sudosecure.net

              is anything truly secure…

Waledac Theme – Reuters: Terror Attack

Posted by jeremy on March 15th, 2009

Looks like the Waledac Authors wore the Couponizer theme out, and have now switched to a new headline “Terror Attack” theme.  Headline News themes are nothing new to botnets like Waledac, as the Storm Worm used them a few times with fairly decent infection rates.  Another note of interest with this attack is the continued usage of GeoIP data to customize the news article for visitors.  I utilized several web proxies and the Waledac GeoIP database seems to provide extremely accurate IP to Location results.  Take a look at a screen grab I took while I was utilizing a Woodstock web proxy.

reuters_waledac

Another interesting touch are the two non malicious web links at the bottom of web page.  One leads to the “Dirty Bomb” wikipedia page and the other leads to Google search results pertaining to “Your GeoIP City” and the key words “Terror Attack”.  The normal iframe hidden link can still be found in all the Waledac web pages I viewed.  The common URL structure for this iframe right now is http://xxxxxx/tds/Sah7 , so some simple URL filtering or logging with your proxies may help to identify users that have visited a Waledac web page and possibly received some malicious exploit attempts passed through this hidden iframe.

If anyone is interested in just how well the Antivirus Companies are doing in keeping up with the Waledac Authors and polymorphic packer here are a few links to VirusTotal’s Static file scan results for some of my recently collected binaries:

Not looking all that good, if you ask me.

5 Responses to “Waledac Theme – Reuters: Terror Attack”

  1. Waledac Theme - Reuters: Terror Attack | Enlarge4u Blog Says:

    [...] the rest here: Waledac Theme – Reuters: Terror Attack Site Search Tags: No [...]

  2. David Says:

    I am receiving some spams pointing to tntbreakingnews.com and breakingkingnews.com.

  3. jeremy Says:

    Thanks for the additional domains, I have added them to my tracker. I have been kind of lazy collecting new domain names due to personal time constraints, but I know a friend of mine over at shadowserver.org maintains a pretty good list here: http://www.shadowserver.org/wiki/uploads/Calendar/waledac_domains.txt I believe he has a few updates to post soon with new domains, so we may want to keep an eye out for those.

  4. Edgar Says:

    McAfee SiteAdvisor seems to have some problems with the pages Waledac

    http://edetools.blogspot.com/2009/03/waledac-sites-e-verifiche-online.html

    Edgar :)

  5. Edgar Says:

    New botnet Waledac theme for SMS spy

    Waledac Botnet is proposing a new page with the usual links to malware and the new ‘theme’ SMS TRAP

    http://edetools.blogspot.com/2009/04/nuovo-tema-waledac-botnet-per-spiare.html

    Edgar :)

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>