Monday, August 18, 2008

The Analysis of Mystery Web Attack Hijacks Your Clipboard

Recently, The Register reported "Mystery web attack hijacks your clipboard", what happened? The conclusion is attacker tries to lure users to install a fake antivirus software and most people guess attacker uses Adobe Flash's vulnerability.

When clicked link (first picture), it will display the following screens:

























When clicked, wireshark captures files downloaded as below:



==The following focus on Web Reputation Service Testing==

Google Search CANNOT find it as below:



McAfee SiteAdvisor CANNOT find it as below:



Trend Micro WRS CANNOT find it as below:



finjan URL analysis CAN find it as below:



Dr.Web URL analysis CANNOT find it as below:



Exploit Prevention Labs's LinkScanner CANNOT find it as below:



Symantec Safe Web CANNOT find it as below:



==The following focus on AV Scanners Testing==

File AV2009Install_77011807.exe received on 08.17.2008 09:39:49 (CET)

Result: 8/36 (22.22%)

Antivirus Version Last Update Result
AhnLab-V3 2008.8.15.0 2008.08.15 -
AntiVir 7.8.1.19 2008.08.16 -
Authentium 5.1.0.4 2008.08.16 -
Avast 4.8.1195.0 2008.08.15 -
AVG 8.0.0.161 2008.08.16 Downloader.FraudLoad.E
BitDefender 7.2 2008.08.17 Trojan.FakeAlert.Gen.1
CAT-QuickHeal 9.50 2008.08.16 -
ClamAV 0.93.1 2008.08.16 -
DrWeb 4.44.0.09170 2008.08.17 -
eSafe 7.0.17.0 2008.08.14 -
eTrust-Vet 31.6.6035 2008.08.15 -
Ewido 4.0 2008.08.16 -
F-Prot 4.4.4.56 2008.08.16 -
F-Secure 7.60.13501.0 2008.08.17 Trojan-Downloader.Win32.FraudLoad.vbef
Fortinet 3.14.0.0 2008.08.17 -
GData 2.0.7306.1023 2008.08.16 Trojan-Downloader.Win32.FraudLoad.vbef
Ikarus T3.1.1.34.0 2008.08.17 -
K7AntiVirus 7.10.417 2008.08.15 -
Kaspersky 7.0.0.125 2008.08.17 Trojan-Downloader.Win32.FraudLoad.vbef
McAfee 5362 2008.08.15 -
Microsoft 1.3807 2008.08.17 -
NOD32v2 3361 2008.08.16 a variant of Win32/Adware.XPAntivirus
Norman 5.80.02 2008.08.15 -
Panda 9.0.0.4 2008.08.16 -
PCTools 4.4.2.0 2008.08.16 -
Prevx1 V2 2008.08.17 Fraudulent Security Program
Rising 20.57.61.00 2008.08.17 -
Sophos 4.32.0 2008.08.17 -
Sunbelt 3.1.1546.1 2008.08.15 -
Symantec 10 2008.08.16 AntiVirus2009
TheHacker 6.3.0.3.046 2008.08.13 -
TrendMicro 8.700.0.1004 2008.08.16 -
VBA32 3.12.8.3 2008.08.15 -
ViRobot 2008.8.16.1338 2008.08.16 -
VirusBuster 4.5.11.0 2008.08.16 -
Webwasher-Gateway 6.6.2 2008.08.17 -

Additional information
File size: 123904 bytes
MD5…: 978e985fc9f6e206fe9622ba42dc3d56
SHA1..: a8b20d587d62e34865814053c8f87574e1ffe790
SHA256: a53458279fa483236a453d7abdc718de69c361198f09a74a9a1b44d259f573ad
SHA512: 392bd1b0fe6b93a7df153e0faf25e0dd0ac68b38bae642a8061e459b2942d26a
d168fcb8ddf6d5d3e09437d539f476aab5809a2745f617ff7b6ee30e23e22e4a
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0×401210
timedatestamp…..: 0×45beb2d0 (Tue Jan 30 02:52:00 2007)
machinetype…….: 0×14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0×1000 0×57af 0×5800 5.19 922e2eb51ad64e063aa3d5aa5876de09
.data 0×7000 0×11557 0×11600 7.59 49b48fe56d5a4dcb86a792659875b88a
.tls 0×19000 0xdd 0×200 0.00 bf619eac0cdf3f68d496ea9344137e8b
.rdata 0×1a000 0×18 0×200 0.23 735b48446022cb7f0d9c4163b238a9be
.idata 0×1b000 0×5a0 0×600 3.29 97c93ffb47f18bb84d88652306581d5e
.rsrc 0×1c000 0xf4a3 0×6600 5.76 0d0781c1bba73476a7428d3a1667a138

( 2 imports )
> KERNEL32.DLL: CreateProcessA, GetCommandLineA, DeleteAtom, GetFileSize, GetCPInfo, GetComputerNameA, ReadConsoleA, Sleep, WriteFile, OpenFile, GlobalFree, GetFileTime, DeleteFileW, ExitThread, FindFirstFileA, GetConsoleMode, DeleteFileA, SetLastError, OpenFileMappingA, FindAtomA, ReadFile, GetLastError
> USER32.DLL: LoadCursorA, GetCursor, DrawIconEx, CreateIcon, GetFocus, DialogBoxParamW, CopyRect, InsertMenuA, GetWindowTextA, DrawIcon

After executed, it has the following behaviors:

[Added process]
C:\Program Files\AV9\av2009.exe

[Modified service]
NAME: srservice
DISPLAY: System Restore Service (Turn off system restore service)
STATUS: SERVICE_STOPPED
FILE: C:\WINDOWS\System32\svchost.exe-1 -k netsvcs

[Added file]
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
C:\Documents and Settings\Administrator\Desktop\Antivirus 2009.lnk
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\_freescan[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OXI7BCE5\winsystem[2].dll
C:\Documents and Settings\Administrator\Start Menu\Antivirus 2009\Antivirus 2009.lnk
C:\Documents and Settings\Administrator\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk
C:\Program Files\AV9\av2009.exe
C:\RECYCLER\S-1-5-21-515967899-583907252-839522115-500\Dc11.exe
C:\WINDOWS\system32\ieupdates.exe
C:\WINDOWS\system32\scui.cpl
C:\WINDOWS\system32\winsrc.dll

[Added COM/BHO]
{037C7B8A-151A-49E6-BAED-CC05FCB50328}-C:\WINDOWS\system32\winsrc.dll

[Added egistry]
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value=67760428610125642112784689834240
Data=C:\Program Files\AV9\av2009.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value=ieupdate
Data=”C:\WINDOWS\system32\ieupdates.exe”

HKU\S-1-5-21-515967899-583907252-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Value=67760428610125642112784689834240
Data=C:\Program Files\AV9\av2009.exe

HKU\S-1-5-21-515967899-583907252-839522115-500\Software\Microsoft\Windows\CurrentVersion\Run
Value=ieupdate
Data=”C:\WINDOWS\system32\ieupdates.exe”

Wednesday, August 13, 2008

Bogus MSNBC News

Today I receive an email, the subject is "msnbc.com - BREAKING NEWS: Too much freedom will destroy America", the content contains a malicious link, after clicked, it appears the same screen as "Fake CNN Alerts: Breaking news", please be careful.





After clicked the links, it will display as below:



Fake CNN Alerts: Breaking news

Today I receive another fake CNN Alerts News, subject is "CNN Alerts: Breaking news", when clicked the link, it will download "adobe_flash.exe". In the following, I will test web reputation service (most are not live analysis) and AV scanners separately.

Fake "CNN Alerts: Breaking news" email and email source code as below:





After clicked the links, it will display as below:



==The following focus on Web Reputation Service Testing==

Google Search CANNOT find it as below:



McAfee SiteAdvisor CANNOT find it as below:



Trend Micro WRS CANNOT find it as below:



finjan URL analysis CANNOT find it as below:



Dr.Web URL analysis CANNOT find it as below:



Exploit Prevention Labs's LinkScanner CAN find it as below:



Symantec Safe Web CANNOT find it as below:



==The following focus on AV Scanners Testing==

The following test result is from VirusTotal (14/36 (38.89%)):

File adobe_flash.exe-1 received on 08.13.2008 00:18:58 (CET)

Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Dldr.Exchanger.DW
Authentium - - -
Avast - - -
AVG - - Downloader.Agent.AJFH
BitDefender - - Trojan.Downloader.Exchanger.Gen.2
CAT-QuickHeal - - (Suspicious) - DNAScan
ClamAV - - -
DrWeb - - Trojan.DownLoad.3248
eSafe - - Suspicious File
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
F-Secure - - -
Fortinet - - W32/PolyExchanger.A!tr
GData - - -
Ikarus - - Trojan-Downloader.Exchanger.Gen.2
K7AntiVirus - - -
Kaspersky - - Trojan-Downloader.Win32.Exchanger.mn
McAfee - - -
Microsoft - - Trojan:Win32/Tibs.gen!K
NOD32v2 - - a variant of Win32/Agent.ETH
Norman - - -
Panda - - -
PCTools - - -
Prevx1 - - Malware Dropper
Rising - - -
Sophos - - Mal/EncPk-DA
Sunbelt - - -
Symantec - - -
TheHacker - - -
TrendMicro - - -
VBA32 - - -
ViRobot - - -
VirusBuster - - -
Webwasher-Gateway - - Trojan.Dldr.Exchanger.DW
Additional information
MD5: 06bd0701d470475d32c6d98a0c685e4b
SHA1: 0e1a02834b931a5d34d684f7708c918e0c8fa187
SHA256: a629c6ea28327a467e666a2a7d5a5ccc3194858b2217f608431b98dff268c2d9
SHA512: cf15fc7e1a26ef63cf7a1483b4a50a52deaae00a3f2667acf3d3396985dfbf20ba2033a0081656d5463de640116fc7ec49019683f63123afd3dd0d23e790710f

The following test result is from VirusTotal (10/33 (30.30%)):

File update.htm-malscript received on 08.13.2008 04:26:00 (CET)

Antivirus Version Last Update Result
AhnLab-V3 2008.8.13.0 2008.08.12 -
AntiVir 7.8.1.19 2008.08.12 HEUR/HTML.Malware
Authentium 5.1.0.4 2008.08.12 JS/Agent.FA
Avast 4.8.1195.0 2008.08.12 -
AVG 8.0.0.161 2008.08.12 Downloader.Zlob.HTML
BitDefender 7.2 2008.08.13 Trojan.HTML.Zlob.Y
CAT-QuickHeal 9.50 2008.08.12 HTM/Zlob.GEN.2
ClamAV 0.93.1 2008.08.12 -
DrWeb 4.44.0.09170 2008.08.12 -
eSafe 7.0.17.0 2008.08.12 JS.Agent.ib.
eTrust-Vet 31.6.6029 2008.08.13 -
Ewido 4.0 2008.08.12 -
F-Prot 4.4.4.56 2008.08.12 JS/Agent.FA
Fortinet 3.14.0.0 2008.08.12 JS/Zlob!tr.dldr
GData 2.0.7306.1023 2008.08.13 -
Ikarus T3.1.1.34.0 2008.08.13 Trojan.HTML.Zlob.Y
K7AntiVirus 7.10.412 2008.08.12 -
Kaspersky 7.0.0.125 2008.08.13 -
McAfee 5359 2008.08.12 -
Microsoft 1.3807 2008.08.13 -
NOD32v2 3350 2008.08.12 -
Norman 5.80.02 2008.08.12 -
Panda 9.0.0.4 2008.08.12 -
PCTools 4.4.2.0 2008.08.12 -
Prevx1 V2 2008.08.13 -
Rising 20.57.12.00 2008.08.12 -
Sophos 4.32.0 2008.08.13 -
Sunbelt 3.1.1542.1 2008.08.13 -
TheHacker 6.3.0.3.046 2008.08.12 -
TrendMicro 8.700.0.1004 2008.08.12 -
ViRobot 2008.8.12.1333 2008.08.12 -
VirusBuster 4.5.11.0 2008.08.12 -
Webwasher-Gateway 6.6.2 2008.08.13 Heuristic.HTML.Malware
Additional information
File size: 20881 bytes
MD5...: f610dd6607641f7de0a0e504147534a1
SHA1..: 27c52ffd95c799a787c081f3a55cbf61a4b9e528
SHA256: 56086eb41f081f1b7faea2807082097a0b677858a45336edd30e6a756c69afae
SHA512: 78395acdb375c97692110fc0f263a07f5b173cc443e6c0d688af4dc9774927d3
7fcb3ea7eca617c42d14fe7001b9f68e5242594e60443fd5722894182de47fc7
PEiD..: -
PEInfo: -

After executed, this malware has the following behaviors:

[Added process]
C:\WINDOWS\System32\CbEvtSvc.exe

[DLL injection]
C:\Program Files\Internet Explorer\setupapi.dll

[Added service]
NAME: CbEvtSvc
DISPLAY: CbEvtSvc
FILE: C:\WINDOWS\System32\CbEvtSvc.exe -k netsvcs

[Added file]
C:\9ndb39.exe
C:\Documents and Settings\Administrator\Desktop\adobe_flash.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\bvp[1].css
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\metai[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\index[1]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\update[1].htm
C:\Documents and Settings\LocalService\Application Data\521632863.exe
C:\Documents and Settings\LocalService\Application Data\633968421.exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\BJW6A44R\install[1].exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MMFL79XH\12scan2[1].exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WDWHWPH6\fg[1].exe
C:\Program Files\Internet Explorer\setupapi.dll
C:\WINDOWS\system32\CbEvtSvc.exe
C:\WINDOWS\system32\drivers\5a92b36c.sys (Rootkit Behavior)
C:\WINDOWS\Temp\37D8BF6785C63DB6.tmp
C:\WINDOWS\Temp\4AECE6A407384DE3.tmp
C:\WINDOWS\Temp\92618DBC42FD0246.tmp
C:\WINDOWS\Temp\AB.tmp
C:\WINDOWS\Temp\ACBF1B06A8F8098A.tmp


Sunday, August 10, 2008

Fake "CNN Alerts: My Custom Alert"

After fake "CNN.com Daily Top 10" Video, another fake "CNN Alerts: My Custom Alert" appears recently. When clicked the link, it will download "adobe_flash.exe" and it identifies as TR/Crypt.XPACK.Gen.

Fake "CNN Alerts: My Custom Alert" email as below:



Fake "CNN Alerts: My Custom Alert" email header as below:



After clicked the links in email, it will display as below:




The above link contains a malicious script as below:



==The following focus on Web Reputation Service Testing==

Google Search can find it as below:



McAfee SiteAdvisor finds nothing as below:



Trend Micro WRS finds nothing as below:



finjan URL analysis finds nothing as below (regard it as legitimate):



Dr.Web URL analysis finds nothing as below:



Symantec Safe Web finds nothing as below:



==The following focus on AV Scanners Testing==

The following test result is from VirusTotal (14/36 (38.89%)):

File adobe_flash.exe1109.safe received on 08.09.2008 17:23:24 (CET)

AhnLab-V3 2008.8.9.0 2008.08.08 -
AntiVir 7.8.1.19 2008.08.09 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2008.08.09 -
Avast 4.8.1195.0 2008.08.08 -
AVG 8.0.0.156 2008.08.08 I-Worm/Nuwar.V
BitDefender 7.2 2008.08.09 Trojan.Downloader.Exchanger.Gen.2
CAT-QuickHeal 9.50 2008.08.08 (Suspicious) - DNAScan
ClamAV 0.93.1 2008.08.09 -
DrWeb 4.44.0.09170 2008.08.09 Trojan.DownLoad.3248
eSafe 7.0.17.0 2008.08.07 Suspicious File
eTrust-Vet 31.6.6021 2008.08.08 -
Ewido 4.0 2008.08.09 -
F-Prot 4.4.4.56 2008.08.08 -
F-Secure 7.60.13501.0 2008.08.09 -
Fortinet 3.14.0.0 2008.08.09 -
GData 2.0.7306.1023 2008.08.09 Trojan-Downloader.Win32.Exchanger.lj
Ikarus T3.1.1.34.0 2008.08.09 Win32.SuspectCrc
K7AntiVirus 7.10.408 2008.08.09 -
Kaspersky 7.0.0.125 2008.08.09 Trojan-Downloader.Win32.Exchanger.lj
McAfee 5357 2008.08.08 -
Microsoft 1.3807 2008.08.09 Trojan:Win32/Tibs.gen!K
NOD32v2 3341 2008.08.08 a variant of Win32/Agent.ETH
Norman 5.80.02 2008.08.08 -
Panda 9.0.0.4 2008.08.09 -
PCTools 4.4.2.0 2008.08.09 -
Prevx1 V2 2008.08.09 Malware Dropper
Rising 20.56.41.00 2008.08.08 -
Sophos 4.32.0 2008.08.09 Mal/EncPk-DA
Sunbelt 3.1.1538.1 2008.08.09 -
Symantec 10 2008.08.09 -
TheHacker 6.2.96.395 2008.08.08 -
TrendMicro 8.700.0.1004 2008.08.08 -
VBA32 3.12.8.3 2008.08.09 -
ViRobot 2008.8.8.1329 2008.08.08 -
VirusBuster 4.5.11.0 2008.08.09 -
Webwasher-Gateway 6.6.2 2008.08.09 Trojan.Crypt.XPACK.Gen

