/?pid=313

Updated:06:47 PM EDT Apr 24


this is ggmania.com subsite Trojan horse? Researchers warn of Trojan hearse - TechAmok

Trojan horse? Researchers warn of Trojan hearse - [security]
06:23 PM EST - Mar,21 2006 - post a comment

Security researchers at Sana Security Inc. are warning of a new type of malicious software designed to steal usernames and passwords from Web surfers. The malware, dubbed "rootkit.hearse," uses rootkit cloaking techniques, making it extremely difficult to detect. In order to steal information, however, the software must first be downloaded onto a user's system. This can be done by tricking the user into downloading the malicious code, or by infecting a computer with some other form of malware. Once installed, it sends the sensitive information to a server in Russia that appears to have been in operation since March 16, Sana said.

The software has two components: a Trojan horse application that communicates with the Russian server, and rootkit software that cloaks the malicious software from system tools and antivirus programs. Sana has observed the software being downloaded in conjunction with the Win32.Alcra worm. Rootkit.hearse uses the same kind of cloaking techniques made infamous by Sony BMG Music Entertainment's XCP (Extended Copy Protection) rootkit software, according to Sana Chief Technology Officer Vlad Gorelik.
This Trojan and rootkit was found during the investigation of an in-the-wild worm, named Win32.Alcra. This worm, if not stopped, attempted to contact various websites and download additional payloads. On one of these websites was the installer for this rootkit and Trojan. Once these components were silently installed on a machine, the Trojan invisibly starts communicating to yet another web server located in Russia. This web server acts as the repository for the stolen usernames and passwords.

One of the sites is still actively infecting machines. It attempts to download several pieces of Spyware, Adware, and Trojans, in addition to the rootkit. The rootkit has two pieces: the first piece is a device driver named 'zopenssld.sys', and a DLL named 'zopenssl.dll'. The device driver appears to cloak any file named 'zopenssld.sys' or 'zopenssl.dll' regardless of where they reside, though the malicious versions are located in the System32 folder.

While the DLL was invisible on the file system, it is visible as an injected DLL in many running processes. Since zopenssl.dll registers itself as a Winlogon.exe extension and does not run as a process, most users would never see it, and it can survive even in safe mode.

The Trojan appears not to be active at all times, but it does wake up and start communicating when it sees a user browsing to a website that requires authentication. To view it in action, a virtual machine was infected with the rootkit and Trojan, and then the user browsed to http://bankofamerica.com, and entered a fake username and password. All of the network traffic was recorded, and after ending the web browser session, the Trojan communication became apparent.


Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,24 2024 President Biden signs TikTok bill into law
Apr,24 2024 The Humble PC
Apr,24 2024 Researchers have unlocked the 'Holy Grail' of memory technology
Apr,24 2024 The Best Gaming GPU Ever Released, Nvidia GeForce GTX 1080 Ti, 2024
Apr,24 2024 Your Own Private Network Attached Storage Solution by UGREEN
Apr,23 2024 ATLAS | Official Trailer | Netflix
Apr,22 2024 The World's Fastest CPU (Technically...) - Intel i9-14900KS
Apr,22 2024 We can do THIS now! - Lumafield CT Scanner
Apr,21 2024 Huawei Pura 70 Ultra - Apple Should be WORRIED
Apr,21 2024 Sony 2024 TV Lineup Revealed
Apr,20 2024 ICE - A Thousand Suns / Episode 1
Apr,20 2024 Minisforum V3 AMD Tablet Review
Apr,20 2024 AMD & Intel SLASH CPU Prices!
Apr,20 2024 EK is Imploding: Not Paying Employees, Partners, & Suppliers
Apr,20 2024 Backing Up My NAS To My... Parents' House?
Apr,20 2024 NEW Ryzen APU BEATS RTX 40 GPUs!
Apr,20 2024 (Live) Black Tape Project - All New Raw and Uncut - LA Fashion Week
Apr,19 2024 NVIDIA Geforce 552.22 WHQL Driver
Apr,19 2024 You Deserve this much OLED - AORUS CO49DQ
Apr,19 2024 Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC
Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs