Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Worst Company in America The RIAA - Consumerist
  • Hackers exploit latest IE zero-day with drive-by attacks
  • Salon Radio: Patriot Act and FISA reforms
  • Waxahachie Daily Light - News - House bill aimed at protecting privacy
  • U.S. Plan for Airline Security Meets Resistance in Canada
  • Definition Changing for People's Privacy
  • House Intelligence Committee To Probe CIA Disclosure Policy

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Another Downloader-AAP or 'German Online Computer Spying by Intelligence Agents'?

Submitted by MacRonin on May 9, 2007 - 10:57am
  • AAP
  • Alert
  • Exploits
  • Law Enforcement
  • Privacy
  • Scams
  • SPAM

Another Downloader-AAP or “German Online Computer Spying by Intelligence Agents”?: "

No - although it pretends to be sent by German authorities, it’s just another trojan.

Another spamming of Downloader-AAP happened this past Saturday, May 5th, 2007. Those spam runs are nothing unusual here in Germany - we usually see one or two a week. Today, Wednesday, May 9th we see almost the same again. Just the malicious binaries have changed.

While having some ongoing discussions about ‘Online Computer Spying by Intelligence Agents’ here in Germany, the body of the spammed mail pretends to be send by ‘LKA Rheinland-Pfalz’ - State Office of Criminal Investigation.

The user gets notified about an online search, because his IP address was found while monitoring Peer-to-Peer networks. Backups of the content of users hard drive got taken by the ‘Bundestrojaner’.

Further on, the user will face a criminal prosecution because of illegal software, movies and/or music files found on the machine. Detailed information about the online search can be found in the attached protocol.

No - no protocol - only another trojan. Don’t click!

Given the user executed the attached file, the trojan starts to download a copy of Spy-Agent.ba from different servers and executes it. All it does is drop a DLL in %windir%\system32 and to register it as Browser Helper Object (BHO) for the Internet Explorer, which captures confidential account information from different e-banks and uploads them on the attackers servers.

This DLL gets proactively detected as Spy-Agent.ba.dll.

Below is an example of a spammed mail:

[...]

Proactive detection for the new spammed Downloader-AAP and the Spy-Agent.ba.dll have been in the DATs before the spamming started. Detection for the new Spy-Agent.ba will be included in todays 5027 DATs.

(Read Original Article - Via McAfee Avert Labs.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • The Beginning of the End of Data Retention
  • Wanted: Trust Detector
  • Wikibooks Cryptography Textbook
  • Feds: TSA Worker Tried to Sabotage Terror Database
  • Hi-tech governments growing keener on snooping, says report
  • Classmates.com’s Facebook Mimicking Prompts Privacy Suit
  • Zeus botnet dealt a blow as ISP Troyak knocked out
  • Better U.S. Net Rules for Iran, Cuba and Syria
  • European Parliament Rips Global IP Accord (ACTA)
  • Hackers exploit latest IE zero-day with drive-by attacks
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.