12345

3/07/2011

Identified malicious file disguised as an Anti-virus SW for DDoS

1. Introduction

Recently, an erratic malicious file disguised as an Anti-Virus SW for DDoS has been found. This malicious file has been revealed that it doesn't have a function to DDoS attack, however, appearance of malicious file used social engineering technique can cause additional damage related DDoS.

2. Spreading path and symptoms of infection

First of all, recently found malicious file, known as spreading from Korean public web portal and forums, can also be spread as an attachment of e-mail or link in SNS.

 

General user can be seduced with its familiar icon. Furthermore, it was known of using "ALYAC"'s digital signature. Its various variants can be created and spread until now.

With the figure above, it pirated its icon and even set its company name as "Microsoft Corporation".
Upon infected, it will create additional malicious files.



* Generated files

- (Windows system folder)\inpleqlxa.exe (179,181 bytes)
- (User account folder)\Temp\(7~8digits number)_lang.dll (125,570 bytes)

Also, it registered registry value and makes generated files run on booting.

* Generated registry value

- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\its CLSID]
- Value name : "stubpath"
- Value data : (Window System folder)\inldtepix.exe

* (Window System folder) is C:\WINDOWS\SYSTEM on Windows95,98, and ME,

C:\WINNT\SYSTEM32 on Windows2000 and NT, C:\WINDOWS\SYSTEM32 on WindowsXP.

* (User account folder) is C:\Documents and Settings\(User account).

Based on our analysis, this malicious file is expected to steal account information with using keylogging. Detailed analysis is on progress.

3. How to prevent

The most important thing is that user must have a big eye to avoid from malwares.
To use PC safely from security threats of these malicious attachments, we recommend following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) provides diagnosis/treatment function with “nProtect AVS” and runs responding system against various security threats. 

8 comments:

  1. I think that if you look here you will find some interesting info on how to buy essay. You should do it as soon as possible

    ReplyDelete
  2. I will show this post to my friends. They should see this. It's important.

    ReplyDelete
  3. Cleaning cleaning company is one of the biggest problems facing a lot of it, if your cleaning experience is the purchase of detergents that help in cleaning you now have the best detergents in the world against the lowest pricesشركة النجوم لخدمات التنظيف
    شركة كشف تسربات المياه بالرياض
    نصائح للقضاء على الحشرات
    تنظيف السجاد

    ReplyDelete
  4. تقدم شركه الصفرات افضل العماله المدربه ونحن ملتزمون بتقديم ضمان للعميل علي جودة الخدمة المقدمة المتفق عليها مسبقا مع مندوبناونحن فى شركه الصفرات نسعى لتقديم افضل خدمه بأفضل الاسعار على الاطلاق نحن فى شركه الصفرات نهتم بأدق التفاصيل لأداء الخدمه لعملاء الكرام فقط تواصلو معنا نصلكم اينما ىكنتم فى انحاء الرياض

    شركة الصفرات لتنظيف المنازل بالرياض
    شركة الصفرات لعزل الاسطح بالرياض
    شركة الصفرات لتنظيف المجالس بالرياض
    شركة الصفرات لتنظيف السجاد بالرياض
    شركة الصفرات لنقل الاثاث بالرياض
    شركة الصفرات لمكافحة الحشرات بالرياض
    شركة الصفرات لكشف التسربات بالرياض
    شركة الصفرات لتنظيف المسابح بالرياض
    شركة الصفرات لتنظيف الخزانات بالرياض
    شركة الصفرات لتسليك المجاري بالرياض

    ReplyDelete
  5. Custom Article Review Writing Services you secure from the firm are versatile such as Custom Article Review Help and Legitimate Article Review Writing Help and any other form of writing, contact them for assistance.

    ReplyDelete
  6. It is understandable that one is more confident when their task is in the hands of the Professional Essay Writing Help than a novice; thus, one hires Essay Writing Asssignment Help Writer who delivers the ideal Custom Essay Paper.

    ReplyDelete