Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Malformed FileZilla FTP client with login stealer
avast antivirus blog ^ | January 27th, 2014 | Malware Analyst Workforce

Posted on 01/28/2014 10:08:51 AM PST by Utilizer

Beware of malformed FileZilla FTP client versions 3.7.3 and 3.5.3. We have noticed an increased presence of these malware versions of famous open source FTP clients.

The first suspicious signs are bogus download URLs...

Malware installer GUI is almost identical to the official version. The only slight difference is version of NullSoft installer where malware uses 2.46.3-Unicode and the official installer uses v2.45-Unicode. All other elements like texts, buttons, icons and images are the same.

The installed malware FTP client looks like the official version and it is fully functional! You can’t find any suspicious behavior, entries in the system registry, communication or changes in application GUI.

The only differences that can be seen at first glance are smaller filesize of filezilla.exe (~6,8 MB), 2 dll libraries ibgcc_s_dw2-1.dll and libstdc++-6.dll (not included in the official version) and information in “About FileZilla” window indicates the use of older SQLite/GnuTLS versions. Any attempt to update the application fails, which is most likely a protection to prevent overwriting of malware binaries.

(Excerpt) Read more at blog.avast.com ...


TOPICS: Business/Economy; Computers/Internet; Reference
KEYWORDS: downloading; hacking; malware; passwords
Navigation: use the links below to view more comments.
first previous 1-2021-26 last
To: Utilizer

M4L


21 posted on 01/28/2014 11:33:07 AM PST by Scrambler Bob ( Concerning bo -- that refers to the president. If I capitalize it, I mean the dog.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FReepers
Did You Know?

The Current FReepathon Pays For The Current Quarters Expenses?

Please Donate And Keep FR Running


22 posted on 01/28/2014 11:38:04 AM PST by DJ MacWoW (The Fed Gov is not one ring to rule them all)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dfwgator
I generally use download.cnet.com.

SourceForge and Freecode are quite reliable. Some would argue more so.

23 posted on 01/28/2014 11:51:19 AM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the mooslimbs trying to kill them-)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Utilizer

I’m sorry I am so uneducated with computers, but I know my computer has been hacked.. I downloaded FileZilla, but don’t know how to run the program, can anyone help.. I know, I’m an idiot..


24 posted on 01/28/2014 1:36:18 PM PST by carlo3b (Corrupt politicians make the other ten percent look bad.. Henry Kissinger)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Utilizer

Thanks for posting this info. Fortunately, my copy seems to have been unaffected, but I passed this along to other users.


25 posted on 01/28/2014 1:36:33 PM PST by unlearner (You will never come to know that which you do not know until you first know that you do not know it.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

“My favorite advice. Heck, at least half the LEGIT download sites want to use their own damn installable downloader,”

Yep. We mostly don’t need sophisticated downloaders any more so what’s up with those? I don’t know nor care. I prefer to download from the developer’s own site whenever possible.


26 posted on 01/28/2014 3:11:44 PM PST by expat1000
[ Post Reply | Private Reply | To 10 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-26 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson