FYI…

- http://preview.tinyurl.com/35tps9
January 14, 2008 (Symantec Security Response Weblog) - "…Trojan downloads a configuration file that contains the domain names of over 400 banks. Not only are the usual large American banks targeted but banks in many other countries are also targeted, including France, Spain, Ireland, the UK, Finland, Turkey—the list goes on. The ability of this Trojan to perform man-in-the-middle attacks on valid transactions is what is most worrying. The Trojan can intercept transactions that require two-factor authentication. It can then silently change the user-entered destination bank account details to the attacker's account details instead. Of course the Trojan ensures that the user does not notice this change by presenting the user with the details they expect to see, while all the time sending the bank the attacker's details instead. Since the user doesn’t notice anything wrong with the transaction, they will enter the second authentication password, in effect handing over their money to the attackers… The configuration files for this Trojan currently contain over 200kb of data; however, new URLs and HTML are being added to the configuration files on a daily basis… We are currently monitoring all of the updates to this Trojan. The Trojan accesses the following URLs for configuration, updates, and to send stolen data:
• iloveie.info
• webcounterstat.info
• microcbs.com
• reservaza.com
• screensaversfor-fun.com
• mystabcounter.info
• [removed]
The Trojan also downloads a copy of Trojan.Flush.J, which changes the users DNS settings to the following attacker settings:
• [removed]
• [removed]
For protection, please keep your antivirus definitions up to date and block the above addresses at the firewall…"

:ph34r: