Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Virus alerts

August 9th, 2006, 10:06 GMT · By

Internet Explorer BHO Trojan

SHARE:

Adjust text size:


Websense Security Labs has announced in a press release that the company has received and analyzed a new Trojan that implements innovative techniques to camouflage its actions. While the keylogger
generates traffic containing the information that it has recorded and stolen from a compromised machine, it disguises the data as Internet Control Message Protocol packets. Normally this protocol is reserved for the transmission of erroneous and control messages, router generated unavailability notifications or echo requests from ping utilities.

"Websense Security Labs has received a sample of a new phishing Trojan that delivers stolen information back to the attacker via ICMP packets. Upon infection of a victim's computer, the Trojan will install itself as an Internet Explorer Browser Helper Object (BHO). The BHO then waits for the user to post personal information to a monitored website. As this information is entered by the user, it is captured by the BHO and sent back to the attacker. The method of network transport used by the attacker makes this Trojan unique. Typically, keyloggers of this type will send the stolen information back to the attacker via email or HTTP POST, which can appear suspicious. Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into the data section of an ICMP ping packet." explained the company.

The ICMP packets containing captured encoded sensitive data bypass administrators and egress filters, as the packet looks masquerade as legitimate traffic.

"In our example, we infected a workstation and entered account information into the SSL website of Deutsche Bank. The Trojan BHO captured the information and sent a ping to a malicious remote server. Below you can view the encoded contents of the ICMP data section as well as the actual contents after they were manually decoded," stated Websense.

TELL US WHAT YOU THINK:

41,381 hits · 7 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Malware Search Engine

Zidane's Head But Spreads Trojan

Hacked Advertisment on MySpace Infected a Million Users

Hackers Implement Open Source Techniques

Suicidal Malware Rises New Threats

READER COMMENTS:


Comment #1 by: bifta man on 18 May 2009, 19:10 UTC reply to this comment

just a quick tip, for trojan removal, Malwarebites and anti malware is a free program wich captures trojan before the get a chance to infect your system,
and works a treat!!


Comment #2 by: PJ on 27 Aug 2009, 22:31 UTC reply to this comment

I have a question, Malwarebytes did not detect the virus UNTIL I did a scan, thus does that mean that the trojan had already stolen my information?

Comment #2.1 by: STRIKER/RC4 on 18 Feb 2011, 02:01 GMT

Logico...


Comment #3 by: iMcMark on 29 Aug 2009, 04:39 UTC reply to this comment

heh malwarebytes is great :D saved my old laptop when I was infected by major trojans.. they locked up my account and changed all of my settings :| but I fixed it all in time :D


Comment #4 by: tracey on 31 Oct 2009, 21:18 UTC reply to this comment

I have both a trojan.BHO and a Frethog.DAI on my computer
I dont know how I got the Trojan.BHO because I don't use Internet Explorer


Comment #5 by: roe2121 on 18 Jan 2010, 03:53 UTC reply to this comment

tracey even though you dont use internet explorer doesnt so matter mean you cannot be infected with this trojan horse.

Comment #5.1 by: marty on 16 May 2011, 04:15 GMT

Yes i did a scan with malwarebytes and it detected liek 5 hbo trojans, so, now im scared of logging on to anything...

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM