/?pid=313

Updated:06:27 PM EST Jan 12


this is ggmania.com subsite Trojan horse? Researchers warn of Trojan hearse - TechAmok

Trojan horse? Researchers warn of Trojan hearse - [security]
06:23 PM EST - Mar,21 2006 - post a comment

Security researchers at Sana Security Inc. are warning of a new type of malicious software designed to steal usernames and passwords from Web surfers. The malware, dubbed "rootkit.hearse," uses rootkit cloaking techniques, making it extremely difficult to detect. In order to steal information, however, the software must first be downloaded onto a user's system. This can be done by tricking the user into downloading the malicious code, or by infecting a computer with some other form of malware. Once installed, it sends the sensitive information to a server in Russia that appears to have been in operation since March 16, Sana said.

The software has two components: a Trojan horse application that communicates with the Russian server, and rootkit software that cloaks the malicious software from system tools and antivirus programs. Sana has observed the software being downloaded in conjunction with the Win32.Alcra worm. Rootkit.hearse uses the same kind of cloaking techniques made infamous by Sony BMG Music Entertainment's XCP (Extended Copy Protection) rootkit software, according to Sana Chief Technology Officer Vlad Gorelik.
This Trojan and rootkit was found during the investigation of an in-the-wild worm, named Win32.Alcra. This worm, if not stopped, attempted to contact various websites and download additional payloads. On one of these websites was the installer for this rootkit and Trojan. Once these components were silently installed on a machine, the Trojan invisibly starts communicating to yet another web server located in Russia. This web server acts as the repository for the stolen usernames and passwords.

One of the sites is still actively infecting machines. It attempts to download several pieces of Spyware, Adware, and Trojans, in addition to the rootkit. The rootkit has two pieces: the first piece is a device driver named 'zopenssld.sys', and a DLL named 'zopenssl.dll'. The device driver appears to cloak any file named 'zopenssld.sys' or 'zopenssl.dll' regardless of where they reside, though the malicious versions are located in the System32 folder.

While the DLL was invisible on the file system, it is visible as an injected DLL in many running processes. Since zopenssl.dll registers itself as a Winlogon.exe extension and does not run as a process, most users would never see it, and it can survive even in safe mode.

The Trojan appears not to be active at all times, but it does wake up and start communicating when it sees a user browsing to a website that requires authentication. To view it in action, a virtual machine was infected with the rootkit and Trojan, and then the user browsed to http://bankofamerica.com, and entered a fake username and password. All of the network traffic was recorded, and after ending the web browser session, the Trojan communication became apparent.


Add your comment (free registrationrequired)

Short overview of recent news articles

Jan,12 2026 Lee Cronin's The Mummy - Official Teaser Trailer (2026) Jack
Jan,12 2026 Ferrari SF90 XX v Xiaomi SU7 Ultra: DRAG RACE
Jan,10 2026 Welcome to the Wasteland - Fallout (American TV series) fan video
Jan,09 2026 GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell
Jan,07 2026 NVIDIA Releases GeForce 591.74 WHQL Drivers with DLSS 4.5 Support
Jan,07 2026 Predator: Badlands Exclusive Deleted Scene (2025)
Jan,06 2026 Greenland 2: Migration - Official Trailer 3 (2026) Gerard Butler,
Jan,05 2026 The Best Laptops of 2025 - For Gaming, Creators & Students!
Jan,05 2026 Punkt Updates its Privacy-Focused Smartphone
Jan,05 2026 Clicks Launches New Ways to Add a Physical Keyboard to Your Life
Jan,05 2026 Building a PC for the First Time
Jan,03 2026 Building a PC in 2026
Jan,02 2026 I want this phone so bad... - Samsung Galaxy Z TriFold
Jan,02 2026 The Real Finewine Strikes Again: Ryzen 5600X, 5700X & 5800XT Revisit
Jan,02 2026 Nokia N8 Symbian Re-Awakened With Passion
Jan,02 2026 Europe Forces Apple to Open up More of iOS
Jan,02 2026 Must have Privacy and Security Tweaks: 2026 Edition
Jan,01 2026 How Did RAM Get So Expensive?!
Dec,31 2025 GeForce RTX 5090 prices to soar to $5,000 as NVIDIA and AMD prep GPU
Dec,30 2025 Hacker arrested for KMSAuto malware campaign with 2.8 million
Dec,29 2025 Killer Whale - Official Trailer (2026) Virginia Gardner, Mel
Dec,28 2025 NVIDIA Showed Me Their Supercomputer
Dec,28 2025 2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait?
Dec,27 2025 Disable this Windows Feature that Secretly Eats Up RAM!
Dec,27 2025 New Windows 11 vs Old Malware: Will it survive?
Dec,27 2025 Samsung TriFold Durability Test: We found the limit
Dec,26 2025 TRUST WALLET CONFIRMS SECURITY BREACH
Dec,26 2025 Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price
Dec,25 2025 Merry Christmas Gaming Insanity
Dec,24 2025 Battlefield 6 - Official PS5 Features Trailer
Dec,24 2025 NVIDIA GeForce Hotfix Driver 591.67 Released
Dec,23 2025 Finally! A Battery That's Better Than Energizer and Duracell!
Dec,22 2025 NVIDIA Killing Cheap 16GB Local AI GPUs?
Dec,21 2025 Top 10 Movie Sequels of All Time
Dec,21 2025 He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez,
Dec,20 2025 Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World
Dec,20 2025 9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right
Dec,19 2025 The XG27AQWMG Sets a New Standard for 1440p OLED
Dec,19 2025 OnePlus 15R Boasts Huge 7,400 mAh Battery
Dec,19 2025 Motorola Refreshes moto g power for 2026
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs