Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection

Reply
 
LinkBack Thread Tools Display Modes
Old 08-15-2007, 04:28 PM   #1 (permalink)
Osiris
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 23,015
Default Webmail-creating Trojan targets Gmail

A strain of malware capable of setting up bogus Hotmail and Yahoo! accounts in order to send spam has been adapted to also target Gmail accounts.
The HotLan Trojan creates automatically-generated webmail accounts, implying that spammers have discovered a means to defeat Captcha challenge-response systems. Captcha systems, which typically prevent accounts being created until a user correctly identifies letters depicted in an image, are designed to ensure requests are made by a human rather than an automated program.
document.write('\x3Cscript src="http://ad.uk.doubleclick.net/adj/reg.security.4159/spyware;'+RegExCats+GetVCs()+'pid='+RegId+';'+RegK W+'maid='+maid+';test='+test+';pf='+RegPF+';dcove= d;sz=336x280;tile=3;ord=' + rand + '?" type="text/javascript">\x3C\/script>');
Since the arrival of the first variant of the Trojan last month, more than 500,000 spam email accounts have been created, according to Romanian anti-virus firm BitDefender. A joint effort between the security teams of BitDefender and Yahoo! appears to have stymied attempts to generate and use Yahoo! accounts to send spam.
However, this has pushed the problem onto Hotmail and Gmail (a new target of a latter variant of the Trojan) rather than having the desired effect of bringing the creation of bogus accounts under control.
The use of compromised PCs to send spam has been going on for years. The HotLan Trojan follows a more complex routine. Each active copy of the Trojan attempts to set up a webmail account, sending off the captcha image in an encrypted form to a spammer-controlled website. Servers behind this site process the image and extract the solution to the captcha challenge, which is then posted in the appropriate field.
Once a webmail account is established, encrypted spam emails are sent from a website onto infected machines. The HotLan Trojan then decrypts these junk emails and sends them to (presumably valid) addresses taken from yet another website.
Junk mail sent using the malware have largely been used to spamvertise pharmacy sites. Multiple bogus accounts are created from each infected machine. The Trojan itself is not widespread, indicating a possible desire by its authors to keep a low profile, even though its effects on Hotmail (in particular) are serious.
"There were 514,000 Hotmail accounts created [by the Trojan], as well as about 49,000 at Google," said Viorel Canja, head of BitDefender Anti-Virus Lab. "However, it is worth noting that while most of the Hotmail accounts are operational, Gmail accounts get blocked pretty fast, usually about a couple of days after being created."

Webmail-creating Trojan targets Gmail | The Register
Osiris is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hotlan Trojan Focuses on Hotmail, Gmail Osiris Virus - Spyware Protection / Detection 0 08-11-2007 06:31 PM
Trojan creates bogus webmail accounts to punt drugs Osiris Virus - Spyware Protection / Detection 3 07-06-2007 07:26 PM


All times are GMT. The time now is 02:21 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC8