Dnschanger Malware Set To Knock Thousands Off Internet On Monday
#1
Posted 05 July 2012 - 06:08 AM
#2
Posted 05 July 2012 - 09:18 AM
#4
Posted 05 July 2012 - 05:44 PM
Gibson295, on 05 July 2012 - 09:18 AM, said:
Now, it's easy to know if you've been infected with DNSChanger; even Google and Facebook are starting to warn users, but 5 years ago it wasn't like that. And even when you remove DNSChanger, there still may be other stealth malware hidden on your system. DNSChanger spread primarily through the TDSS Rootkit, an extremely advanced rootkit that hooks deep into the Windows OS. TDSS usually spreads through one of two attack vectors. The first attack vector is warez and porn sites. For example*:
TDSS Rootkit Silently Owns the Net - Prevx
"The infection comes from the usual dropper spread by peer to peer networks or by crack and keygen websites, and it needs administrator privileges to run its payload. If UAC is disabled or the user voluntarily gives admin permissions, this infection can run even on Windows Vista and Windows 7.
This is likely to be the usual scenario, where a user looks for specific cracks and don't mind if UAC warnings him, he gives admin privileges to the wanted crack."
___________________________________________________________________________
The second category is the drive-by download usually through a 0px (invisible) iframe. One example:
Fragus Exploit Kit - TDSS Rootkit
"While looking after an AutoIt decompiler I ran into the Fragus Exploit Kit on a hacked Wordpress Blog. It all started with an iframe pointing to [xxxxxxx].com.
We run straight into [the file] show.php containing a heavily obfuscated JavaScript hiding several exploits. The unlucky visitor bumps into a 404 page not found error while the JavaScript silently starts its evil work in the background, leaving the victim unaware of what's happening. The same 404 page is meant to slow down analysts too.
Once the script decoded we discover several exploits:
CVE-2006-0003 - MDAC
PDF: printf(), collectEmailInfo(), getIcon()
CVE-2008-0015 - MsVidCtl Overflow
Aolwinamp: IWinAmpActiveX.ConvertFile - Info here and here
CVE-2008-2463 - MSOfficeSnapshotViewer
CVE-2005-2127 - COMObjectInstantiationMemoryCorruption
CVE-2009-1136 - MSOfficeWebComponents - OWC10.Spreadsheet msDataSourceObject
The Fragus Exploit Kit, build with PHP, is available in both English and Russian; the kit is hosted on a Web Server and allows the attacker to choose which exploits to run.
All lead to the same final payload which is then served to the visitor."
___________________________________________________________________________
It is the second attack vector that is more worrying. The viewer doesn't know that their machine has been compromised by a drive-by download unless they have advanced knowledge of computers and networking. You can become infected by visiting legitimate sites that have been breached, clicking ads, or by simply clicking on a shortened url (e.g. bit.ly). And your antivirus won't save you. When TDSS installs, it bypasses behavioral protection by forcing a legitimate service to load a legitimate, but maliciously patched DLL. This is done by modifying the msi.dll file in \knowndlls directory, followed by launching the “Microsoft Installer” service. As well, it recompiles hourly, further confusing antivirus solutions. The only ways to effectively prevent drive-by downloads are to use NoScript, use Sandboxie, or deny execution on the AppData folder (where most malware resides).
It's not as simple as just running an AV and downloading from trusted sites.
* Examples of attack vectors found on Wilders Security Forum from user "Rmus"
#5
Posted 05 July 2012 - 06:08 PM
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
#6
Posted 06 July 2012 - 03:29 AM
ronin7752, on 05 July 2012 - 06:08 PM, said:
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
Conficker infected 1.6 million PCs in Q4 2011 alone. Nobody knows exactly what it does, but it's still very alive.
This post has been edited by Extremist: 06 July 2012 - 03:34 AM
#9
Posted 06 July 2012 - 05:02 PM
ronin7752, on 05 July 2012 - 06:08 PM, said:
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
#10
Posted 06 July 2012 - 05:05 PM
Jameshoqh, on 06 July 2012 - 05:02 PM, said:
ronin7752, on 05 July 2012 - 06:08 PM, said:
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
This one is a bit different. The FBI is running the servers. They caught the crooks, and have continued to run the servers to help the people infected to solve their problems. On Monday, the FBI shuts the server down. If you are infected, you will not have internet access. It is not what might happen, it is what will happen.
#11
Posted 07 July 2012 - 12:30 AM
#12
Posted 07 July 2012 - 10:04 AM
DarkRaptor, on 07 July 2012 - 12:30 AM, said:
Sounds awfully fishy... (fake AV scanner maybe?)
Need a Windows ISO image?
#13
Posted 07 July 2012 - 11:41 AM
ronin7752, on 05 July 2012 - 06:08 PM, said:
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
We had a rogue windows 2k PC on the network that would periodically lock out about 30 passwords for a year. It wasn't until the CEO's new pc was attacked by it that the security guys turned it off permanently.
#15
Posted 07 July 2012 - 11:44 AM
Jameshoqh, on 06 July 2012 - 05:05 PM, said:
Jameshoqh, on 06 July 2012 - 05:02 PM, said:
ronin7752, on 05 July 2012 - 06:08 PM, said:
Seriously, if you know, please tell me, because I looked for the number for weeks after zero-day and couldn't find it. None of the AV companies nor the IT media had anything to report.
Find that odd....?
Always
This one is a bit different. The FBI is running the servers. They caught the crooks, and have continued to run the servers to help the people infected to solve their problems. On Monday, the FBI shuts the server down. If you are infected, you will not have internet access. It is not what might happen, it is what will happen.
3rd party hired by the FBI. Wonder what data they have been collecting for the past 8 months.
#16
Posted 07 July 2012 - 12:00 PM
#17
Posted 07 July 2012 - 03:36 PM
BrandonHope, on 07 July 2012 - 12:00 PM, said:
The problem is that legit sites can get infected, and there are sometimes holes in software that haven't been patched yet. I'm not saying AV is the cure-all solution here. However, it is a good idea, just in case.
Need a Windows ISO image?
#18
Posted 07 July 2012 - 04:16 PM
#19
Posted 07 July 2012 - 04:17 PM
#20
Posted 07 July 2012 - 04:27 PM
AppleDystopia, on 07 July 2012 - 04:16 PM, said:
You can't ping google.com without a working DNS server - it looks it up there, and then gets the IP. If you click on a search result from it, you'll also need DNS. If you're pinging and visiting 74.125.224.68 (that's one of google's IPs) or something, then no, it doesn't matter.
Need a Windows ISO image?
Help













