FYI…

- http://isc.sans.org/diary.php?date=2005-05-05
Updated May 5th 2005 23:34 UTC
"…Here's a write-up of what we found, to sharpen your malware survivor senses…

Exploit #1 - Java Classloader Vulnerability …

Exploit #2 - IE Vulnerabilities …

Exploit #3 - More Internet Explorer Vulnerabilities …

The payload
At the time of writing, update.exe is not yet recognized by any of the Antivirus softwares we could test it with. The file is packed with FSG, and after unpacking almost 400kB of size. Lots of nasty things can be done in 400k of code… What we know so far from analyzing the binary, it contains a component used to gather information on the system and to submit this bounty via HTTP POST to a webserver in Europe. It also installs a multifunctional proxy (HTTP/Socks/POP3/etc). What else it does we dont know yet.
Update 2015 UTC: McAfee/NAI have dubbed this file "Backdoor-CRR".

Thanks to a hosting provider who very quickly and competently responded to our report of the malicious site, the site hosting this flurry of exploits is no more. But the web servers in Europe to which update.exe is reporting information on infected hosts are still up…"


(If you need more detail, use the URL link above.)


:blink: :ph34r: