Posting Freak
Posts: 7,905
Threads: 472
Joined: 2008-07
http://www.nationmultimedia.com/home/201...31457.html
Article Wrote:One entry of note in the end-user Top Twenty malware list was a Trojan that steals account logins and passwords for popular online games. Players of CabalOnline, Metin2, Mu Online and various games developed by Nexon.net have all been affected by Trojan-GameThief.Win32.Magania.dbtv.
So yeah...
Posting Freak
Posts: 970
Threads: 25
Joined: 2010-03
Gender: Male
IGN: LunaMimosa
Server: El Nido
Level: 134
Job: OP Elf Queen
Guild: Some no-name guild
Guild Alliance: Read above.
Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.
Unless... this trojan hit nexon directly ;] then that explains it.
Posting Freak
Posts: 7,905
Threads: 472
Joined: 2008-07
Seanny Wrote:Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.
Unless... this trojan hit nexon directly ;] then that explains it.
Well, it's just something I came accross that felt was relevant. It is almost assuredly not the entire cause, but may very well have been a large portion.
Posting Freak
Posts: 4,440
Threads: 122
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: spain
Seanny Wrote:Only problem with that theory is it doesn't explain the players who had multiple accounts; yet only one of them got hit. (like mine) Even more odd was it was my inactive account.
Unless... this trojan hit nexon directly ;] then that explains it.
It does explain it. They have the logins, the passwords... BUT they don't know who's who. You just got unlucky, same with a lot more.
Posting Freak
Posts: 18,970
Threads: 319
Joined: 2008-07
The question is now how was it spread.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Alloy Wrote:It does explain it. They have the logins, the passwords... BUT they don't know who's who. You just got unlucky, same with a lot more.
No, it wouldn't explain it because they'd have the logins and passwords for everyone you used during the infected period, and no one else.
There were way too many people who were hit on accounts that were completely inactive, or were using accounts on one nexon game that didn't have all the required pieces to let you login to Maple, like my guild - We were all strictly mabinogi during this period and had been for months but they didn't have to change our PINs which aren't used in mabi and several of us were hit on maple accounts that were different from our mabi ones anyhow.
Posting Freak
Posts: 7,905
Threads: 472
Joined: 2008-07
Eosian Wrote:No, it wouldn't explain it because they'd have the logins and passwords for everyone you used during the infected period, and no one else.
There were way too many people who were hit on accounts that were completely inactive, or were using accounts on one nexon game that didn't have all the required pieces to let you login to Maple, like my guild - We were all strictly mabinogi during this period and had been for months but they didn't have to change our PINs which aren't used in mabi and several of us were hit on maple accounts that were different from our mabi ones anyhow.
Like I said, it might explain a few, but not all. Regardless, it was worth bringing to everyone's attention.
Member
Posts: 93
Threads: 14
Joined: 2009-12
I'm not too good on this internet stuff, just wondering, how could someone sneak a trojan into a program like that?
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
No one has said what the trojan was attached to. There was no implication it was embedded in the actual applications named, only that it targeted them.
Member
Posts: 93
Threads: 14
Joined: 2009-12
Oh I see, sorry for the misunderstanding. I wonder what could have given the mass of people hacked that trojan, my guess is it probably was some popular website filled with malicious ads, alot of the sites I visit are having those "malicious ads" lately.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
My guess is it's completely unrelated because there is and has been no trace of this or any other trojan, virus, worm, or other malware on any machine in my network.
Posting Freak
Posts: 6,092
Threads: 186
Joined: 2008-07
Eosian Wrote:My guess is it's completely unrelated because there is and has been no trace of this or any other trojan, virus, worm, or other malware on any machine in my network.
Supposing it's a newly written malware, how do you tell if it is one?
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Kalovale Wrote:Supposing it's a newly written malware, how do you tell if it is one?
Not having downloaded or installed anything new, and having had nothing new show up in Process Explorer are pretty good give aways.
It autoloads in all my machines and I tend to watch the full command line and parameters of all running processes the way normal people use screen savers.
Although If it's truly newly written it couldn't be responsible for four months ago anyhow, now could it?
Test Mushroom
Posts: 10,045
Threads: 1,506
Joined: 2008-06
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
IGN: GuavaCowboy
Server: Zenith
Level: 10x
Job: Jett
Guild: L>
Even hidden processes, like HackShield/Maple, show up on the Process Explorer too? I thought it'd be all too easy to hide a process.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Rootkit Revealer prevents that, and before it can rootkit itself it'd still show up the initial stuff that's doing the naughty bits. Can't hide itself before it's done the hiding directives.
Hackshield and Maple both show up, that's why they refuse to run while process explorer is running. If they're able to detect it. Rootkits work both ways
Posting Freak
Posts: 6,092
Threads: 186
Joined: 2008-07
Eosian Wrote:Rootkit Revealer prevents that, and before it can rootkit itself it'd still show up the initial stuff that's doing the naughty bits. Can't hide itself before it's done the hiding directives.
Hackshield and Maple both show up, that's why they refuse to run while process explorer is running. If they're able to detect it. Rootkits work both ways 
pineapple I should've read this sooner, Maple just closed down on me. Hoping I'm not autobanned for having "hacking tools detected".
|