Categorized | Security

i can haz flaming recon pls?

If you play Halo, you probably know that the Recon Armor is a rare armor variant that is only available to the makers of Halo, Bungie, and players who have unlocked all Vidmaster challenges in previous versions of the game. With the recent release of Halo: Reach, a lot of users are looking for free means to get hold of this armor for their game play.  Apparently, malware writers also took notice of this opportunity to distribute malware masking as code generators for the flaming recon helmet and Halo Reach itself. 


Figure 1 – Recon Armor

We came across two samples, detected as PWS:Win32/Fignotok.A, named  “Mod V3xD.exe” (Sha1: 1855974d848568968f4c97871a70fa42aff8fbc8) and “Halo Reach Flaming Recon.exe” (Sha1: 775c62aa8530eb616ff5444298d3dc4cff5c823e).   These both drop a file named “haloreachflamingrecon.exe” that promises to generate code for the Recon Armor but instead steals the user’s Xbox Live credentials by asking the user for logon details (see Figure 2 below) and sending it to a remote attacker via email.  It also connects to a remote location, which is now inaccessible, from where it gets other configuration files.


Figure 2 – Enter your XBox Live account details to activate your Flaming Recon! But actually, just watch your credentials get stolen.

Another malware family that banks on the popularity of the Halo franchise has the file name “Halo Reach Generator.exe” (Sha1: 7ab2f6cbacd967aa72360af76e666e3c6cbf56ec) and is already detected as Worm:Win32/Rebhip.A. This worm can spread via removable drives and can steal sensitive information as well.

So think twice before sprucing up that armor through code-generators, as this might lead to your account being gamed. Everyone hates cheaters, and fair play earns you those bragging rights too.

Marianne Mallen
MMPC Dublin

View full post on Microsoft Malware Protection Center

Related Posts

suspicious cloud 7 f

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago