Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Update on Osama Bin Laden themed Malware - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Update on Osama Bin Laden themed Malware

So far, we have seen very little Osama Bin Laden themed malware. The most prominent case that was discussed by a number of sites took advantage of facebook.

The page asks the user to copy / paste javascript into the URL. This technique isn't new, and it is still amazing what people will do to watch videos. The javascript wil... you guessed it... load more javascript.

Here a quick rundown of what the javascript will do:

- Send a message "See the Osama Bin Laden EXECUTION Video!" (full URL omited)
- add a message to your status pointing to the "video"

Some of the domain names and IP addresses involved in this scam:

- (see code below)
- and (URL shorteners used by the scam. not all URLs at these domains are malicious)
- (tries to download a file called "laden.png". However, this file no longer appears to be available)
- (a non-malicious newspaper site. Only used to downlaod a "Loading" indicator)
- - hosting an HTML page shown after the script runs





Johannes B. Ullrich, Ph.D.
SANS Technology Institute

I will be teaching next: Application Security: Securing Web Apps, APIs, and Microservices - SANS London June 2022


4479 Posts
ISC Handler
May 3rd 2011



21 Posts
We are seeing Phishing Incidents where users are being directed to an external site to watch a video. They are being offered to download an exe which then tries to disabled Antivirus's.
The malware is being hosted on this site:

Anubis malware analysis of the Exe:
Anubis malware analysis of the initial site:


When the exe is ran, it installs a irc client, attempts to turn off Antivirus, but is currently not getting grabbed. Once installed it blocks access to security vendor sites. According to the Conficker Eye Chart, it lists as a possible Conficker A/B Variant.
2 Posts

Sign Up for Free or Log In to start participating in the conversation!