Skip to navigation
   
Davey Winder's Blog

Crimeware toolkit targets 10,000 trusted sites

By Davey Winder in Editorial

Posted in Data Protection, Blog, Spyware, Security, Internet on January 15, 2008 at 11:51 am

Permalink | Author Profile

The Finjan Malicious Code Research Center is reporting that a crimeware Trojan named ‘random js toolkit’ is threatening to turn highly trusted websites into lucrative money making traps for the online underworld. It has identified in excess of 10,000 sites in the US which have been infected by the toolkit Trojan in December alone, and the actual figure is likely to be much higher as it is an extremely elusive little bugger which can avoid detection unless some kind of real-time code inspection technology is being used.

The payload, unsurprisingly, is the theft of data from the machines of those unlucky enough to get infected. Data such as documents, passwords, surfing habitats, pretty much anything and everything required to do the identity theft thing.

Finjan has published an in-depth report covering a random js toolkit attack, but the basics are as follows:

The random js attack is performed by dynamic embedding of scripts into a webpage.  It provides a random filename that can only be accessed once.  This dynamic embedding is done in such a selective manner that when a user has received a page with the embedded malicious script once, it will not be referenced again on further requests.  This method prevents detection of the malware in later forensic analysis. random js toolkit is a JavaScript code that is created dynamically and changes every time it is being accessed, making it almost impossible to be detected by traditional signature-based anti-malware products because signaturing dynamic script or exploiting code is not effective. Even keeping an up to date list of very dodgy domains cannot fully protect against such a dynamic exploit. “What’s needed to counter this exploit is dynamic code inspection technology that can detect and block an attack in real time” Yuval Ben-Itzhak, Finjan CTO explains “this technology doesn’t depend on the origin URL, signature or the site’s reputation, but inspects the Web content in real-time, as served.  It analyzes the code’s intentions before enabling it be executed on the end-user browser.”

Of course, although extremely worrying as an individual exploit, the bigger picture is even scarier right now. Finjan reckon that at least 30,000 new infected web pages are being created every single day and around 80 percent of them will hosting malicious software or drive-by downloads were actually located on hacked or hijacked machines.

Did I mention that the above statistics were from the middle of 2007 and that Ben-Itzhak tells me that “today the situation is much worse.”

12345
Rated: 100% (3 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Richard - January 15, 2008 on 12:31 pm

Well I guess using Firefox and NoScript is a bit of help - depends on what you want from the site I suppose.
Do you have any advice for the cautious user to help avoid this little gem?

Comment by JED SLADE - May 4, 2008 on 7:36 pm

The only way i can see is to disable java script.i came across an infected webpage today dealing with barges for sale,this is the site—etnofest.nsk.ru/documents/image/sebastion-likan/thumbs/nobugcoe.htmlo–it requested you click on and download an active x module,which turned out to be a porn film,on not playing it,the real culprit pops up–XP INLINE SCANNER–a 2008 program which downloads trojans,nasty cookies,virus and other real bad naughtiness,in order to force you into buying/using/downloading the XP SCANNER.pure poison,avoid like the plague.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

xmas terrorism Twitter stupidity IBM MSNBC millions Battery network Adobe spam surveys VPN InfoSec betting Big Brother books Health policy MessageLabs storage code christmas Ballmer chips Rant Linux Microchip Business Gartner Hack fool staffing Kill Switch graphics science ASUS scan universe copyright Rumour economics ISPA HPC payments computer rootkits linkedin Google compromise web 2.0 gaming worker dumb money AMD scareware e-commerce email biometrics Windows social networking payment server OCR adware virtual world size iPhone 3G help ecommerce BSI Silverlight report black hat standards Firefox prison NASA archiving global SSL worm service remote working Funny MSN work scam banking environment library phishing virtual machine broadband Government Project debian virus Performance computing VM outsourcing development Flash CAPTCHA Bill Gates second life FBI hypervisor Obama Research malware XP Lotus IP data protection privacy Paris Hilton Zango hacker survey tech Video web symantec The Federation Deal search ID Theft computing crime students Digg Energy security China Supercomputer trust world of warcraft fun Yahoo sick IDC open source Trojan Vista Blogging Eee SMS shopping man-in-the-middle technology Russia holidays hubdub hardware statistics office credit card fraud Application Top 500 Apple Olympics green Death OS exploit Mobile Phone migration mobile transactional security Web Development Finjan remote Noro USA carbon copy patch management BOFH home MiniBook Facebook Microsoft Texas Instruments productivity banks NBC Eee PC Jesus Phone DNS Internet fraud digitise news theft hacking Windows 7 museum iPhone data Space Programming Software stupid avatar botnet Mars workplace printing politics documentation teleworking Texting Steve Jobs
Advertisement
Advertisement
Advertisement