Additional information
File size: 78848 bytes
MD5...: 0e41b670cbccce9051fb8d1188aebd0a
SHA1..: d9a952ef59c5ee30e63b9d3dd781a7477911c866
SHA256: a5528757cd736d7a801443d0d4490b0d6d7c54a09e014afc240c62fd45ddadf6
SHA512: 1654e3b70376b817c9428007d26b34474f081e3082acdcbd3759b136d0dbe4f0
a04ba3c8da0d9ee1b84689d3b3f437f9595f3a4c763fed578d67ae201acc6cc4
PEiD..: -

After executed, this malware has the following behaviors:

[Added process]
C:\WINDOWS\System32\CbEvtSvc.exe

[Added service]
NAME: CbEvtSvc
DISPLAY: CbEvtSvc
STATUS: SERVICE_RUNNING
FILE: C:\WINDOWS\System32\CbEvtSvc.exe -k netsvcs

[Added file]
C:\Documents and Settings\Administrator\Desktop\adobe_flash.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\cnncurrent[1].htm
C:\Documents and Settings\LocalService\Application Data\666410720.exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\BJW6A44R\install[1].exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MMFL79XH\08scan[1].exe
C:\WINDOWS\system32\CbEvtSvc.exe
C:\WINDOWS\system32\drivers\91226516.sys (Rootkit Behavior)
C:\WINDOWS\Temp\37D8BF6785C63DB6.tmp
C:\WINDOWS\Temp\4AECE6A407384DE3.tmp
C:\WINDOWS\Temp\92618DBC42FD0246.tmp
C:\WINDOWS\Temp\A9.tmp
C:\WINDOWS\Temp\ACBF1B06A8F8098A.tmp

Saturday, August 9, 2008

The Slides of 4th Hacks in Taiwan Conference

4th Hacks in Taiwan Conference has held on July 19,2008, now the slides (some contain traditional chinese) have published on http://hitcon.org/hit2008/.

Vista system restore rootkit - Principle and protection by CardMagic
Web Threat Detection and Prevention by Roger Chiu
Firefox Extension Spyware by ANT
You can't see me!! by Unohope
You can't see me!! by Trueman
0Day Demo (unavailable)
Worm ,Botnet and remote exploit by militan (unavailable)
Malicious Document Detection and Analysis by Tim Hsu
0Day Demo: Nopam+ Authentication Bypass Vulnerability
Remote Control Software Design by Kelp
Cloud (in)Security by tt

Fake IE7 Update

Recently I received several emails with subject "Internet Explorer 7", this is a fake IE7 update. When you clicked the link in this mail, it will download "update.exe" to local system, please be careful.

An email of fake IE7 update as below:



Fake IE7 update email header as below:



After clicked the links in mail, it will display as below:



After executed in VMWare, it displays an error as below:



Google Search finds nothing as below:



McAfee SiteAdvisor finds nothing as below:



Trend Micro WRS can find it as below:



finjan URL analysis finds nothing as below:



Dr.Web URL analysis can find it as below:



The following test result is from VirusTotal (Result: 32/36 (88.89%)):

File update.exe received on 08.09.2008 00:30:56 (CET)

