A trojan attacks Firefox masquerading as Adobe Flash Player update


Recommended Posts

Trend Micro threat analysts were alerted to the discovery of a spyware (detected as TSPY_EBOD.A) purporting to be an Adobe Flash Player update. Upon execution, the spyware creates a Firefox add-on called ?Adobe Flash Player 0.2,? the installer of which uses JavaScript (detected as JS_EBOD.A) and appears to spread via forum posts.

TSPY_EBOD_A.jpg

The said add-on injects ads into the user?s Google search results pages. More disturbing, however, is its capability to monitor the user?s browsing activities, particularly his/her Google search queries using the Firefox browser. It then sends the information it gathers to http://{BLOCKED}jupdate.com.

We have seen a lot of malware target Internet Explorer in the past. This is probably one of the reasons why a huge number of users are opting to use alternative browsers such as Firefox, Chrome, Safari, and Opera instead. Though this used to be considered a safe computing practice it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxor:rolleyes::rolleyes:

http://blog.trendmicro.com/firefox-addo-sp...search-results/

probably going to get blocked with an update

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Extensions can be easily installed without prompt. Not through Firefox but through Windows.

Yeah, amazing how secure is FireFox..... :unsure:

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

But that required a user to install something to do that in the first place.

Though this used to be considered a safe computing practice before, it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxb>:rolleyes:s:

Right. Like we're all going to stop using Firefox because of this:rolleyes:s:

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

That is because you read - As the very old saying goes "There is one born every minute". And I make my living cleaning up after they click 2x's without reading what they are clicking on.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation. Firefox is responsible for the security of its own script addons, not Microsoft.

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

When you get off your high horse and stop assuming that a program is secure just because it prompts you on everything, you'll realize that social engineering is exactly how malware spreads these days.

Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

I think you have a wrong computer software knowledge mate.

The FireFox ADDON/Extension, have NOTHING to do with Microsoft. The problem is in FireFox square.

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation.

The .NET plugin provided an uninstallable extension.

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

Did it install an extension without permission? Check.

Did it introduce a vulnerability? Check.

Did it not provide an uninstaller? Check.

I wouldn't qualify it as malware as that would imply an intention to do harm that I'd hope this didn't, but it still shares those three qualities though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Adobe Acrobat Reader DC 2026.001.21651 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The consumer ESU is ending in 4 months. LTSC isn't now, never has been, and never will be for consumer use, it is for OT usage - plant machinery, medical devices, manufacturing equipment etc. LTSC requires a Microsoft EA. You can't legally obtain LTSC to run on your PC at home.
    • Hmm actually looks decently interesting!  
    • Being on GitHub doesn't make something safe. Like any unofficial scripts to do x or y this caters to people with just enough knowledge to be dangerous. If you want to do what this does, and you actually know what you're doing then write your own script (or maybe just add the reg keys yourself) if you don't have the ability to read and understand what a script is doing, and especially don't run it with elevated privileges. Or in this case just use an MSA, sign up the normal route, and stop trying to push water up hill
  • Recent Achievements

    • Week One Done
      JKR earned a badge
      Week One Done
    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      490
    2. 2
      PsYcHoKiLLa
      271
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      64
  • Tell a friend

    Love Neowin? Tell a friend!