Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Hydraq Trojan/Aurora Attack (MS10-002)

Subscribe

Check Point Reference: CPAI-2010-100
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS10-002
ThreatExpert Blog
Industry Reference(s): CVE-2010-0249
Protection Provided by: Security Gateway
  • R70
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Vulnerability Description
The Hydraq Trojan (also known as Aurora) was being used in the recent attack against Google and other large companies. A then unpatched Internet Explorer vulnerability (CVE-2010-0249) was used as one of the propagation vectors for this Trojan. The intent of the trojan is to open a back door on a compromised computer allowing a remote attacker to monitor activity and steal information from the compromised computer. Once installed inside a corporate network, the Trojan can also allow the attacker to use the initially compromised computer to launch into the rest of the infrastructure.
Vulnerability Status
The vulnerability is being actively exploited in the wild.
Update/Patch Available
Microsoft has released a cumulative security update for Internet Explorer:
Microsoft Security Bulletin MS10-002
Vulnerability Details
Upon installation on a computer, Trojan.Hydraq attempts to make contact with a command and control server in order to receive instructions and to upload any information that it may have collected. The Trojan will then be able to create, modify, and delete registry files, read and execute attributes of files, restart and shut down the computer, adjust token privileges and more.

Protection Overview
This protection detects and blocks connections over port 443 that appear to be running the Aurora/Hydraq protocol.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway R70

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Application Intelligence > Malware Traffic.
2. In the right pane, double-click the following protection:

Trojan: Aurora.Hydraq

3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Malware Traffic
Attack Information: Trojan: Aurora.Hydraq

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Network Security > Trojans and Remote Administration, and select the Aurora / Hydraq protection group.
3. Click Aurora / Hydraq trojan (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Aurora / Hydraq Trojan Detector
Description: Aurora / Hydraq trojan