<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; trojan</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hackers will do anything for your WoW password (updated)</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/</link>
		<comments>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 16:19:38 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[all your wow-gold are belong to us]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[World of Warcraft]]></category>
		<category><![CDATA[wow]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=709</guid>
		<description><![CDATA[So the Analyt&#8217;s Diary blog at viruslist.com has an article on some new mass SQL injection attack that jacks up .asp pages with redirects to browser exploits. The exploits drop one of two trojans that steal passwords and whatnot. Here is h.js: document.write(&#8220;&#8221;); document.write(&#8220;&#8221;); WordPress won&#8217;t display the script. Basically, it loads an iframe that [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 260px"><img title="Trojan Horse" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/02/250px-trojanhorsemythimage.jpg" alt="Trojan Horse" width="250" height="166" /><p class="wp-caption-text">Trojan Horse</p></div>
<p>So the Analyt&#8217;s Diary blog at viruslist.com has an <a href="http://www.viruslist.com/en/weblog?weblogid=208187604">article</a> on some new mass SQL injection attack that jacks up .asp pages with redirects to browser exploits.  The exploits drop one of two trojans that steal passwords and whatnot.  Here is h.js:</p>
<p><del datetime="2008-11-10T18:10:20+00:00"><em>document.write(&#8220;&#8221;);<br />
document.write(&#8220;&#8221;);</em></del></p>
<p>WordPress won&#8217;t display the script.  Basically, it loads an iframe that points to two separate URLS (these URLs contain browser exploits so don&#8217;t follow them):</p>
<p>hxxp://vvexe.com/haha/index.html and<br />
hxxp://www.kenya.com/faq.htm<br />
<del datetime="2008-11-11T02:44:42+00:00"><br />
I can&#8217;t seem to get to either of these sites at the moment.  I&#8217;ll try again later.</del></p>
<p><strong>Update:  </strong>I spent some time looking at this malware.  The two pages listed earlier in this post contain iframes to browser plug-in exploits for real player and other typical vulnerabilities.  The exploits attempt to load and run down.exe (e160f590d894a98474697ac0db987746 not packed/delphi code) which in turn downloads hxxp://www.vvexe.com/haha/down.txt to get the additional files 1.exe (a7fc8c966fdeb550fe19aba3169569be not packed/VC++), do.exe (5af5edaa2cebf1fed56ad36799b2c850 ) and cool.exe (18867d6de1a3a9241c14c22c19b51351 not packed/delphi).</p>
<p>1.exe is a WoW trojan and waits for passwords sent to:</p>
<p>grunt.wowchina.com and [kr|us|tw|eu].[version|logon].worldofwarcraft.com.  It also looks for and attempts to disable many types of security software.  It attempts to send the stolen credentials to an asp on www.yilu777.com.</p>
<p>do.exe is a little more interesting.  It appears to be a generic remote access trojan that sends a beacon to qq number 58836533.  A quick search for that qq number revealed that this person&#8217;s paipai account has been frozen:</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/paipai.png"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/paipai.png" alt="http://shop.paipai.com/58836533" title="paipai" class="alignleft size-medium wp-image-724" /></a></p>
<p>So I do some more digging and find the QQ profile with a name and nick:</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/picture-3.png"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/picture-3.png" alt="" title="QQ_Profile" class="alignnone size-thumbnail wp-image-726" /></a></p>
<p>Searching for the nickname got me to a few blogs and profiles that had some young girl who is really into anime.  Maybe her QQ account got pwn3d or maybe, just maybe she is a member of <a href="http://www.thedarkvisitor.com/2008/05/chinese-female-hacker-group/">&#8220;China Girl Security&#8221;</a>.  I tried to get an add on that QQ account so I could talk to the hacker but didn&#8217;t have any luck.</p>
<p>Note to Chinese hackers:  <a href="http://www.casualgaming.biz/news/27887/China-to-tax-virtual-property">Please pay the tax</a> on your WoW gold profits.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chinese hackers&#8230;masters of social engineering</title>
		<link>http://www.thedarkvisitor.com/2008/05/chinese-hackersmasters-of-social-engineering/</link>
		<comments>http://www.thedarkvisitor.com/2008/05/chinese-hackersmasters-of-social-engineering/#comments</comments>
		<pubDate>Tue, 20 May 2008 10:27:42 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Red Heart]]></category>
