Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 10-27-2007, 05:18 AM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
A Monster Trojan

A Monster Trojan
<p>Yesterday, we analyzed a sample of a new Trojan, called <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-081617-4608-99">Infostealer.Monstres</a>, which was attempting to access the online recruitment Web site, Monster.com. It was also uploading data to a remote server. When we accessed this remote server, we found over 1.6 million entries with personal information belonging to several hundred thousand people. We were very surprised that this low profile Trojan could have attacked so many people, so we decided to investigate how the data could have been obtained.</p>

<p>Interestingly, only connections to the hiring.monster.com and recruiter.monster.com subdomains were being made. These subdomains belong to the “Monster for employers” only site, the section used by recruiters and human resources personnel to search for potential candidates, post jobs to Monster, <em>et cetera</em>. This site requires recruiters to log in to view information on candidates.</p>

<p>Upon further investigation, the Trojan appears to be using the (probably stolen) credentials of a number of recruiters to login to the Web site and perform searches for resumes of candidates located in certain countries or working in certain fields. The Trojan sends HTTP commands to the Monster.com Web site to navigate to the Managed Folders section. It then parses the output from a pop-up window containing the profiles of the candidates that match this recruiter’s saved searches.</p>

<p><a href="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/08/recruiter_monster_com_lg.html" onclick="window.open('http://www.symantec.com/enterprise/security_response/weblog/upload/2007/08/recruiter_monster_com_lg.html','popup','width=800, height=526,scrollbars=no,resizable=no,toolbar=no,d irectories=no,location=no,menubar=no,status=no,lef t=0,top=0'); return false"><img alt="recruiter_monster_com_sm.jpg" src="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/08/recruiter_monster_com_sm.jpg" width="350" height="261" /></a><br />
<strong>Click image to view larger version</strong></p>

<p>The personal details of those candidates, such as name, surname, email address, country, home address, work/mobile/home phone numbers and resume ID, are then uploaded to a remote server under the control of the attackers. </p>

<p>This remote server held over 1.6 million entries with personal information belonging to several hundred thousands candidates, mainly based in the US, who had posted their resumes to the Monster.com Web site. </p>

<p>Such a large database of highly personal information is a spammer’s dream. In fact, we found the Trojan can be instructed to send spam email using a mail template downloadable from the command & control server.</p>

<p>The main file used by Infostealer.Monstres, ntos.exe, is also commonly used by <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-071711-3132-99">Trojan.Gpcoder.E</a>, and both also have a similar icon for the executable file that reproduces the Monster.com company logo—hardly a coincidence.</p>

<p>Furthermore, Trojan.Gpcoder.E has reportedly been spammed in Monster.com phishing emails. These emails were very realistic, containing personal information of the victims. They requested that the recipient download a Monster Job Seeker Tool, which in fact was a copy of Trojan.Gpcoder.E. This Trojan will encrypt files in the affected computer and leaves a text file requesting money to be paid to the attackers in order to decrypt the files. The code for Gpcoder is rather similar to that of Monstres, which may indicate the same hacker group is behind both Trojans.</p>

<p>We have informed Monster.com of the compromised Recruiter accounts so they can be disabled. To protect your identity when using recruitment sites, or at least limit your exposure to identity theft, you should limit the contact information you post on these sites, use a separate disposable email address and never disclose sensitive details such as your Social Security number, passport or driver’s license numbers, bank account information, etc to prospective employers until you have established they are legitimate.</p>

<p>I would like to thank Hazel, one of our very patient colleagues in the HR department, for assisting us during this investigation.</p>
http://www.symantec.com/enterprise/security_response/weblog/2007/08/a_monster_trojan.html
http://www.symantec.com/enterprise/security_response/weblog/2007/08/a_monster_trojan.html
Fri, 17 Aug 2007 14:26:18 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 01:47 PM.


    Firefox 2