Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Keeping an Eye Out for the Sinowal Trojan

    Written by

    Brian Prince
    Published November 3, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      After eWEEK published the initial story last week about RSA finding a cache of data stolen by the Sinowal Trojan, several readers requested additional information.

      Here is a little more background on the Trojan, RSA’s findings and links to more information. Also identified as Torpig and Mebroot, Sinowal has rootkit elements that infect the Master Boot Record and allow it to hide. The Trojan has many variants, some of which are detectable by traditional anti-virus companies such as Symantec and McAfee. However, the number of variants and their low distribution volumes make it difficult for security vendors to keep track of the latest variants.

      For the past six months, RSA has observed at least 60 variants of the Trojan each month. A recent variant, submitted Oct. 21 to Virustotal, was detected by less than 30 percent of the 35 security vendors given the file.

      RSA investigators found nearly 300,000 online banking account credentials, as well as a roughly equal number of credit and debit account numbers and associated personal information. The cache of data represents bounty collected from Sinowal’s victims as far back as February 2006.

      “An analysis of the Sinowal Trojan itself identified a road map leading to the location commonly known as the drop zone, a point where Trojans send their stolen information,” said Sean Brady, manager of identity protection at RSA, EMC’s security division. “The drop zone itself was publicly exposed to the Internet, where the RSA FraudAction Research Lab was able to address the database and recover the credentials.”

      Vulnerabilities are fading from the threat foreground. Read more here.

      Once downloaded, Sinowal uses an HTML injection feature to inject new Web pages or information fields into the victim’s Web browser. When a user tries to visit one of 2,700 financial service domains, the fake site pops up instead and prompts the user for log-in or financial information. Detected variants target Windows 2000, XP, Vista and Windows Server 2003, according to various security vendors.

      “The best initial line of defense is to maintain an up-to-date anti-virus solution on your PC and use it to run a full system scan,” Brady advised. “However, the Sinowal Trojan can be challenging to detect once it is installed locally, since it uses rootkit techniques designed to evade detection.”

      Brady recommended that users keep an eye out for changes to Web sites they normally visit. For example, a prompt for personal information or for the user to download files in order to view a video could be a tip-off.

      “Knowing that their financial institutions should never randomly request personal information online, such as log-in credentials or Social Security numbers, [can be a defense],” he said.

      For those looking for a list of financial institutions, RSA has chosen not to publicize them, citing privacy and security. However, RSA officials said they have reached out to affected institutions as well as law enforcement.

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.