ThreatFire Research Blog Home
 
 
« Pdf Reader Exploitation 2009 (cont)
That Darn Amanda »

MSN Messenger Worm Continues to be a Problem

Spoofing video codecs and third party video player plugin upgrades have proven to be an effective way to fool users into running malware on their systems. Malware does not need to spread effectively by exploiting vulnerable and unpatched code on a system.

Another extremely common and effective technique has been convincing users that their friends are sending them pictures. Attackers will use a variety of legitimate sounding Urls, alter the icons of the files they want users to run so that executables appear to be image files, and modify filenames to appear to be image files. These sorts of techniques are very common right now.

ThreatFire is currently preventing a high number of users from running an IM worm and its accompanying downloaded bot. The worm attempts to send itself out to MSN Messenger users’ address book contacts, convincing friends that fun pictures await. This worm installs an IRCbot, adding the machine to yet another botnet. Here is a handful of files being spread at the moment:

Image.php hosted at hxxp://hi5-album.com, hxxp://hi5-foto.net, and a number of other legitimate sounding Urls redirect users to a variety of files at
hxxp://66.29.31.3(slash)~RIVUX
with file names like PIC2009-02-15-JPG.exe, PICT1321.JPG.EXE, PICT0018.JPG.EXE and the others in the screenshot above. The downloads icons appear exactly as in the screenshot above, and when extensions are turned off for known file types (a Windows explorer setting) a user may not realize that they have an executable and not an image on their system. And because of the icon tampering, they look even more like jpg and gif files.

We’ve been posting about this sort of scheme for some time now. It continues to be effective and users need to be more aware of the techniques used.

This entry was posted on Thursday, March 19th, 2009 at 3:15 pm and is filed under Bot, IM Worm, Social Engineering. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).