Benazir Bhutto Assassination: New Avenue for Spreading Malware
Friday December 28, 2007 at 5:32 am CST
Posted by Rahul Mohandas
A few weeks back we blogged about malware-laced codecs embedded in various Blogspot domains. Today within hours after the assassination of former Pakistani Prime Minister Benazir Bhutto, malware authors have started capitalizing on this news to spread a new fake codec. This time it is purported to be an assassination video of the former PM.
Claiming to be a New HD Codec, these malware authors attempt to social engineer users into believing they are downloading a legitimate codec for playing the video. At least 10 Blogger websites are observed to be hosting this fake video (at the time of writing this blog) which redirects the users to the typo-squatted domain containing fake codec:
http://video.googl.[removed]

Malicious code hosted on the 3322 domain is not something novel. One of the recent high profile attacks which pointed to a malicious script from the 3322 domain was the Indiatimes Mail hack.
There are a plethora of websites which attempt drive-by installations when unsuspecting users visit websites returning search engine results for “Benazir Bhutto”. Many of these compromised webpages have malicious scripts injected into the webpage which points to the 3322 domain. These webpages contain obfuscated variants of the MS06-014 exploit which is perhaps one of the most popular of all the exploits we see on a daily basis.
This fake Trojan Codec is detected by the current DATS as Puper. The downloaded exploit is detected as VBS/Psyme and the executable is detected as Generic Downloader.c
(Credits to Pradeep Govindaraju for the great malware analysis)

December 29th, 2007 at 2:42 am
Lo último en malware: fake codecs dentro de vídeos…
Estan apareciendo blogs con supuestos vídeos como el de la muerte de Benazir Bhutto. Cuando lo quieres ver te dice que te falta algún codec, el cual te tienes que descargar. Y en ese codec donde está el malware. Naturalmente, solo pueden "disfr…
December 29th, 2007 at 7:50 pm
i just got that puper on my computer when my sister went to look at one of her friends profiles on myspace. i dont think it just on websites that have videos about the PM being assassinated. i think it’s going to all kinds of websites. i been tryin to take it off, by following the instructions at McAfee but its not working. i think this is one trojan that can’t be removed.
December 30th, 2007 at 11:25 pm
i was infected by this when i was on a softball message board serioussoftball.com …message board illinois message stated britney did it again and like a fool i enterd the link and now i can not find a way to get rid of this.i dont know much about computers so im having a hard time
December 31st, 2007 at 8:55 am
It is so crazy how much social engineering plays into a lot of today’s attacks. That is one thing that software cannot overcome, human curiosity…like an email with the subject “I Love You”. How simple that sounds now, but genius at the time it came out.
Maybe, some day, software can help fend off curiosity!
All the best,
Michael Rowles
CopiaTECH
SMB Security