AhnLab-V3: Win32/Zhelatin.worm.139776.QM
AntiVir: TR/Dldr.Small.aafh
Authentium: W32/Downldr2.DIFM
Avast: Win32:Trojan-gen {Other}
AVG: Downloader.Generic7.AEHX
BitDefender: Trojan.FakeAlert.YK
CAT-QuickHeal: TrojanDownloader.Small.aafh
ClamAV: Trojan.Fakealert-446
DrWeb: Trojan.Fakealert.995
eSafe: Suspicious File
eTrust-Vet: Win32/Bugnraw.CC
Ewido:
F-Prot: W32/Downldr2.DIFM
F-Secure: Trojan-Downloader.Win32.Small.aafh
Fortinet: W32/FakeAle.AAFH!tr.dldr
GData: Trojan-Downloader.Win32.Small.aafh
Ikarus: Trojan-Downloader.Win32.Small.aafh
K7AntiVirus:
Kaspersky: Trojan-Downloader.Win32.Small.aafh
McAfee: Generic FakeAlert.a
Microsoft: TrojanDownloader:Win32/Renos.DI
NOD32v2: Win32/TrojanDownloader.FakeAlert.DJ
Norman: W32/Renos.dam
Panda: Adware/Antivirus2008XP
PCTools: Trojan-Downloader.Small!sd6
Prevx1: Malicious Software
Rising:
Sophos: Troj/FakeAle-EF
Sunbelt: Trojan.Unidentified.Gen.AT
Symantec: Trojan.Dropper
TheHacker:
TrendMicro: TROJ_RENOS.ADX
VBA32: Trojan-Downloader.Win32.renos.adx
ViRobot: Trojan.Win32.Downloader.139776.C
VirusBuster: Trojan.FakeAlert.FV
Webwasher-Gateway: Trojan.Dldr.Small.aafh

Additional information
MD5: 6b50dc99f2ca5e90ef6ecef9a25c6157
SHA1: 464d7f2e540eafc2162293ad11b28ba8b91dd21b
SHA256: 9083a161e7e9fb25bd99d814cfafa953881b1249ad079040c5faf158a3b7f203
SHA512: 1c70fe117fb7a757807484bad7ab7400427433e0b9e1cceb05c72b194cb22e7dc25e4b5774679c3a782ad4873fdfdc931e01e3b50f53ef65f6582aa081b50896

Related News:

Fake Microsoft Internet Explorer 7.0 Update
Fake IE 7.0 Update: Full Analysis

Friday, August 8, 2008

Trend Micro Web Protection Add-On Identifies PDF Files as Spyware

Trend Micro Web Protection Add-On identifies the following PDF files as spyware, this is a false-positive detection.

http://www.hitcon.org/hit2008/download/HIT2008-Vista_system_restore_rootkit-CardMagic.pdf
http://www.hitcon.org/hit2008/download/HIT2008-%20You_Cannot_See_Me-Unohope.pdf
http://www.hitcon.org/hit2008/download/HIT2008-%20You_Cannot_See_Me-Tureman.pdf
http://www.hitcon.org/hit2008/download/HIT2008-MDScan-TimHsu.pdf
http://www.hitcon.org/hit2008/download/HIT2008-%BB%B7%B1%B1%B3n%C5%E9%B3%5D%ADp-Kelp.pdf
http://www.hitcon.org/hit2008/download/HIT2008-Cloud_inSecurity-tt.pdf

The key reason is www.hitcon.com is identified as a malicious web site.









What is Trend Micro Web Protection Add-On? According to this help, includes Trend Micro Web Threat Protection and “in-the-cloud” bot behavior analysis capabilities...

Fake "CNN.com Daily Top 10" Video

Recently many news about CNN.com Daily Top 10, this is a fake CNN videos, it contains a malware, please be careful.

The following is fake CNN.com Daily Top 10's email:



After clicked the links in mail, it will display as below:



Google Search finds nothing as below:



McAfee SiteAdvisor finds nothing as below:



Trend Micro WRS can find it as below:



finjan URL analysis finds nothing as below:



Dr.Web URL analysis finds nothing as below:



Exploit Prevention Labs's LinkScanner finds nothing as below:



After executed, the desktop's theme will become as below:



After executed, this malware has the following behaviors:

[Added process]
C:\WINDOWS\System32\CbEvtSvc.exe
C:\WINDOWS\system32\lphcl76j0eg03.exe

[Added service]
NAME: CbEvtSvc
DISPLAY: CbEvtSvc
FILE: C:\WINDOWS\System32\CbEvtSvc.exe -k netsvcs

