Sponsored by..

Thursday, 13 March 2008

Very authentic looking Hallmark ecard trojan

A very authentic (but fake) trojan was send out overnight purporting to be from Hallmark.com


A Friend has sent you a Hallmark E-Card.

If you recognize this name, click the link to see your E-Card.
http://www.hallmark.com/ECardWeb/ECV.jsp?a=[snip]


If this name is not familiar to you and you're concerned about online security, please use the following steps:

1. Visit http://www.hallmark.com/getecard
2. Enter your e-mail address in the Original Recipient.s E-Mail Address box.
3. Enter EG0694262772475 in the Confirmation Number box.
4. Click Display Greeting.

Want to send an E-Card too ? Visit www.hallmark.com/ecards



To view Hallmark’s privacy policy or for questions, visit www.hallmark.com, and click the links at the bottom of the page.


The displayed links are all safe, however the FIRST link actually points to hxxp:||pop.ayudaenaccion.org.sv|card.exe



VirusTotal detection is not bad.

Files loaded are as follows:
%systemroot%\system32\nicks.txt
%systemroot%\system32\remote.ini
%systemroot%\system32\script.ini
%systemroot%\system32\servers.ini
%systemroot%\system32\sup.bat
%systemroot%\system32\sup.reg
%systemroot%\system32\users.ini
%systemroot%\system32\aliases.ini
%systemroot%\system32\control.ini
%systemroot%\system32\explorer.exe
%systemroot%\system32\mirc.ico
%systemroot%\system32\mirc.ini


Payload is Zapchast, basically it tries to join the machine to an IRC controlled botnet.

Added:
The remote.ini it drops onto your machine has some interesting host names you might want to block and/or investigate:

[users]
n0=100:*!*@lamerzkiller.users.undernet.org
n1=100:*!*@209.43.75.13
n2=100:*!*@estranho-colo.iquest.net
n3=100:*!*@OMGyouSUCK.users.undernet.org
n4=100:*!*@CoReCt.users.undernet.org
n5=100:*!*@hxr.users.undernet.org
n6=100:*!*@BebiDeea.users.undernet.org
n7=100:*!*@asdz.users.undernet.org
n8=100:*!*@ZmAu.users.undernet.org
n9=100:*!*@ReKt.users.undernet.org
n10=100:*!*@BebeDulce.users.undernet.org
n11=100:*!*@ReCt.users.undernet.org
n12=100:*!*@hacler.ro
[variables]
n0=%HAck1 #GangstaRap | #:">
n1=%console
n2=%utime 1205420752
n3=/away :sã îmi suge-ti cuca zdrentzelor !
n4=%ochan #GangstaRap | #:">

1 comment:

Carmen said...

I inadvertently downloaded a similar thing disguised as a hallmark card. The stupid thing is that it didn't get me to the website - but instead asked me to download a file - I stupidly downloaded it.

It shows up as a program in my program list - but when I try to Add/Remove - it won't delete all the files.

I run Norton 360 I'm having it do a scan now - do you think that will get at it?