Windows Media Player DRM Exploit

Windows Media Player DRM Exploit

Secure Home | Search | About

Anti-Virus Software - Computer security - anti-virus software 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Windows Media Player DRM Exploit David H. Lipman 08-11-2006
Posted by David H. Lipman on August 11, 2006, 7:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I don't know how many of you know about this one.

I have been seeing a rise in a new way to get you infected with malware. It
actually isn't
too new. It is almost two years old. However its use is rising and may become
more
prevelant in the coming months.

Here's the deal.

I am seeing new Social Engineering posts in the alt.binaries.* News Groups.
Instead of directly attaching malware, thes posts are exploiting the Windows
Media Player
DRM.

Being posted are WMV files with such names as...

Anna Kournikova Calendar Shoot 2005.wmv
Charlize Theron And Penelope Cruz Kiss.wmv
Christina Aguilera Showing Off.wmv
Courtney Cox Lingerie.wmv
Debra Messing Covered Up.wmv
Drew Barrymore Braless.wmv
Keira Knightly Lap Dance.wmv
Melyssa Ford in Lingerie.wmv

When you play the WMV files you have to agree to a EULA and when you click on
"Play Now" it
will download SETUP.EXE from static.zangocash.com the EXE is a malware
installer for
Zango/180Solutions.

The SETUP.EXE file is fairly well recognized such as;
Ewido: Adware.180Solutions and
Kaspersky: not-a-virus:AdWare.Win32.180Solutions.as

The WMVs are not so well recognized but here is a sampling...

AntiVir -- EXP/WMV.A.1 , EXP/WMV.A.2
AVG -- Downloader.Wimad.B
BitDefender -- Trojan.Wimad.A
Ewido -- Downloader.Wimad.h
Fortinet -- W32/WIMAD.C!tr
Ikarus -- Trojan-Downloader.WMA.Wimad.h
Kaspersky -- Trojan-Downloader.WMA.Wimad.h
UNA -- TrojanDownloader.WMA.Wimad.D7FF


Some of these WMVs are too large to submit as their sizes surpass the maximum
submission
size set by the anti malware vendors.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Fitz on August 11, 2006, 11:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the info Dave.
***

>I don't know how many of you know about this one.
>
> I have been seeing a rise in a new way to get you infected with malware.
> It actually isn't
> too new. It is almost two years old. However its use is rising and may
> become more
> prevelant in the coming months.
>
> Here's the deal.
>
> I am seeing new Social Engineering posts in the alt.binaries.* News
> Groups.
> Instead of directly attaching malware, thes posts are exploiting the
> Windows Media Player
> DRM.
>
> Being posted are WMV files with such names as...
>
> Anna Kournikova Calendar Shoot 2005.wmv
> Charlize Theron And Penelope Cruz Kiss.wmv
> Christina Aguilera Showing Off.wmv
> Courtney Cox Lingerie.wmv
> Debra Messing Covered Up.wmv
> Drew Barrymore Braless.wmv
> Keira Knightly Lap Dance.wmv
> Melyssa Ford in Lingerie.wmv
>
> When you play the WMV files you have to agree to a EULA and when you click
> on "Play Now" it
> will download SETUP.EXE from static.zangocash.com the EXE is a malware
> installer for
> Zango/180Solutions.
>
> The SETUP.EXE file is fairly well recognized such as;
> Ewido: Adware.180Solutions and
> Kaspersky: not-a-virus:AdWare.Win32.180Solutions.as
>
> The WMVs are not so well recognized but here is a sampling...
>
> AntiVir -- EXP/WMV.A.1 , EXP/WMV.A.2
> AVG -- Downloader.Wimad.B
> BitDefender -- Trojan.Wimad.A
> Ewido -- Downloader.Wimad.h
> Fortinet -- W32/WIMAD.C!tr
> Ikarus -- Trojan-Downloader.WMA.Wimad.h
> Kaspersky -- Trojan-Downloader.WMA.Wimad.h
> UNA -- TrojanDownloader.WMA.Wimad.D7FF
>
>
> Some of these WMVs are too large to submit as their sizes surpass the
> maximum submission
> size set by the anti malware vendors.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by James E. Morrow on August 12, 2006, 6:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sat, 12 Aug 2006 03:03:38 +0000, Fitz wrote:

> Thanks for the info Dave.
> ***
>
>>I don't know how many of you know about this one.
>>
>> I have been seeing a rise in a new way to get you infected with malware.
>> It actually isn't
>> too new. It is almost two years old. However its use is rising and may
>> become more
>> prevelant in the coming months.
>>
>> Here's the deal.
>>
>> I am seeing new Social Engineering posts in the alt.binaries.* News
>> Groups.
>> Instead of directly attaching malware, thes posts are exploiting the
>> Windows Media Player
>> DRM.
>>
>> Being posted are WMV files with such names as...
>>
>>

<Snip>

Thank you Mr. Lipman for this warning. The threat seem very serious. And
thanks to Bulletproof for the warning regarding Kerio. I'm in Linux now
but when I get back to Windows XP the first thing I'll do is tighten the
Kerio settings.

Does anyone have any specifics regarding Art's point about Irfanview etc?
Is just not using WMP a real protection or could this just be a false
sense of security? I agree with Art on this, but I would like further
reassurance on this.

--
James E. Morrow
jamesemorrow@email.com


Posted by David H. Lipman on August 12, 2006, 7:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| Thank you Mr. Lipman for this warning. The threat seem very serious. And
| thanks to Bulletproof for the warning regarding Kerio. I'm in Linux now
| but when I get back to Windows XP the first thing I'll do is tighten the
| Kerio settings.
|
| Does anyone have any specifics regarding Art's point about Irfanview etc?
| Is just not using WMP a real protection or could this just be a false
| sense of security? I agree with Art on this, but I would like further
| reassurance on this.
|

Please... Don't be so formal. Call me Dave or David. :-)

BTW: While I deliberately Cross-Posted this to microsoft.public.security.virus
The Microsoft News Server filters seems to blocked it from posting it on the
Microsoft News
Server. Most likely it was the name of the WMV files that triggered it.

I'll try reposting just on the MS News Server sans the names of the WMV files.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by James E. Morrow on August 12, 2006, 8:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sat, 12 Aug 2006 23:41:34 +0000, David H. Lipman wrote:

>
>
> |
> | Thank you Mr. Lipman for this warning. The threat seem very serious. And
> | thanks to Bulletproof for the warning regarding Kerio. I'm in Linux now
> | but when I get back to Windows XP the first thing I'll do is tighten the
> | Kerio settings.
> |
> | Does anyone have any specifics regarding Art's point about Irfanview etc?
> | Is just not using WMP a real protection or could this just be a false
> | sense of security? I agree with Art on this, but I would like further
> | reassurance on this.
> |
>
> Please... Don't be so formal. Call me Dave or David. :-)
>
> BTW: While I deliberately Cross-Posted this to microsoft.public.security.virus
> The Microsoft News Server filters seems to blocked it from posting it on the
Microsoft News
> Server. Most likely it was the name of the WMV files that triggered it.
>
> I'll try reposting just on the MS News Server sans the names of the WMV files.

Alright Dave, thanks for your efforts.

--
James E. Morrow
jamesemorrow@email.com


Similar ThreadsPosted
Windows Media Player Error February 27, 2006, 8:53 pm
Windows Media Player 9 Problem! February 28, 2006, 5:48 pm
Any Internet Login & Media Player Not Working July 26, 2006, 6:27 pm
Researcher Finds Media Player Flaws Options (FWD) August 4, 2007, 6:47 am
Exploit Prevention Labs Updates LinkScanner Safe Surfing Product Line With Support for Vista and Firefox (SYS-CON Media) February 11, 2007, 9:02 am
Exploit Prevention Labs Updates LinkScanner Safe Surfing Product Line With Support for Vista and Firefox (SYS-CON Media) February 11, 2007, 9:02 am
Exploit Prevention Labs Updates LinkScanner Safe Surfing Product Line With Support for Vista and Firefox (SYS-CON Media) February 12, 2007, 2:02 am
Windows 98 and MSIE VML exploit September 24, 2006, 12:18 pm
New Exploit for Unpatched Windows Flaw January 1, 2006, 1:51 am
Media Center Hdtv Tuner May 17, 2009, 7:54 am

The site map in XML format XML site map

Contact Us | Privacy Policy