|04 Sep 2010||#1|
Webroot warns on political Koobface data hijack
IT security vendor Webroot says it has discovered a pro-Israeli website apparently receiving passwords stolen by Koobface, the social networking worm that has been around for more than a year.
According to Webroot, Koobface - an anagram of Facebook - has been seen hijacking legitimate websites for more than a year, using them not only to host malicious payload files, but also to work as proxy command-and-control servers for the botnet.
Andrew Brandt, a senior security researcher with the firm, says that one such hijacked Web domain - migdal.org.il - recently popped up in a number of blog posts and on websites which list the domains used to host malware, as far back as this past May, when the Koobface crew began using a slew of new hijacked servers as distribution points for its malicious files.
"And since the summer, Koobface has been delivering a password stealing trojan among the several payloads it brings down to an infected computer", he said in a security blog posting yesterday evening.
The trojan's name, he says, is migdal.org.il.exe, and the stolen passwords it scrapes from infected computers are sent right back to the migdal.org.il web server, which is physically located at an ISP in the UK.
Infosecurity (UK) - Webroot warns on political Koobface data hijack
|My System Specs|
|Similar help and support threads|
Yaa! DLL Hijack Auditor: For Microsoft DLL hijack vulnerability
Not sure if anyone has posted on this tool (or similar tools) yet, but security Exploded makes incredible tools, especially Anti Rootkit tools and Root kit detection tools, so I was happy to learn about this: rmhsCBMIJnA
AT&T warns of coming clamp-down on iPhone data hogs
Users who consume more than their fair share of bandwidth on AT&T's wireless network could have a higher monthly bill in the future, one company executive said Wednesday. Speaking to investors at a UBS conference in New York, Ralph de la Vega, head of consumer services for AT&T, said that the...
© Designer Media Ltd
All times are GMT -5. The time now is 20:53.