Trend Micro has received reports from users about a new, dangerous file infector. This threat, detected as PE_LICAT.A, uses a domain generation algorithm, a technique last seen in WORM_DOWNAD/Conficker variants. This technique allows the file infector to download and execute malicious files from various servers on the Internet.
Like WORM_DOWNAD, PE_LICAT.A generates a list of domain names from which it downloads other malicious files. The domain name generation function is based on a randomizing function, which is computed from the current UTC system date and time. This particular randomizing function returns different results every minute.
According to Escalation Engineer Alvin Bacani, whenever a file infected by PE_LICAT.A is executed, the malware generates a pseudorandom domain name, with the exact value depending on the system’s time. It then tries to connect to the said domain name. If it is successful, it downloads and executes the file at that pseudorandom URL. If not, it tries up to 800 times, generating a “new” URL every time. This helps ensure that the malware will be able to keep itself updated and even if one or more domains are taken offline, others can take its place.
Based on PE_LICAT.A’s code, the downloaded files are first validated before executed, which is the same technique WORM_DOWNAD employed. Users whose systems have been infected are at risk of downloading more malicious files onto their systems every time PE_LICAT.A is executed.
Trend Micro protects product users from this attack via the Trend Micro™ Smart Protection Network™, which detects and blocks the said file infector from running.
Analysis of this threat is ongoing and further details will be provided when they become available.
'IT 보안소식' 카테고리의 다른 글
구글 로고(Google Logo), 한글이 창조 된 "한글날 564돌"을 기념하는 로고 (4) | 2010.10.09 |
---|---|
구글 로고(Google Logo), 존 레넌(John Winston Ono Lennon) 70번째 생일 축하기념 (0) | 2010.10.09 |
구글 로고(Google Logo), HP 창립자 "데이비드 패커드(David Packard)" 기념이 아닌 "구글 순간검색 런칭 기념" 로고 (12) | 2010.10.07 |
알약(ALYac), SCADA 시스템 공격을 시도하는 Stuxnet 악성코드 (0) | 2010.10.06 |
카스퍼스키(kaspersky), 2010년 9월 악성프로그램 통계 (0) | 2010.10.06 |
댓글