Sykipot Trojan takes advantage of Adobe Reader zero-day flaw
Posted on 13.12.2011
AlienVault Labs researchers have unearthed a piece of malware that takes advantage of the recently discovered zero-day Adobe Reader flaw used for attacking defense contractors.

The malware in question is the Sykipot Trojan, which has been found abusing various zero-day vulnerabilities in the past.

According to the researchers, the attackers misuse the flaw to make the target computer download the malware, which then searches for outlook, iexplore or firefox in the list of running processes. Once it has found them, it injects DLL files into them.

After that, the malicious binary creates a PDF file that apparently contains “CONUS rates” for traveling expenses in the continental US (click on the screenshot to enlarge it):



"The injected DLL will contact XXXhksrv.hostdefence.net/asp/kys_allow_get.asp?name=getkys.kys to download an encrypted configuration file," explain the researchers. "This file contains several commands that the victim will execute on the sending the results back to the C&C server."

The hostdefence.net domain on which the C&C server is hosted is located in China.






Spotlight

Cloned, booby-trapped Dark Web sites steal bitcoins, login credentials

Apart from being a way for dissidents and journalists to do their business without being spotted and identified by "the powers that be", the Dark Web is also a place where criminals sell and buy illegal wares and services and, apparently, where they also get robbed by scammers.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Fri, Jul 3rd
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //