Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 3rd, 2009, 12:06 PM
Carl Farrington Carl Farrington is offline
Regular Poster
 
Join Date: Jun 2004
Location: Manchester, England, U.K.
Posts: 57
Default Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Curious one this. The infected computer works fine, however banking websites, which show the correct url and whose certificates appear fine, have an additional textbox asking for the full security phrase, instead of just various digits from the security phrase.
I tried Lloyds, Rbsdigital.com and Hsbc personal banking, all showed these symptoms. DNS resolution of the sites appear correct.

Has anybody seen this before? I have the files in a password protected 7z archive.


Here's the analysis results for one of the .dlls, called through Run -> rundll32. Doesn't look good for detection rates.
~All Virus Total links removed per Policy.~


Here are the results for twext.exe, which I've come across many times before. Called through Winlogon -> Userinit.
~Snip~

c:\windows\system32\a.exe , doesn't appear to be called from anywhere that I've noticed yet, but obviously suspect filename and file date:
~Snip~

c:\windows\system32\userinit32.exe , called via addition to Winlogon > Userinit, hidden from Windows API and only visable with icesword, but registry modification was re-creating itself after removal. File timestamp on this one is 2004-08-11 , same as most stock XP files.
~Snip~
Microsoft Antivirus (whatever that is) misses this one.

c:\windows\usebexuyiruburu.dll - can't remember where this was called from. Think it was HKCU -> Run, whereas others were HKLM -> Run
~Snip~
Again Microsoft Antivirus does well while nearly all the other 38 antivirus programs fail.

NOD doesn't find a thing.

Is it time to switch to Microsoft Antivirus?

One of the staff at the client has convinced the infected chap that "Spybot would have found that", and that I should have run Spybot. (I take that to be Spybot S&D) I used icesword, gmer, hijackthis and virustotal.com. He'll probably run Spybot S&D, find a couple of tracking cookies and tell me he told me so!

I have nothing against Spybot S&D but it's long winded and unlikely to be of much use against rootkits and things that generally put themselves back in place as soon as they/their registry keys are removed.

Last edited by ronjor : April 3rd, 2009 at 01:00 PM. Reason: Remove Virus Total links
  #2  
Old April 3rd, 2009, 01:23 PM
Carl Farrington Carl Farrington is offline
Regular Poster
 
Join Date: Jun 2004
Location: Manchester, England, U.K.
Posts: 57
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

I'm unable to edit the above post since it was moderated.
The purpose of the virustotal links was to get across the mesage that on average nearly 92% of the tested antivirus packages do not detect these files, so instead I'll give the statistics for each file and the virus names that were given, but without naming any antivirus products.

All stats are from VT.com:

First .dll file, ijowavate.dll, recognised by 2/40 scanners (5%). Recognised as: "Trojan:Win32/Hiloti.gen!A" and "High Risk Fraudulent Security Program"

twext.exe, not to be confused with twext.dll (legitimate WinXP file), recognised by 4/40 scanners (10%). Recognised as: "Gen:Trojan.Heur.Dropper.B0F7080808" and "VirTool:Win32/Obfuscator.ES" and "Email-Worm.Win32.Waledac.Gen (v)"

a.exe, same file as twext.exe above.

userinit32.exe, recognised by 5/39 scanners (12.82%). Recognised as:
"TR/Dropper.Gen" and "Gen:Trojan.Heur.Dropper.41629D9D9D" and "Trojan.Win32.Nodef.fga"

usebexuyiruburu.dll, recognised by 2/40 scanners (5%). Recognised as:
"Suspicious File" and "Trojan:Win32/Hiloti.gen!A" (same as first file, but different MD5 hash and only one product recognised it as the same thing).
  #3  
Old April 3rd, 2009, 02:03 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Is Microsoft Antivirus an infector or a deinfector?
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #4  
Old April 3rd, 2009, 03:32 PM
Carl Farrington Carl Farrington is offline
Regular Poster
 
Join Date: Jun 2004
Location: Manchester, England, U.K.
Posts: 57
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Is it not alarming to people how this is apparently modifying banking pages in-line ? It's got me concerned!
  #5  
Old April 3rd, 2009, 04:02 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Quote:
Microsoft Antivirus (whatever that is) misses this one.
My point is, This Product doesn't exist as a valid tool in name.
Microsoft Antivirus and Win Antivirus were/are malware, no?

After discovering the sleight, How did you determine what files were a threat?
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #6  
Old April 3rd, 2009, 05:54 PM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,856
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Not to throw fuel on the fire, but have you been using Ultrasurf ?
  #7  
Old April 3rd, 2009, 05:56 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,410
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Quote:
Originally Posted by Searching_ _ _
My point is, This Product doesn't exist as a valid tool in name.
Microsoft Antivirus and Win Antivirus were/are malware, no?
Searching_ _ _, the Microsoft engine that VirusTotal uses is actually Windows Defender. VT just states Microsoft under AVs.

@Carl Farrington,
Malwarebytes Anti-Malware would eradicate Trojan.Hiloti, Trojan.Waledac and Trojan.Dropper. Because of the severe infection, the MBAM scan probably needs to run in Safe Mode.

I don't think too many Wilders members would be alarmed at the sight of these Trojans when most of us have seen far worse.
  #8  
Old April 4th, 2009, 04:41 AM
Carl Farrington Carl Farrington is offline
Regular Poster
 
Join Date: Jun 2004
Location: Manchester, England, U.K.
Posts: 57
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Quote:
Originally Posted by Searching_ _ _
My point is, This Product doesn't exist as a valid tool in name.
Microsoft Antivirus and Win Antivirus were/are malware, no?

After discovering the sleight, How did you determine what files were a threat?

Kind of figured that it would be Onecare or whatever MIcrosoft currently offers.

I determined they were a threat due to how they were called, e.g. additions to Userinit under Winlogon, HKLM...>RUN>"asedalsedakl" (random characters etc.), and the fact that they were hidden from the Windows API, and the fact that both the symptoms disappeared after their removal, and the re-instigation of the bad registry keys stopped happening after others were removed.
  #9  
Old April 4th, 2009, 04:41 AM
Carl Farrington Carl Farrington is offline
Regular Poster
 
Join Date: Jun 2004
Location: Manchester, England, U.K.
Posts: 57
Default Re: Curious phishing/rootkit modifies banking webpages in-line, requesting full password.

Quote:
Originally Posted by Fly
Not to throw fuel on the fire, but have you been using Ultrasurf ?

It was a customer's computer, but I'm fairly sure the answer is no.

Last edited by Carl Farrington : April 4th, 2009 at 04:47 AM.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:40 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums