About Me

Geok Meng Ong

Geok Meng Ong
Senior Research Manager

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

W32/Kibik.b – Seeking Them Out From Your Codecs and Winlogon.Exe

Friday, January 4, 2008 at 9:46am by Geok Meng Ong
Geok Meng Ong

Websites delivering malicious payload either in the form of web exploits or plain old executables masquerading as multimedia or legit applications is not uncommon. In the past year, we must have blogged a dozen times how the popularity of Internet audio and video has turned them into a malware wonderland – from movie infecting worms to dodgy codec installers, yes even on MacOS; and most recently, Puper trojans capitalizing on the Bhutto assassination video. From widespread infection that hit the headlines the next day, to stealthy backdoors and password stealers aimed to stay quiet and reside in your computer for as long as possible.

McAfee’s SiteAdvisorTM technology performs behavioral analysis looking for suspicious activities in code that resides within the inter-twined nests of exploited sites. Be it rogue administrators or compromised servers, such sites might certainly host safe downloads, but they are far more likely to host something malicious than your average site.

Just before Christmas 2007, when our crawlers detected dodgy behavior that was attributed to a site linked to a nest of exploits, our system quickly escalated it for human review. It turned out to be a variant of W32/Kibik, a stealthy limited parasitic virus that targets only specific files and stays low under most radar. The website tricks the user into downloading a fake media codec, now detected as W32/Kibik.b.

Instruction to download fake media codec
Figure 1. Instruction to download fake media codec

Like its big brother, the new variant is hard to detect as it infects Winlogon.exe by quietly planting the virus in an unused null-ed out segment of the file, and unlike most viruses, does not change the size of the file. It also does not leave a trace in the Windows registry or modifies other files in the computer, but starts each time the system starts up.

W32/Kibik.b retrieves commands from the server hosted at swf1.flashxyx.com. This domain appears to be hosting free games for download, but is (ab)used as a command and control server for W32/Kibik.b.

On each startup, the following several actions are performed once:
1) A network connection is made to swf1.flashxyx.com.
2) At the time of our investigation, the host was active but not delivering any files, but our static analysis shows it can and will download and execute additional files:

Download and execute code in DLL
Figure 2. Download and execute code in DLL

It goes on to poll the website in 5-minute intervals to retrieve further commands from the controller.

As its actions are relatively low-noise, and was active during the holiday season, few security vendors have detected W32/Kibik.b, as was its older variant.

More details of W32/Kibik.b are available.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (1)

  • Geïnfecteerde Winlogon.exe lastig te detecteren January 11, 2008 12:39AM

    [...] Virusonderzoekers hebben een nieuwe variant van het Kibik virus ontdekt dat zichzelf injecteert in een ongebruikt gedeelte van Winlogon.exe. [...]