Blog

Chinese alliance against Google spreading malicious code

02.13.2007 - 11:41 AM
Our "ThreatSeeker" process recently discovered an interesting website that attempts to exploit un-patched Internet Explorer users who have the Chinese language pack installed. Assuming users are not running the latest version of I.E. they will be exploited with code that utilized the MS06-14 "MDAC" vulnerability. Upon visiting the site a Trojan Downloader connects to another site which downloads and installs a file called md5.exe. This file is run as "chenzi.exe". This filename has been used in the past by infected websites within the Chinese domain/IP space and appears to be a password stealing Trojan Horse.

One particularly interesting item is the site the site contents. The site claims to be some sort of anti-Google group. The following information is on their English front page:

---From the site ---

Purpose:

One:Our league is an organization which against www.google.com treat large-scale net friends and the heads of station unfair. The purpose of our league is to collect the unfair proof and supervise google company go to fair.

Two: The league is organize by net friends spontaneous, our league isn't controlled and assisted by any organizaons or companies at home and in abroad.

Three:Ones want to join in our league must obey our country law,illegal,etoticism,virus and so on are prohabitted in our league.

The site is hosted in one of the Chinese .CN sub-domains and is *not* owned by Google, however a simple typo could land one there.

Site Screenshot:

Malicious Code Encoded:

Malicious Code Decoded:

Bookmark This Post:

Post a Comment: