Your ad here
Powered by MaxBlogPress  

Never cease in the fight for peace, justice, and equality for all people. Be persistent in all that you do and don't allow anyone to way you from your conscience.
- Leonard Peltier

filipino-voices
Your ad here

« Take Back the Tech: Web Voyeurism
» Take Back the Tech: Mobile Pornography

Net, Tech, Web, Tech Security

Another SOHANAD worm

11.29.06 | Comment?


If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

I think a new SOHANAD variant is in the wild.

I had received a suspicious message from a friend via YM. Actually I had received several messages, but it contains one link only. Unlike other SOHANAD variants, the link is not disguised as such; the link address is what is stated in the message.

So I tried looking at it, and it was a PHProxy page. But when I viewed its source, it was just just a frameset with two frames, both SRCs are located OUTSIDE the Web site itself. One points to a Vietnamese-like Web site (with a Vietnamese-sounding URL), and another from a Yahoo!-hosted page (no longer available at the moment).

So viewing the Vietnamese-sounding Web site and its source, I am convinced it is a SOHANAD worm. The source contains a VBScript typical of SOHANAD carriers that exploits MS06-014.

Basically what it does is to download a file from the Vietnamese-sounding Web site, save it on your computer, and using the exploit to execute the downloaded file. Voila!

So far, here are the messages that I had received:

Beauty KIDs… http://cso[BLOCKED]2.net
For iTunes hacker, the freedom of the open code … http://cso[BLOCKED]2.net
How Windows XP Wasted $25 Billion of Energy… http://cso[BLOCKED]2.net
Oh my GOD #… http://cso[BLOCKED]2.net

The file to be downloaded is named VNN.EXE.

YM users are advised to be careful when handling links sent via IM, even if it came from your friends. BTW, FireFox users can view the page safely, as it ignores VBScript.

Like my article? Leave a tip! Or, treat me to a cup of coffee!

Visit the AWBHoldings.com Online Store!


If your comment is eaten by Akismet or just went somewhere else, please let me know. You can either leave a message at the chat box at the lower left, or via the contact page. Thanks!

RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Comments will be sent to the moderation queue.


« Take Back the Tech: Web Voyeurism
» Take Back the Tech: Mobile Pornography