Newsfeed
(click to hide)
Last 10
- Friday Squid Blogging: Cipherlopods
- Netflix cancels recommendation contest over privacy
- Bugtraq: VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability
- Vuln: Cisco Digital Media Manager Default Credentials Authentication Bypass Vulnerability
- Bugtraq: [XSS] I found a xss in phpmyadmin 3.3.0 when we create new database in interface!
- Bugtraq: iDefense Security Advisory 03.11.10: Multiple Vendor WebKit HTML Element Use After Free Vulnerability
- Bugtraq: [SECURITY] [DSA 2013-1] New egroupware packages fix several vulnerabilities
- Bugtraq: [USN-911-1] MoinMoin vulnerabilities
- Bugtraq: [SECURITY] [DSA 2014-1] New moin packages fix several vulnerabilities
- Cybercrime surge pushes 2009 losses to 559 million dollars (AFP)
SANS Newsbites
SANS @Risk
Today´s Diary
If you have more information or corrections regarding our diary, please share.
Last Updated: 2010-03-11 22:40:20 UTC
by donald smith (Version: 1)
Earlier this week Jared sent us an interesting SKYPE spim. I suspect this was sent using the Skype IMbot discussed in the previous diary.
This one was a social engineering attempt to get the recipient to load scareware or fakeAV. Like most of these sites it had some java that is intended to simulate an antivirus scan. The scan is free of course. Everyone that gets "scanned" by this junk is infected. Getting cleaned of your viruses costs since you have to buy the commercial version to "clean" your infection. They have nice little functions like "hideActiveXDialog" and a doUpdatePercents which simply counts off tics to make it appear they are scanning the system. Then they throw up a banner2.jpg which is a warning that you have a bunch of scarey viruses including "System Soap Pro", AntiLamer Light, MC 30 day, SoftEther, I-Worm.NetSky.q, I-Worm.Bagle.n, Tofger-A, Zinx-A, B-S Spy 1.90 and KrAIMer 1.1"
Some of those names are known malware others appear to have been made up to insult anyone that gets this message. Who came up with System Soap, AntiLamer, SoftEther or BS spy. Here is the text that was sent out to entice victims to pay for this LAME fake AV.
WINDOWS REQUIRES IMMEDIATE ATTENTION
URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!
hxxp://www.onlineck.org
For the link to become active, please click on 'Add to
contacts' skype button or type it in manually into your web browser !
FULL DETAILS OF SCAN RESULT BELOW
****************************************
WINDOWS REQUIRES IMMEDIATE ATTENTION
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should
install a repair utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
http://www.onlineck.org/
For the link to become active, please click on 'Add to
contacts' skype button or type it in manually into your web browser!”
Last Updated: 2010-03-11 18:28:34 UTC
by donald smith (Version: 1)
CERT.at has provided a good technical analysis of a Skype IMBot.
The authors, Christian Wojner, L. Aaron Kaplan, did a good job of analysis of this IMBot.
They also "swapped notes" with Aaron Hackworth of secureworks.com. Such public/private collaboration I find to be very encouraging.
This is a fairly new vector. I have seen other IM based malware using skype IM so it’s not brand new but not too common yet either. The malware detects many Reverse Engineering applications and attempts to make the system unbootable if any type of RE is detected. It uses a new (novel) method to hide its processes/files. It scans local networks for 445 probably to exploit one of the many Microsoft vulnerabilities that can be exploited via that service. It uses "conficker like" encryption. It had logic to "infect" usb drives.
I really enjoyed this analysis as it included some interesting approaches and pointed to functionality that appeared to be in the bot but they were unable to trigger within their RE environment.
http://cert.at/static/downloads/papers/cert.at-an_analysis_of_the_skype_imbot_logic_and_functionality_1.2.pdf
If you have more information or corrections regarding our diary, click here to contact us.
Diary Archive
| Date | Author | Title |
|---|---|---|
| 2010-03-11 | donald smith | Cert write up on Skype IMBot Logic and Functionality. |
| 2010-03-11 | donald smith | Interesting SKYPE SPIM. |
| 2010-03-10 | Rob VandenBrink | What's My Firewall Telling Me? (Part 4) |
| 2010-03-10 | Rob VandenBrink | Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7 |
| 2010-03-09 | Marcus Sachs | Energizer Malware |
| 2010-03-09 | John Bambenek | Vodafone Android Phone: Complete with Mariposa Malware |
| 2010-03-09 | John Bambenek | March 2010 - Microsoft Patch Tuesday Diary |
| 2010-03-08 | Raul Siles | Samurai WTF 0.8 |
| 2010-03-08 | Raul Siles | SEO poisoning on TV show |
| 2010-03-07 | Mari Nichols | DHS issues Cybersecurity challenge |
Search Diaries:
Latest Reading Room Papers
Poll
Trends
more details
World Map
