
這事件的意義不是要大家注意香港的 垃圾信 ,要建立良好的收信看信習慣:

  1. 盡量少開啟信件預視功能。
  2. 不認識的信盡量不要收下開啟。
  3. 認識的信也要注意,因為可能為假冒信件或是他人已中毒擴散。
  4. 使用信件軟體時盡量建立垃圾郵件排除規則。
  5. 只要是連結,都先盡量不去點選。
  6. 只要是附件,要先確認或掃毒後才能開啟,如非必要也少開啟。


Attack involving .hk domains
Published: 2007-06-16,
Last Updated: 2007-06-16 12:07:05 UTC

by Maarten Van Horenbeeck (Version: 1)
Eric, one of our many valued contributors wrote in yesterday with various spam messages that contained nothing but a short piece of text and a link to a very simple HK domain. Different domains were used in each message.

Subject line: Hello, Pal
Body: look


When investigating this, we noticed that these domains have no less than 10 authorative nameservers. Most interesting is that each of these appear to be located within an ISPs dynamic IP address range. This is naturally highly suspicious. Random querying for A records shows that a large number of other compromised hosts are being used to host the actual website.

On each of these servers, the index.html page contains nastiness:

One piece of obfuscated javascript code, that once decoded appears to exploit a known vulnerability in msdss.dll;
One piece of obfuscated javascript which contains iframe inclusion of three other files, exp1.htm, exp2.htm and exp3.htm and a link to an icon file 123.htm. The three HTM files attempt to exploit three vulnerabilities in Internet Explorer, the 123.htm file in fact turns out to be a malicious ANI file.
A final piece of human readable text that invites a user to click on a link, should the ‘download not start automatically’. Once you click on this link, a file ‘fun.exe’ will be downloaded from this same web server.
The resulting file ‘fun.exe’ appears to be different on each single server. We have currently seen the following SHA1 hashes:


Detection of the code by regular Anti-virus is very spotty, shown by the following output of Virustotal. These were the only solutions that detected malicious code. As you can see, even these are mostly generic detections:

BitDefender 7.2 06.16.2007 GenPack:Trojan.Peed.NG
CAT-QuickHeal 9.00 06.15.2007 (Suspicious) - DNAScan
DrWeb 4.33 06.16.2007 Trojan.Packed.138
eSafe 06.14.2007 Suspicious Trojan/Worm
Fortinet 06.16.2007 suspicious
F-Secure 6.70.13030.0 06.15.2007 Tibs.gen111
Kaspersky 06.16.2007 Email-Worm.Win32.Zhelatin.eu
Norman 5.80.02 06.15.2007 Tibs.gen111
Sophos 4.18.0 06.12.2007 Mal/EncPk-E
Sunbelt 2.2.907.0 06.16.2007 VIPRE.Suspicious
Webwasher-Gateway 6.0.1 06.16.2007 Worm.Win32.Malware.gen (suspicious)

This type of well-prepared and extensive attack is very difficult to shut down, mostly due to the amount of servers and authorities involved. As such, the most effective way of responding would be to have the domain itself taken down. This issue has been reported to the HKCERT as well as the administrators of the .hk TLD. In addition, we’re working with anti virus vendors to improve coverage of both the resulting file and the trojan droppers being used on the malicious site.

Maarten Van Horenbeeck

0619 0931 更新

 SANS Internet Storm Centerは、悪質サイトへのリンクを含んだごく簡単な内容のスパムメールが出回っていると伝えた。メール本文では「Look」(見て)などの一言と、香港ドメインへのリンクのみが記載されている。



 それぞれのサーバには、難読化され見えにくくしたJavaScriptコードなどの不正コードが仕掛けられ、msdss.dllの脆弱性やInternet ExplorerIE)の脆弱性、アニメーションカーソルの脆弱性などが悪用されている。

 これらの攻撃コードは、通常のウイルス対策ソフトでは検出できたりできなかったりと、むらがあるという。SANSでは攻撃に使われているドメイン自体を 無効にするため、HKCERT.hkドメインの管理者に通報するとともに、ウイルス対策ソフトメーカー各社と協力して対応に当たっている。


    創作者 ivan0914 的頭像

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()