{"id":3217,"date":"2010-09-07T13:23:18","date_gmt":"2010-09-07T20:23:18","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=3217"},"modified":"2018-01-30T12:22:21","modified_gmt":"2018-01-30T19:22:21","slug":"fake-flash-update-needs-flash-to-work","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/09\/07\/fake-flash-update-needs-flash-to-work\/","title":{"rendered":"Fake Flash Update Needs Flash to Work"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align: left;\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2002.png\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/09\/07\/fake-flash-update-needs-flash-to-work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Facebook\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2012.png\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;title=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Digg\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2022.png\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;title=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Del.icio.us\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2032.png\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;title=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Stumbleupon\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2042.png\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;title=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Reddit\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2052.png\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;Title=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Blinklist\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2062.png\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Twitter\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2072.png\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Technorati\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2082.png\" \/><\/a><a title=\"Add to Furl\" href=\"http:\/\/www.furl.net\/storeIt.jsp?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;t=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Furl\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2092.png\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F09%2F07%2Ffake-flash-update-needs-flash-to-work&amp;h=Fake%20Flash%20Update%20Needs%20Flash%20to%20Work\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Newsvine\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2102.png\" \/><\/a><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2112.png\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-install_flash_crop.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-3219\" title=\"20100907_noflashflash-install_flash_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-install_flash_crop.jpg\" width=\"390\" height=\"95\" \/><\/a>If you live in the US, you may have played sports, barbequed, or enjoyed the last long weekend of the summer outside doing something fun outdoors. Unfortunately, that wasn&#8217;t an option here in Boulder, where <a href=\"http:\/\/www.dailycamera.com\/fourmile-canyon-fire\/ci_15998749\" target=\"_blank\">a large wildfire<\/a> generated a thick plume of smoke and ash. So, what&#8217;s a malware analyst to do indoors on a beautiful day with toxic smoke outside? Why, spend some quality time with <strong>Koobface<\/strong>, of course.<\/p>\n<p>I took a closer look at the worm&#8217;s behavior and also noted that, since <a href=\"http:\/\/blog.webroot.com\/2010\/09\/02\/pro-israel-website-receives-passwords-stolen-by-koobface\/\" target=\"_blank\">the Migdal keylogger<\/a> site went dark for the Koobface crew, they&#8217;ve switched to using a new domain as the dead drop for credentials stolen by the Koobface password stealer payload: <strong>m24.in<\/strong>, the Web site of some sort of media company based in India. The behavior I saw by the keylogger was virtually identical to that used by the Migdal variant, reported in a previous post. The payload is even named <strong>m24.in.exe<\/strong>, just like the Migdal payload was named after the domain where it posted stolen passwords.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-m24-in_passwords.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3229\" title=\"20100907_noflashflash-m24.in_passwords_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-m24-in_passwords_crop.jpg\" width=\"473\" height=\"33\" \/><\/a><\/p>\n<p>It&#8217;s been a while since the worm changed its primary method of infection: For nearly its entire existence, Koobface has spread by manipulating the social network accounts of infected users so it appears the user posted a link to a video. Of course, <a href=\"http:\/\/blog.webroot.com\/2009\/08\/14\/koobface-not-just-for-facebook-anymore\/\" target=\"_blank\">the worm does the posting<\/a> in the name of the user, and the link points to a page which purports to be some sort of streaming video, but actually pushes the malware on anyone who visits.<\/p>\n<p>And, in order to take on the appearance of a real online video, it uses Flash.<\/p>\n<p><!--more--><br \/>\nThe overall look and feel of the fake video has been static for some time, but <a href=\"http:\/\/blog.webroot.com\/2010\/01\/20\/spongeface-koobface-variant-uses-spongebob-as-a-tease\/\" target=\"_blank\">the content<\/a> changes periodically, and the current iteration of the page (which <a href=\"http:\/\/blog.eset.com\/2010\/04\/07\/massive-new-koobface-campaign\" target=\"_blank\">appeared this past April<\/a>), titled &#8220;Video posted by &#8230; Hidden Camera,&#8221; is still in use and hasn&#8217;t been updated since then.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-with_flash.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-3221\" title=\"20100907_noflashflash-with_flash\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-with_flash.jpg?w=300\" width=\"300\" height=\"179\" \/><\/a><\/p>\n<p>On the video page, a user is encouraged to download and install a file the page claims is <strong><em>Flash Player 10.37<\/em><\/strong> &#8212; never mind that Adobe only recently updated Flash to version 10.1 &#8212; which happens to be the main Koobface installer. What I didn&#8217;t really pay attention to, until this weekend at least, is the fact that the video page actually requires the user to have a previous installation of Adobe Flash installed, otherwise the scam doesn&#8217;t work. Talk about stupid malware tricks. Here&#8217;s what you see on a test machine with no Flash installed:<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-install_flash.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3226\" title=\"20100907_noflashflash-activex-warning\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-activex-warning.jpg\" width=\"554\" height=\"195\" \/><\/a><\/p>\n<p>Note in the screen above that Internet Explorer threw a warning into both the frame on the page where the video appears, and at the top of the page, prompting the user to install Flash.<\/p>\n<p>The video window that appears, which has all the appearance of an interactive Web page coded in Ajax, is actually itself a Flash .SWF file, playing within a frame in the page. And the Flash video is scripted in such a way that, whenever a user even mouses over the &#8220;video&#8221; it attempts to force the visitor&#8217;s browser to download the Koobface installer, which is typically called &#8220;setup.exe&#8221; or something equally generic.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-download.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3225\" title=\"20100907_noflashflash-download_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-download_crop.jpg\" width=\"487\" height=\"253\" \/><\/a><\/p>\n<p>So this Flash video that runs is actually a video of a fake Flash update prompt, embedded within a fake video page. If you don&#8217;t have Flash installed, you have to install Flash before you can be prompted to install (what you are told is) Flash.<\/p>\n<p>It&#8217;s too bad the double-fakery doesn&#8217;t simply negate the damage caused by the worm. Here are just a few of the payloads it downloads during the course of its infection:<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-ikoobface-payloads-2x.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3230\" title=\"20100907_noflashflash-ikoobface-payloads-2x\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/09\/20100907_noflashflash-ikoobface-payloads-2x.jpg\" width=\"212\" height=\"170\" \/><\/a><\/p>\n<p>Koobface still installs a backdoor on infected computers (with <strong>p.exe<\/strong>), opens ports in the firewall, <a href=\"http:\/\/blog.webroot.com\/2009\/09\/03\/koobfox-variant-digs-for-firefox-cookies\/\" target=\"_blank\">pulls cookie data from Firefox<\/a> (using <strong>ff2ie.exe<\/strong>), and steals FTP credentials (using <strong>m24.in.exe<\/strong>). Once installed, the worm receives commands, including instructions to open browser windows to fake &#8220;antivirus scan&#8221; pages, which can lead to more infections. Fortunately, due to either the laziness or ineptitude of Koobface&#8217;s creator(s), we can still easily detect and remove the worm from infected computers.<br \/>\n<a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\"><img decoding=\"async\" alt=\"wordpress blog stats\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you live in the US, you may have played sports, barbequed, or enjoyed the last long weekend of the summer outside doing something fun outdoors. Unfortunately, that wasn&#8217;t an option here in Boulder, where a large wildfire generated a thick plume of smoke and ash. So, what&#8217;s a malware analyst to do indoors on [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4263,4849,7551,4999,7935,7733,7941,7943,4295,7939,4291,6619,7937,3477,3919,4611,3471,4071,3833,4183],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3217"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=3217"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3217\/revisions"}],"predecessor-version":[{"id":23694,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3217\/revisions\/23694"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=3217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=3217"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=3217"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=3217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}