ThreatFire Research Blog Home
 
 
« AMTSO Oxford
Rigged pdf files »

Obama elected U.S. President 44 in a Landslide Victory, but…

any spammed email message claiming to provide a link to information about U.S. culture or foreign policy may likely provide a trojan with rootkit capabilities.

In one of the most prevalent social engineering schemes of this half of the year, users clicking on a spammed link are directed to a web page with a phony video. The user’s browser then displays a request to update their Adobe Flash version to play the video. This time, the malicious executable’s download name is “Adobe_Flash9.exe“. Users seem to be enticed into clicking links with the text “Proceed to the election results news page” and then running this file.
As always, avoid interacting with messages and links that seem questionable.

Another interesting Obama-related file just hitting our community this afternoon has been an infected executable containing a copy of President-elect Barack Obama’s entire acceptance speech: “obama’s presidential speech.exe“. This one just appears to be run from a system previously infected with a virus with the family name of “Nakuru” or “Kespo”. Symantec’s research team calls it W32.Tupofse.B.
The exe drops the original copy of the .doc file to disk before dropping other viral code, like kspoold.exe. When run, the original .doc file is opened and the entire speech appears:
“If there is anyone out there who still doubts that America is a place where all things are possible; who still wonders if the dream of our founders is alive in our time; who still questions the power of our democracy, tonight is your answer…”
Be sure to pay attention to file extensions before double-clicking on files. The icon for the file is altered by the virus so that it appears to be associated with Word, with a .doc extension, but it only has a .exe extension. Here is an image of the file, on a system that doesn’t have Microsoft Word installed on it (the icon normally never appears for .doc files, the wordpad icon should appear by default):

This entry was posted on Wednesday, November 5th, 2008 at 4:01 pm and is filed under Rootkit, Social Engineering, Spam, Trojan, cybercrime. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).