		<category><![CDATA[Red Heart Robber]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=563</guid>
		<description><![CDATA[If I was in the business of spotting popular trends, the first thing I would do is a hire a Chinese hacker. While the rest of the world is passively watching events unfold around them, Chinese hackers are doing the math on how many people will participate and what online avenues are associated with them&#8230;like [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/redhorse.jpg"><img class="alignnone size-medium wp-image-562 aligncenter" title="redhorse" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/redhorse-300x124.jpg" alt="" width="385" height="144" /></a></p>
<p>If I was in the business of spotting popular trends, the first thing I would do is a hire a Chinese hacker.  While the rest of the world is passively watching events unfold around them, Chinese hackers are doing the math on how many people will participate and what online avenues are associated with them&#8230;like symbols.</p>
<p>According to an article in tech.ccidnet.com, hackers are using recent events and the patriotism they have inspired to spread a new trojan called, &#8220;<a href="http://tech.ccidnet.com/art/1099/20080519/1452017_1.html">Red Heart Robber</a>.&#8221;  The snatching of the Olympic torch, the CNN incident, and earthquake in Sichuan have caused the Chinese online community to <a href="http://www.thedarkvisitor.com/2008/04/the-originator-of-red-heart-china-gets-his-website-hacked-europeans-responsible/">attach red hearts with the Chinese flag</a> (and other variations) to their QQ sig and webpages to show support/sympathy for China.  When normal online users download the image of the red heart flag to show their support for China, a nasty little trojan is attached.</p>
<p>Attacking your own symbol of patriotism&#8230;not cool!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/05/chinese-hackersmasters-of-social-engineering/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Once again, NEVER hack inside the PRC</title>
		<link>http://www.thedarkvisitor.com/2008/03/once-again-never-hack-inside-the-prc/</link>
		<comments>http://www.thedarkvisitor.com/2008/03/once-again-never-hack-inside-the-prc/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 13:44:36 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[idiot]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=438</guid>
		<description><![CDATA[  I found this article this morning from the English language Shanghai Daily.  The article reports that three hackers and an idiot were jailed for using trojan horse programs to steal bank login credentials and then transferred the money to the idiot&#8217;s own account. Yu then used a laptop they bought together to log onto the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/fair_use_rmb.jpg" title="RMB"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/fair_use_rmb.jpg" alt="RMB" /></a> </p>
<p>I found this <a href="http://www.shanghaidaily.com/sp/article/2008/200803/20080325/article_353399.htm" title="article">article</a> this morning from the English language Shanghai Daily.  The article reports that three hackers and an idiot were jailed for using trojan horse programs to steal bank login credentials and then transferred the money to the idiot&#8217;s own account.</p>
<blockquote><p><em>Yu then used a laptop they bought together to log onto the accounts,<br />
targeting accounts with a great deal of money.</em></p>
<p><em><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/fair_use_rmb.jpg" title="RMB"></a><br />
</em></p>
<p><em>He transferred the money to his own online account. Yu, Chen and Zhao<br />
then drew money out of Yu&#8217;s accounts using ATMs in different areas.</em></p></blockquote>
<p>They allegedly stole 127,800 Yuan from three victims.  See also Heike&#8217;s posts about <a href="http://www.thedarkvisitor.com/?p=366" title="Hacking for Money">Hacking for Money</a> and <a href="http://www.thedarkvisitor.com/?p=284" title="Never Hack Inside China, Ever">Never Hack Inside China, Ever</a>.  These guys are probably not the  <a href="http://www.thedarkvisitor.com/?p=357" title="Immoral, robotic-like assassins">immoral, robotic-like assassins</a> that the PRC government is concerned about.</p>
<p><strong>Update:</strong>  I&#8217;m having trouble loading the page.  You can find a mirror of the article on the infosec news list archive on Neohapsis <a href="http://archives.neohapsis.com/archives/isn/2008-q1/0401.html" title="here">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/03/once-again-never-hack-inside-the-prc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

