Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-06-2004, 09:28 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Troj_getegold.a

This Trojan, detected as TROJ_GETEGOLD.A, specifically targets users with e-gold accounts. E-gold is an integrated account-based payment system mainly utilized for e-commerce.

This Trojan does not employ usual phishing techniques, like logging user keystrokes in text files that can be sent to a remote malicious user. Instead, whenever a user tries to access the e-gold account login form via the URL http://e-gold.com/acct/login.html, it opens a hidden duplicate Internet Explorer (IE) window accessing that same URL. It then proceeds to fill up the duplicate Web form, which eventually leads to illegal account access.

The Trojan periodically drains the funds of the compromised account by a certain percentage. The stolen funds are then transferred to another e-gold account.

To be able to successfully perform this function, this Trojan uses IE’s built-in Object Linking and Embedding (OLE) automation functions. This method is similar to API hooks used by file-infectors. In this case, this Trojan executes certain functions for every change in the URL address that occurs while the user continues to navigate through the e-gold Web pages.

(Note: Object Linking and Embedding (OLE) is a compound document standard that enables a user to create objects with one application and then link or embed them in another application.)

When the Trojan detects that the user is accessing the following URLs, it continues to execute its routines:

* e-gold.com/acct/acct.asp
* e-gold.com/acct/balance.asp
* e-gold.com/acct/spend.asp
* e-gold.com/acct/verify.asp
* https://www.e-gold.com/acct/acct.asp
* https://www.e-gold.com/acct/balance.asp
* https://www.e-gold.com/acct/spend.asp

The Trojan runs on Windows 95, 98, ME, NT, 2000, and XP.

E-gold account holders are advised to constantly monitor e-gold Security Alerts at the following URL:

http://www.e-gold.com/unsecure/alert.html
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump



All times are GMT -5. The time now is 04:11 AM.


Firefox 2