[Added file]
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt1.tmp
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt1.tmp.vbs
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt7.tmp
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\get_flash_update[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\index2[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\C13NVBMZ\master[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Q08VKCK4\1[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\dnd[1].js
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SEUIMLSE\metai[1].htm
C:\Documents and Settings\Administrator\wXtwRzv.exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\BJW6A44R\04scan[1].exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MMFL79XH\install[1].exe
C:\WINDOWS\system32\blphcl76j0eg03.scr
C:\WINDOWS\system32\CbEvtSvc.exe
C:\WINDOWS\system32\drivers\4e0f5644.sys (Rootkit Behavior)
C:\WINDOWS\system32\lphcl76j0eg03.exe
C:\WINDOWS\system32\phcl76j0eg03.bmp
C:\WINDOWS\Temp\.ttC9.tmp
C:\WINDOWS\Temp\.ttC9.tmp.vbs
C:\WINDOWS\Temp\.ttD0.tmp
C:\WINDOWS\Temp\37D8BF6785C63DB6.tmp
C:\WINDOWS\Temp\4AECE6A407384DE3.tmp
C:\WINDOWS\Temp\92618DBC42FD0246.tmp
C:\WINDOWS\Temp\ACBF1B06A8F8098A.tmp

[Added registry]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value=lphcl76j0eg03
Data= C:\WINDOWS\system32\lphcl76j0eg03.exe

Until now (Aug 7, 2008 @ 16:07), the following AVs can detect these mlawares (for reference only):

get_flash_update[1].exe (maybe other av can detect it too):
[ Trend ], “TROJ_TIBS.CSZ”
index2[1].htm (maybe other av can detect it too):
[ Trend ], “HTML_DLOADER.PCS”
install[1].exe (maybe other av can detect it too):
[ Trend ], “TROJ_MUTANT.EW”
lphcl76j0eg03.exe (maybe other av can detect it too):
[ Trend ], “ADW_XPANTIVIR”
wXtwRzv.exe (maybe other av can detect it too):
[ Trend ], “TROJ_TIBS.CSZ”
1[1].htm (maybe other av can detect it too):
[ Trend ], “HTML_ADODB.HB”
04scan[1].exe (maybe other av can detect it too):
[ Trend ], “ADW_XPANTIVIR”
blphcl76j0eg03.scr (maybe other av can detect it too):
[ Trend ], “JOKE_BLUESCREEN”
CbEvtSvc.exe (maybe other av can detect it too):
[ Trend ], “TROJ_TIBS.CSZ”
master[1].js:
[ Grisoft ], “Trojan horse Downloader.Generic_c.AAN”
[ WebWasher ], “Script.Dldr.Agent.PV”
[ bitdefender ], “Trojan.FakeAlert.WO”
metai[1].htm:
[ WebWasher ], “BlockReason.46 (suspicious)”
phcl76j0eg03.bmp:
[ Symantec ], “Trojan.Blusod”
[ Nod32 ], “Win32/TrojanDownloader.FakeAlert.DJ trojan”
[ Grisoft ], “Trojan horse Generic_c.OYJ”
[ bitdefender ], “Trojan.FakeAlert.UM”
ttC9.tmp.vbs:
[ Alwil ], “VBS:Malware-gen”
[ HBEDV ], “VBS/Agent.1002″
[ Ikarus ], “Win32.SuspectCrc”
[ WebWasher ], “Script.Agent.1002″

Related News:

New Trojan Bait: CNN Videos (TrendLabs Malware Blog)

Fake CNN headlines (Sunbelt Blog)

We are back ...

We have stopped to test antivirus softwares about a year, now we are back, we will start to perform antivirus comparison from September, 2008.

Friday, June 29, 2007

Antivirus Comparison Report (Jun 28, 2007)

Updated: July 5, 2007

In this report, the terminology, malware, includes virus, trojan, worm, backdoor, spyware, adware, dialer, keylogger, hack tool and so on. The samples we use are collected daily from Honeypot, the total malware count is 267,287, total file size is about 34,156 MB.

The following table shows detection rate and scan performance for antivirus software:




For detailed information, please refer to PDF file.

If you want to verify our test result, we provide the following data, please feel free to contact us:

  • All malware files’ SHA1 value.
  • All antivirus scan logs.
Note: This report is for reference only. Nowadays antivirus softwares have provided total protection for malware, but antivirus test organizations still use old test methodologies to evaluate them, they cannot reflect antivirus softwares' capabilities, so we will use other test methodologies to evaluate antivirus softwares in the future.