Trojan horse maps drive, lifts addresses

NEWS
There are at least two versions of picture.exe making their way around the Internet, as well as a third very similar Trojan horse called soft.exe. And these new versions have even more confusing behaviour. According to a Chinese ISP network manager, picture.exe version 2 roots through computers to gather up a list of every common file on a victim's hard drive, and then it cobbles together every e-mail address from every piece of mail stored on the victim's computer. Then, it tries to ship those off to China. Where in China? To eight e-mail addresses, according to a ISP network administrator in China who consults for the Net providers where picture.exe's files are headed. Network Associates last week posted a report on picture.exe and updated its McAfee anti-virus software after re-ports of the Trojan horse started making their way around Usenet groups. The company says the version of picture.exe it examined builds a list of .txt and .html files on a user's hard drive, then builds a list of Internet sites pulled from a user's Internet cache. It also attempts to steal America Online usernames and passwords. Network Associates' has written a complete report. But the network administrator MSNBC spoke to provided a different picture.exe. One text file his version produced included e-mail addresses pulled from every e-mail saved on a user's machine. Apparently, picture.exe does a full-text search of mail files for @ symbols, then builds a file called $4135.dat. It puts everything it finds just before an @ symbol, the name portion of the e-mail, at the top of that text file. The end result is a lengthy list of addresses tailor-made for bulk e-mail -- spamming. One possible explanation is that this is not a different version of picture.exe but a difference of opinion. Network Associates and the network administrator may have just interpreted the contents of the file differently. The other text file created by the administrator's version of picture.exe. called $2321.dat, is a map (filename and path) of every file with the extensions .txt, .html, .idx, .mdb, .pst, .pab, .db or .pst on the victim's computer. MSNBC was able to reproduce that result. Why would someone want a detailed map of files on a user's hard drive? It could be used by an outsider to tunnel through your computer once an IP connection is established -- say by the user's visiting an innocent-looking Web page. Such a file list is the key to many Web-based attacks, where hackers need only know the location of a file on your machine in order to copy it or edit it. "A file map like that could be very useful with Back Orifice, though it is by no means necessary to use that to cause problems with BO," said a spokesperson for the hacker group Cult of the Dead Cow identifying himself as Tweety Fish. The CDC last year created Back Orifice, which is designed to allow outsiders to take control of PCs remotely. "It's possible that the Trojan was designed to be used with BO, but more likely is that it has its own file transfer built in that would let the creators access those files, possibly en masse," Tweety Fish said. "Another very good possibility is that it was supposed to have functionality like that, but it's broken." But the real intentions of the authors of picture.exe, and why the e-mail gets sent to China, remain a mystery. The Chinese ISP administrator MSNBC contacted offered these additional hints: the eight e-mail addresses check out as legitimate mailboxes, and seven originate in China. The eighth is a hotmail address. Since getting an e-mail in China requires a photo ID, identifying the intended recipients of picture.exe's work is easy for Chinese authorities. But so far, they haven't shown much interest in pursuing the authors. When the Chinese Net administrator complained to the Public Security Bureau about the danger of spamming by the creators of the Trojan horse, he says he was told: "Usually they pay more attention to cases with clear evidence and damage. They wouldn't make any official move until they are sure the evidence is strong enough, the damage is more than some student hackers fooling around." The Trojan apparently hasn't been sent to Chinese recipients. Just from China to outside China. That's unlikely to raise the interest of government officials. He has traced the original spam message to an ISP in Shenzhen. Our source in China also reports his version of picture.exe does not appear to attempt to steal AOL passwords. That matches up with common sense: "I don't think someone from China would actually want AOL passwords," he said. "Calling an AOL dial-up from here is about $5 U.S. a minute.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

21 minutes ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

25 minutes ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 hour ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 hour ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

2 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

2 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

2 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

5 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

6 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

6 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

8 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

9 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

10 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

18 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

1 day ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

1 day ago by awbMaven on US indicts Romanian over NASA climate change hack