|







|
|
Top 10 malware reported to Sophos in June 2005
|
Trojan poses as Osama capture
pics |
| Spam emails that try to dupe Windows users
into infection by offering information about the supposed capture of
terrorist mastermind Osama bin Laden were sent to an estimated one
million surfers yesterday. The bogus emails attempt to seed infection of
a new downloader Trojan, Small-AXR, contained in a pics.scr file within
a zip attachment of the fraudulent messages.
The text of infected messages typically states:
Turn on your TV. Osama Bin Laden has been captured. While CNN
has no pictures at this point of time, the military channel (PPV)
released some pictures. I managed to capture a couple of these
pictures off my TV. Ive attached a slideshow containing all the
pictures I managed to capture. I apologize for the low quality, its
the best I could do at this point of time. Hopefully CNN will have
pictures and a video soon. God bless the USA!
Subject lines of the virus-infected email include: "God Bless
America!", "Captured! Finally!" and "Finally! Captured!". Anti-virus
vendors urge users to ignore any such message and, more particularly, to
avoid the temptation to click on the attachment.
Read
more here...
|
|
VXers love Britney Spears -
official |
Spanish anti-virus firm Panda Software has produced a
ranking of the famous people most often used to spread viruses on the
internet. The listing follows the recent distribution of a Trojan horse
malware using spam messages posing as information about a supposed
suicide attempt by Michael Jackson.
Exploiting society's fascination with celebrity to trick punters into
running malware is a common ruse. Celebrity malware is spread either in
viruses attached to infected emails or (increasingly commonly) loaded
onto maliciously constructed websites promoted using spam messages. Both
these types of attack invariably only target Windows PCs leaving Mac and
Linux users untouched. Serious security commentators, such as VMyths,
argue that focusing on the use of celebrities is nonsense that has
nothing to do with information security.
Read more here...
|
|
Fake news spreads
email virus |
Claims of Osama bin Laden's capture by US soldiers and conspiracy
rumours about Pope John Paul II's death are just two of the supposed
news stories tricking internet users into launching a new email virus.
The
Kedebe-F worm spreads itself through email posing as breaking news
stories about the supposed arrest of the author of the Mydoom worm and
the death of Michael Jackson, warns anti-virus firm Sophos. Windows
users who launch the attached file risk disabling their security
software and firewalls and passing the infection onto other computer
users.
Read
more here...
|
| |
W32/Mytob-CM is a mass-mailing worm and IRC backdoor Trojan.
W32/Mytob-CM runs continuously in the background, providing a backdoor
server which allows a remote intruder to gain access and control over the
computer via IRC channels.
W32/Mytob-CM can spread by sending itself as an email attachment to email
addresses it harvests from the infected computer.
W32/Mytob-CM modifies the Windows hosts file in order to block access to
security-related websites.
Emails sent by the worm have the following characteristics:
Subject line chosen from:
Security measures
Notice: **Last Warning**
*DETECTED* Online User Violation
Your Email Account is Suspended For Security Reasons
Account Alert
Important Notification
*WARNING* Your Email Account Will Be Closed
Email Account Suspension
Notice of account limitation
Message text chosen from:
Once you have completed the form in the attached file , your account records
will not be interrupted and will continue as normal.
The original message has been included as an attachment.
We regret to inform you that your account has been suspended due to the
violation of our site policy, more info is attached.
We attached some important information regarding your account.
Please read the attached document and follow it's instructions.
<random characters>
The attached file consists of a base name followed by the extensions PIF,
SCR, EXE or ZIP. The worm may optionally create double extensions where the
first extension is DOC, TXT or HTM and the final extension is PIF, SCR, EXE
or ZIP.
|
|
|
This web is optimized for 800 x 600 monitor resolution or above and
the latest web browser. Get the latest IE or Netscape web browser. (you
need to connect to the internet first) |
|
|