This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Haxdoor.KI -spam- message

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1642
Last Updated: 2006-08-26 17:24:47 UTC
"F-Secure has updated their description of Haxdoor.KI* to note "The skyinet.info website (located in Russia) that the backdoor connects to, is now offering a URL that points to a file named samki.exe. This file contains a nasty payload that damages Windows beyond repair. This file can be downloaded and launched by a hacker to destroy all infected computers when time comes". . Their original blog alert info is here**."

* http://www.f-secure.com/v-descs/haxdoor_ki.shtml
Updated August 25.

** http://www.f-secure.com/weblog/archives/ar…6.html#00000952

:huh: :ph34r: :ph34r: :ph34r:
FYI…

- http://www.f-secure.com/weblog/archives/ar…6.html#00000982
September 29, 2006
"Haxdoor* rootkit-equipped backdoors are widely used - in the "Rechnungen" and "Räkningen" spam runs in Germany and Sweden for example. These changing Haxdoor variants are generated with a toolkit known as "A-311 Death"… Now, people who use such backdoors quickly collect a lot of information from infected computers. Information such as passwords, credit cards, and bank logons. Some of these attackers filter the logs they collect to find juicy information and then use it themselves. Others grep the data for e-mail addresses (to sell them to spammers) and for credit card numbers and bank logins (to sell them to fraudsters). Then again, others take the easy way out and end up selling the logs as they are, by the megabyte…"
* http://www.f-secure.com/v-descs/haxdoor.shtml
"… Haxdoor is a powerful backdoor with rootkit capabilities. It can hide its presence (processes and files) on an infected system, so it can be only detected by anti-virus programs that use kernel drivers and by rootkit detectors (like our F-Secure BlackLight** for example)…"
** http://www.f-secure.com/blacklight/blacklight.html

.
FYI…

New UrSnif/Haxdoor Variant
- http://isc.sans.org/diary.php?storyid=1782
Last Updated: 2006-10-13 14:53:00 UTC
"A number of readers reported a new variant of "Haxdoor" attachements. As usual, AV will not pick up this new virus for the most part… Ran the attachement through virustotal. Only e-Trust, Ikrasus and Panda picked it up as suspect…"

(Suspect E-mail) partial read:
"Thank you for ordering from our internet shop. If you paid with a credit card,
the charge on your statement will be from name of our shop.
This email is to confirm the receipt of your order. Please do not reply
as this email was sent from our automated confirmation system.
Date : 08 Oct 2006 - 12:40
Order ID : 37679041 …
Your Order Summary located in the attachment file ( self-extracting
archive with "37679041.pdf" file )…"

DELETE THE ENTIRE E-MAIL IF RECEIVED. DO -NOT- ATTEMPT TO OPEN THE ATTACHMENT.

:ph34r: :ph34r: :ph34r:
FYI…

- http://tinyurl.com/yhartc
October 24, 2006
"British electronic-crime detectives are investigating a massive data theft operation that stole sensitive information from 8,500 people in the U.K. and others in some 60 countries, officials said Tuesday. In total, cybercriminals targeted 600 financial companies and banks, according to U.K. authorities, who have worked over the past week to identify and notify victims. Through intelligence sources, U.K. police were given several gigabytes of data – around 130,00 files – that came from a server in the U.S., said Charlie McMurdie, detective chief inspector for the Specialist Crime Directorate e-Crime Unit of the London Metropolitan Police. Most of the data related to financial information, she said. The data was collected by a malicious software program nicknamed Haxdoor that infected victims' computers. Some 2,300 machines were located in the U.K. McMurdie said… Metropolitan police experts built a special program to search through the data and identify victims, she said. The data contained information such as logins and passwords for major Web sites such as eBay Inc., Amazon.com, BT Group PLC and Pipex Internet Ltd., a U.K. Internet service provider…"

:ph34r: