BBB goes IRS (IRS malware ? ...)
Last Updated: 2007-05-30 15:55:28 UTC ~ "Just a quick heads-up - the Better Business Bureau (BBB) malware we've reported on earlier* seems to have mutated into one that claims to come form the Internal Revenue Service (IRS). Still using RTF attachments with embedded malware as vector, though."
Google Counter ...isn't
z-014-1.php contains an obfuscated exploit for MS06-014
z-014-3.php contains another exploit for MS06-014
z-create-o.php contains the IE CreateObject exploit (as seen on Metasploit TV)
z-cs-an.php is an obfuscated exploit for MS07-017
z-java1.php is an oldie, Java-ByteVerify exploit
All of these try to download and run a file "down.exe" off the same site, which in turn downloads and runs a Browser Helper Object (BHO) off someplace else. The BHO is a key logger / banking trojan. We have decoded the configuration file that tells the trojan what to do - you can look at the file under http://handlers.sans...-bho-helper.txt . Yes, lots of banks... Caution: The google-counter site is still live at the time of writing. Sink yourself at your own risk."
Edited by apluswebmaster, 30 May 2007 - 01:12 PM.