In this case, we're talking Sirefef (ZeroAccess aka Max++), probably the nastiest piece of malware circulating on the 'net right now. Sirefef kills any attempt to remove it, and is nearly impossible to clean (short of booting onto a rescue disk and performing cleanup actions, or reformatting).
So just search for "adobe flash", and you might see this ad:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPJly4uDlewwhQQPYy6mOPopOhsfkXvWsCd-yMGHqtFUrJCINXP9JW6wrxc0kxXVdLac3VRLBaoLMS8sOjeaaKVaMG2UBTiaQudeGi5TcXWSj5P4kJdiV1CkMLFlcm5QQgzZ6U/s280/bing2382348888.png)
So just search for "adobe flash", and you might see this ad:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPJly4uDlewwhQQPYy6mOPopOhsfkXvWsCd-yMGHqtFUrJCINXP9JW6wrxc0kxXVdLac3VRLBaoLMS8sOjeaaKVaMG2UBTiaQudeGi5TcXWSj5P4kJdiV1CkMLFlcm5QQgzZ6U/s280/bing2382348888.png)
(That same search term will look identical on Yahoo, since Yahoo displays Bing ads and search results.)
Which leads to an innocent-looking "download flash" page:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkGg3Z25RCCXG2rcrzGp1jkcATzFaiPhFq8Jlolg2fPKLAS33YCnmkfj9xohnKFFQ7IUojm20WQ0_RgVBzeUTlxeoz6V_105k-Mmk67g7nfm_oXdZtlfbxf1kgwXni88piu-kK/s280/bing2382348888a.png)
Note that the page isn't actually "GetAdobeFlash.com". Instead, it redirects to a directory on a compromised trucking site (arulbrothers.com), downloading a file from torreandaluz (dot) com/flash/Flash Player 10 Setup.exe
So let's download that Flash Player and run it through VirusTotal, and no surprise: It's Sirefef.
So let's download that Flash Player and run it through VirusTotal, and no surprise: It's Sirefef.
Alex Eckelberry
(Thanks to Matthew)
No comments:
Post a Comment