CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Malware: When is a Trojan (not)?? image
Worms
When is a Trojan (not)??
December 28, 2003 CCSP Staff
Answer: Blended Threats

What is a Blended Threat??

Blended threats combine the characteristics of viruses, worms, Trojan Horses, and malicious code with server and Internet vulnerabilities to initiate, transmit, and spread an attack. By using multiple methods and techniques, blended threats can rapidly spread and cause widespread damage. Characteristics of blended threats include:

..Causes harm: Launches a Denial of Service (DoS) attack at a target IP address, defaces Web servers, or plants Trojan Horse programs for later execution.

..Propagates by multiple methods: Scans for vulnerabilities to compromise a system, such as embedding code in HTML files on a server, infecting visitors to a compromised Web site, or sending unauthorized email from compromised servers with a worm attachment.

..Attacks from multiple points: Injects malicious code into the .exe files on a system, raises the privilege level of the guest account, creates world read and write-able network shares, makes numerous registry changes, and adds script code into HTML files.

..Spreads without human intervention: Continuously scans the Internet for vulnerable servers to attack.
Exploits vulnerabilities: Takes advantage of known vulnerabilities, such as buffer overflows, HTTP input validation vulnerabilities, and known default passwords to gain unauthorized administrative access.

..Effective protection from blended threats requires a comprehensive security solution that contains multiple layers of defense and response mechanisms, to and including anti-spyware and adware applications (blockers). Links to these applications and information may be found in our Virus-Worm Related and Spyware-HiJack Related Forums.

Blended Threats

According to Symantec's Semantics the Trojan Bookmarker is a trojan. Actually it is not...this is a case where: if it looks like a duck, quacks like a duck, acts like a duck, it's a swan.

Here is a recent listing:

Trojan.Bookmarker

Discovered on: December 20, 2003

Last Updated on: December 23, 2003 01:18:12 PM

Trojan.Bookmarker is a small Trojan horse that modifies the Internet Explorer's home page and search page, and adds bookmarks that point to pornographic Web sites to the Favorites folder.

This Trojan changes the Internet Explorer Home page to the webcoolsearch.com. It is also packed with UPX.

Type: Trojan Horse


Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Systems Not Affected: DOS, Linux, OS/2, UNIX
http://securityresponse.symantec.com/avcenter/venc/data/trojan.bookmarker.html

Trojan Bookmarker

Moral of this story: The above is a Hi-Jack.

Virus-Worm Related

Spyware-HiJack Related

Required Read: So how did I get infected in the first place?
Posted on Sunday, 28 December 2003 @ 11:15:53 UTC by phoenix22 (2865 reads)
[ Trackback ]
image

"Malware: When is a Trojan (not)??" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· Microsoft
· HotScripts
· W3 Consortium
· HTML Standard
· More about Worms
· News by phoenix22


Most read story about Worms:
Kama Sutra/Blackworm Worm Timebomb

block bottom
Article Rating
spacer
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer