leverage the death of a known celebrity or political figure. Recent examples of this include the death of Steve Jobs, and Amy Winehouse. In this spam run using Gadhafi’s death, however, a more compelling lure is being used to trick users into downloading malicious files.

We found several spammed messages that claim to lead to videos of Gadhafi’s death. It is important to note that videos of Gadhafi’s death do exist, and legitimate news sites like Reuters and The Washington Post tell of the graphic content in the video and even host the said videos on their websites. This existence of real videos of Gadhafi’s death relatively makes it a more compelling lure.

The first sample disguises itself as a CNN newsletter in Spanish. It tells the user to download the video footage of Gadhafi’s death through the link provided. However, the supposed video file, Video-Gadhafi.mpeg.exe, that the user is led to turns out to be malware which we detect as BKDR_IRCBOT.DAM.

BKDR_IRCBOT.DAM connects to a certain IRC server and waits for commands from a remote user. So far, the only command we’ve seen being triggered by this connection is the downloading and execution of a file from a certain IP address. The said file is another copy of BKDR_IRCBOT.DAM. We believe that this routine is this malware’s way of updating itself.

 

Click for larger view Click for larger view

Click for larger viewAnother spam sample we found comes in plain text format and has a .RAR attachment. The mail says the attachment only contains the “late Muammar Gadhafi’s dead body pics”, but little does the user know that what he/she is extracting the malware.

The file Gadhafi.exe is verified as malicious and is already detected as BKDR_EXDEPH.A.. Upon execution, this backdoor drops and opens a .JPG file to trick users into thinking that the executed file is legitimate and to hide its execution in the background. Similar to BKDR_IRCBOT.DAM, what BKDR_EXDEPH.A does is connect to a certain URL to receive commands from a remote user. The said URL, however, is inaccessible as of this writing.

The third sample we received is in Portuguese. It has a screenshot of video footage of the bloody Gadhafi as well as a link supposedly pointing to the said video. However, the said link is currently unavailable.

The malicious files, URLs, and spammed messages are already detected and blocked accordingly through the Trend Micro Smart Protection Network. Nonetheless, users are still strongly advised to avoid clicking links found in emails sent by suspicious or unknown senders.

Learn how to protect Enterprises, Small Businesses, and Home Users from ransomware:
ENTERPRISE »
SMALL BUSINESS»
HOME»

Featured Stories

  • systemd Vulnerability Leads to Denial of Service on Linux
  • qkG Filecoder: Self-Replicating, Document-Encrypting Ransomware
  • Mitigating CVE-2017-5689, an Intel Management Engine Vulnerability
  • A Closer Look at North Korea’s Internet
  • From Cybercrime to Cyberpropaganda

Security Predictions for 2019

  • Our security predictions for 2019 are based on our experts’ analysis of the progress of current and emerging technologies, user behavior, and market trends, and their impact on the threat landscape. We have categorized them according to the main areas that are likely to be affected, given the sprawling nature of the technological and sociopolitical changes under consideration.
    Read our security predictions for 2019.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Recent Posts

  • September Patch Tuesday Bears More Remote Desktop Vulnerability Fixes and Two Zero-Days
  • IoT Attack Opportunities Seen in the Cybercrime Underground
  • ‘Purple Fox’ Fileless Malware with Rookit Component Delivered by Rig Exploit Kit Now Abuses PowerShell
  • Malware Classification with ‘Graph Hash,’ Applied to the Orca Cyberespionage Campaign
  • Spam Campaign Abuses PHP Functions for Persistence, Uses Compromised Devices for Evasion and Intrusion

Popular Posts

  • August Patch Tuesday: Update Fixes ‘Wormable’ Flaws in Remote Desktop Services, VBScript Gets Disabled by Default
  • TA505 At It Again: Variety is the Spice of ServHelper and FlawedAmmyy
  • Jenkins Admins: Relying on Default Settings Could Put Master at Risk of Remote Code Execution Attacks
  • Adware Posing as 85 Photography and Gaming Apps on Google Play Installed Over 8 Million Times
  • Uncovering a MyKings Variant With Bootloader Persistence via Managed Detection and Response

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.