Subscribe: Subscribe to BigBlueBallRSSSubscribe to BigBlueBall by emailEmailSubscribe to BigBlueBallTwitter


Go Back   BigBlueBall Forums > Site News & Announcements > Instant Messaging News > AIM News
Forgot Password? Register
Connect with Facebook

Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 11-18-2005, 11:11 AM
Jeff's Avatar
Administrator
 

Join Date: Mar 2001
Location: San Clemente, CA, USA
Posts: 9,077
Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)Jeff has left a lasting impression (500)
Send a message via ICQ to Jeff Send a message via AIM to Jeff Send a message via MSN to Jeff Send a message via Yahoo to Jeff Send a message via Skype™ to Jeff
IM RootKit Worm Controlled by Group in Middle East

Experts at FaceTime Security Labs™ , the threat research division of FaceTime Communications, identified and reported a new threat today related to the AOL Instant Messenger (AIM) “RootKit” worm they first identified on October 28, 2005.

FaceTime security researchers confirmed that computers infected with the lockx.exe rootkit file are being further compromised by a group in the Middle East. The attackers have compromised multiple servers hosted by ISPs worldwide to distribute the malware payload. The additional malware includes a “ster.exe” file that contains six additional files to provide the attacker with the capability to upload, download, and monitor the infected host PC. It has also been found that the malware has the potential to steal Microsoft Outlook Express email passwords and log keystrokes. The infected computers can also be used as a platform for launching attacks on Web sites or networks.

Additional Information

  • The lockx.exe rootkit and its variants connect to an IRC server, where it is capable of receiving instructions through private, automated messages from an IRC operator. These messages can open a browser session or install an unwanted application
  • Over 17,000 users were found to be compromised on a single server, and multiple servers exist worldwide
  • Users may receive the instant message text consisting of:
    • “evilday.us/pic####.com”, or
    • “how do I look[ipaddress]/~q8army/pic0023.com” which links them to one of multiple worldwide servers to deliver additional malware
  • Additional malware includes self-extracting zip files including a “Ster.exe” file which utilizes the compromised machine to deliver multiple payloads that:

    • Can steal your browser auto-complete data which may leak confidential personal information
    • Gain access to Microsoft Outlook Express
    • Open browsers to launch a denial of service attack, and/or
    • Download additional malicious applications
“We have delivered detailed research information to the U.S. federal authorities and are fully cooperating with their efforts,” said Kailash Ambwani, president and CEO of FaceTime Communications. “This army of ‘bots could be used for any number of malicious purposes including a denial of service (DoS) attack against targeted Web sites.”

Resources


Last edited by Jeff; 11-18-2005 at 11:14 AM.
Reply With Quote
 

 
  #2 (permalink)  
Old 11-18-2005, 09:09 PM
DragonSlayerz's Avatar
Senior Member
 

Join Date: Sep 2005
Location: Medieval Times
Posts: 335
DragonSlayerz is on a distinguished road (10)
Send a message via AIM to DragonSlayerz Send a message via MSN to DragonSlayerz Send a message via Yahoo to DragonSlayerz
Wow, that's scary. There are to much worms in the the world wide web servers.
Reply With Quote
Reply


Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Topic Starter Forum Replies Last Post
AIM Worm Plays Nasty New Trick Jeff AIM News 0 10-31-2005 11:34 AM
MSN Messenger Hit by Double-Whammy Worm Jeff Windows Live Messenger News 0 02-03-2005 04:16 PM
Mail Worm Dr Kimble Site News & Announcements 1 02-02-2004 02:42 AM

 

All times are GMT -5. The time now is 07:06 PM.