ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

The what

highMalwareimportance 42
Full article498 words · extracted from securelist.com · click to collapse

Incidents

Incidents

10 Sep 2009

minute read

Late on Monday, a lot of Russian ICQ users got sent this message:

Woland (23:07:23 7/09/2009)
Link to download the file Frogs.rar
http://file.qip.ru/file/*********/********/Frogs.html
[– File sent via file.qip.ru. More details on the site: http://file.qip.ru –]

If you’ve been using ICQ for a while or are even remotely security savvy, you know not to just click on links that get sent to you, even if they appear to come from a known contact. Instead, you’re going to try and check in some way whether it’s really a person who sent you the link, or just a bot. Turing tests are designed to distinguish humans from bots, and everyone’s come across CAPTCHAs, a reverse Turing test. Of course, if you’re on ICQ, you’re not going to use an image to check who’s on the other side of the screen, but you can ask a challenge question – after all, a computer can’t actually answer questions, can it?

But there’s a problem with this – if you get sent a link to a file, you’re going to automatically ask “What is it?” And this is where it gets interesting: the bot behind the link didn’t have any trouble answering this question.

Yuk(23:07:28 7/09/2009)
What is it?

Woland (23:07:28 7/09/2009)
An optical illusion puzzle funny )

This answer sounds pretty human, so why not download and run the file? The puzzle looks like this:

The frogs are just there to divert your attention. Working out which way they should jump is a nice little time-waster. But while you’re doing that, some malware (we detect it as Hoax.Win32.IMPass.al/ Hoax.Win32.IMPass.am) bundled in the package is quietly stealing your ICQ login and password. And once it’s got those details, your password gets changed, and then the same link starts being sent to all your contacts from your account.

The bot’s not as intelligent as it first seems: it’s only able to answer questions which contain one of the following words: «что», «чо», «чё» , «че» , «шо» , «що» и «чито». (The first is standard Russian for “what” – the others are slang widely used on the Russian Internet.)

The whole thing is a neat little lesson: security doesn’t just depend on checking whether links were really sent by your friends, but also on thinking up challenge questions that no bot could ever answer!

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/the-what-bot/30559/