Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Air France Flight 447 Catastrophe Being Used to Drop Malware
Search Topic:
Uniqs:
580
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
100,000 Websites Destroyed by Hackers - 0 Day Vulnerability »
« Microsoft's new Bing search hijacks Google toolbar in IE6  
AuthorAll Replies


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub

Air France Flight 447 Catastrophe Being Used to Drop Malware

PC1 News | 2009-06-05

Without a doubt, the terrifying catastrophe of Air France Flight 447 has been among the top news headlines throughout the world. And even though the tragedy has not yet been resolved and many questions are left unanswered, cyber criminals are successfully using this issue in their malicious schemes. This time they are exploiting users' curiosity to find more information about the tragedy on search engines. Watch out because cyber criminals will use this opportunity to drop TROJ_YEKTEL.AA onto your PC then an installation prompt will be displayed for the fake Personal Antivirus.

How does the whole malicious attack take place? And what should you be aware of? Just imagine, you go to google.com and enter certain keywords related to the Air France Flight 447 crash, just to find some new useful information. You do nothing wrong - you don't open any unknown attachment or read suspicious messages. But even in this case cyber criminals can trick you. Through the use of a SEO (search engine optimization) poisoning attack, searches for crash related information can lead you to links that when opened can navigate you to various suspicious sites. This attack ultimately ends in the download of rogue antivirus software.

This fake antivirus software is downloaded by the executable file called Install_2022.exe. The malicious executable is also detected as TROJ_FAKEAV.BIM and has no other known alias names. When executed, TROJ_FAKEAV.BIM connects to a certain URL, downloads a file and renames it when stored in the affected system. The downloaded file is saved as TROJ_YEKTEL.AA.

When executed, TROJ_YEKTEL.AA - also known as TrojanDownloader:Win32/Yektel.A, Generic Downloader.z, Packed.Generic.187 - prompts potential victims to download a purportedly necessary antivirus software called Personal Antivirus. As is the case with a majority of rogue software, as soon as you install this program, a message about the whole bunch of supposedly detected malware will be displayed. Keep in mind that all this malware is fake and the only aim of hackers in this case is to scare unaware users into purchasing a copy of the full version of Personal Antivirus.

Therefore, stay extremely alert if you don't want your computer to be infected with malware and fake antivirus software. Always remember that the most recent important worldwide news - both tragedies and happy events - attract not only yours but cyber criminals' attention as well. The more serious and important the news event, the more chances it will be used by hackers for malicious activities.
Source: »www.pc1news.com/news/0701/troj-y···rus.html

See also: »blog.trendmicro.com/search-resul···tivirus/
--
Smokey's Security Forums »www.smokey-services.eu/forums/
Smokey's Security Weblog »smokeys.wordpress.com/
Site Member ASAP - Alliance of Security Analysis Professionals


siljaline
mind that delimiter
Premium
join:2002-10-12
Montreal, QC
  Thanks Smokey, posted elsewhere to those that need to know - thanks for this !


jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
reply to Smokey Bear
That's really sick. To use something of this magnitude for dropping a trojan is just sick.!


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
To these criminals it is business as usual.


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

reply to jaykaykay
Whatever the topic of the day is means nothing to these scum other then an increased chance that you will fall victim to one of their schemes, its purely business to them.

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool


Its a Secret
Whatever
Premium
join:2008-02-23
U B Funny
 reply to Smokey Bear
Sadly, this tactic is nothing new, and happens with every major disaster. Next up are the 419ers'...


MrBrightSide

@inet.fi

reply to Smokey Bear
While the malware authors are shameless and ruthless as usual.. I see a small bright side to this Fake Antivirus trend. Now it is easier than maybe ever before to notice you are infected, when the bad guys literally throw it in your face with fake antivirus prompts that fill the whole damn screen. I'd much rather have loud fake antivirus infections than stealthy silent rootkits that hide in the background stealin' all your passwords without advertising their presence to you.


shearer
Northern Lights
Premium
join:2002-06-18
Toronto, ON
clubs:


1 edit
said by MrBrightSide :

I'd much rather have loud fake antivirus infections than stealthy silent rootkits that hide in the background stealin' all your passwords without advertising their presence to you.
Agree 101%.
Silent ones are scary - I managed to get one on my system & didn't notice anything until on one free day I fired up TCPview to watch local TCP traffic for fun. Detected a strange PID trying to call home and immediately restored from a clean image.
-
Forums » Up and Running » Security » Security100,000 Websites Destroyed by Hackers - 0 Day Vulnerability »
« Microsoft's new Bing search hijacks Google toolbar in IE6  


Wednesday, 09-Dec 07:38:57 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [194] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [52] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [50] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [21] AT&T Releases Network Reporting iPhone App
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Comcast refused to install 400' feet. [Comcast HSI]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· ICC Strats??? [World of Warcraft]
· Extjs grid combo box. [Webmasters and Developers]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· CRTC Response to ME: You will be Band F FOREVER!!! [TekSavvy]
· SB6120 Firmware update [Comcast HSI]