Trojan Piggybacks on Windows Updater
May 15, 2007Researchers discover a Trojan that uses an integral part of Windows to download files onto infected systems.
At least one Trojan virus writer is now using an integral part of the Windows operating system - BITS (Background Intelligent Transfer Service) - to download files to already infected systems.
Windows Update uses BITS as an asynchronous download service to fetch patches, updates and other files - and, in this instance, malware.
Security researcher Frank Boldewin, along with Symantec's Elia Florio, discovered the technique the week of May 7 after analyzing a recent Trojan distributed via spam e-mail in Germany toward the end of March. According to Florio's May 10 posting on Symantec's site, Boldewin determined that the Trojan - which he detected as "Downloader" - was using BITS to bypass the firewall and download files without firewall inspection. As part of the operating system, BITS is trusted and gets passed through without having to go through the firewall.
According to Florio, more common methods used by malware to bypass firewalls include running a continuous thread that sends "Yes, accept" messages to the firewall window, which warns users about strange network connections; shutting down the firewall or killing its processes; injecting malicious code into Internet Explorer or other processes in the firewall's trusted applications list; and patching network drivers to disable firewall filtering.
This new technique doesn't constitute a significant new threat, as the Trojan doesn't evade anti-virus products and is only using BITS as a means of connection. Still, it's an interesting new development in that attackers are using a component of Windows itself, rather than having to write downloaders or updaters themselves, Oliver Friedrichs, director of Symantec Security Response, said in an interview.
"The main impact of this particular threat is the ability to evade outbound firewall filtering," Friedrichs said. "That's not a new concept, … - but - it's another novel way malicious code can use outbound connections."
Symantec, based in Cupertino, Calif., observed this technique being discussed as a means of downloading files on Russian hacker boards at the end of 2006. This is one of the first times it's been seen in the wild, Friedrichs said, and it's something the company expects to see more of in the future.
A Microsoft spokesperson said the company is aware of public reports that BITS is being used by the Trojan, whose official name is TrojanDownloader:Win32/Jowspry, to bypass policy-based firewalls in order to install additional malware.
However, Microsoft, based in Redmond, Wash., says the bypass relies on TrojanDownloader:Win32/Jowspry already being present on the system - in other words, BITS isn't an attack vector for the initial infection.
"The bypass most commonly occurs after a successful social engineering attempt lures the user into inadvertently running TrojanDownloader:Win32/Jowspry, which then utilizes BITS to download additional malware," the spokesperson said in an e-mail exchange.
Microsoft recommends that any users who believe their systems have been affected by TrojanDownloader:Win32/Jowspry visit Windows Live OneCare to scan their systems, determine if they are infected and clean up all currently known variants of the Trojan.
Copyright 2007 by Ziff Davis Media, Distributed by United Press International
-
WUSTL physicist debates 'quantum mind' at New York roundtable
Feb 07, 2011 |
3.9 / 5 (12) |
3
-
Energizer Duo battery charger hides a Trojan
Mar 09, 2010 |
4.8 / 5 (17) |
11
-
Trojan horse for ovarian cancer -- nanoparticles turn immune system soldiers against tumor cells
Jul 15, 2009 |
5 / 5 (5) |
1
-
Digital frame virus traced to China
Feb 19, 2008 |
4.6 / 5 (7) |
2
-
Researcher Reveals 2-Step Vista UAC Hack
May 17, 2007 |
3.2 / 5 (12) |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Need help reading 3-D
7 hours ago
-
A way to send and receive wireless data
13 hours ago
-
Tabletop Cold Fusion Reactor
14 hours ago
-
Calling function with no input argument
Feb 10, 2012
-
Force free body diagram problem on gym equipment
Feb 10, 2012
-
Empirical data regarding shower heads and water
Feb 10, 2012
- More from Physics Forums - General Engineering
More news stories
Walney offshore wind farm is world's biggest (for now)
(PhysOrg.com) -- The Walney wind farm on the Irish Sea--characterized by high tides, waves and windy weather--officially opened this week. The farm is treated in the press as a very big deal as the Walney ...
GPS court ruling leaves US phone tracking unclear
A US Supreme Court decision requiring a warrant to place a GPS device on the car of a criminal suspect leaves unresolved the bigger issue of police tracking using mobile phones, legal experts say.
16 hours ago |
4 / 5 (2) |
0
Europeans protest controversial Internet pact
Tens of thousands of people marched in protests in more than a dozen European cities Saturday against a controversial anti-online piracy pact that critics say could curtail Internet freedom.
12 hours ago |
5 / 5 (7) |
0
Netflix settlement trims 14 pct off 4Q earnings
(AP) -- Netflix pressed the rewind button on its fourth-quarter earnings after settling allegations that the video subscription service violated a consumer-privacy law.
16 hours ago |
not rated yet |
0
Navy to begin tests on electromagnetic railgun prototype launcher
The Office of Naval Research (ONR)'s Electromagnetic (EM) Railgun program will take an important step forward in the coming weeks when the first industry railgun prototype launcher is tested at a facility ...
Feb 06, 2012 |
4.7 / 5 (15) |
91
|
Europe stakes billion-dollar bet on new rocket
A pencil-slim rocket is scheduled to lift into space from South America on Monday, carrying a billion-dollar bet that Europe can grab a juicy slice of the market to place satellites in low orbit.
Study finds that anti-diabetic medication can prevent the long-term effects of maternal obesity
In a study to be presented today at the Society for Maternal-Fetal Medicine's annual meeting, The Pregnancy Meeting, in Dallas, Texas, researchers will report findings that show that short therapy with the anti-diabetic medication ...
Explained: Sigma
It's a question that arises with virtually every major new finding in science or medicine: What makes a result reliable enough to be taken seriously? The answer has to do with statistical significance -- but ...
Political leaders play key role in how worried Americans are by climate change: study
More than extreme weather events and the work of scientists, it is national political leaders who influence how much Americans worry about the threat of climate change, new research finds.
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
NASA budget will axe Mars deal with Europe: scientists
US President Barack Obama's budget proposal to be submitted next week for 2013 will cut NASA's budget by 20 percent and eliminate a major partnership with Europe on Mars exploration, scientists said Thursday.