Advanced Bayrob trojan targets eBay users

Published March 9th, 2007


Symantec has warned eBay users that a sophisticated trojan is seeking to scam them with a man-in-the-middle attack.

Named Trojan.Bayrob, the malware changes user hosts files to redirect traffic destined to numerous eBay sites, including eBay Motors, to a local proxy server and listens on localhost port 80. From there, Bayrob downloads configuration data from the eBay servers, including a number of php scripts.

“The most interesting of these scripts is var.php; this script returns many different variables, which will be used in the attack,” Liam O’Murchu wrote on the Symantec Security Response blog. “The downloaded variables include tokenised versions of legitimate eBay pages.”

O’Murchu said that the exact motive behind Bayrob is still a mystery, since proxy servers are not yet using the right variables to start showing fake pages to users.





Related Articles
Symantec internet security warm of eBay motors Trojan
UK eBay users targeted in Trojan botnet attack
Robot targets eBay tax dodgers
Man-in-the-middle attack targets eBay
PC Plus - eBay’s advanced seller tools