wannabegeek.org
Home Page arrow Software NewsFlash arrow New MSN Messenger Trojan Spreading Quickly
Monday, 08 September 2008
Main Menu
Home Page
Search
About
Forum
Free File Hosting
Downloads
Download Links
Software Library
LINK Exchange
Blog
Privacy Policy
Legal Stuff
SiteMap
Contact Us
Articles & Guides
Beginners guides
Essential Software
Basic System Maintenance
Learn Programming
Make Your Own Webpage
Host Your Own Web Page
Apache and XP
WGA What really works?
MuBlinder Tutorial
Vista Review
Administrator





Login Form





Lost Password?
No account yet? Register
We have 1 guest online
wannabefriends



How-to Computer Guides for the Rest of Us
WinVistaClub
Technoworld
Keep up with the fast paced world of tech and computers

TechFreakiez - Gadgets, Technology, Entertainment & Wallpapers
JCXP.net
wannabegeek

linkexchange
msfn
9down
New MSN Messenger Trojan Spreading Quickly
Written by Lisa Vaas   
Wednesday, 21 November 2007
Digg!

Del.icio.us!

Slashdot!

Technorati!

New MSN Messenger Trojan Spreading Quickly

An MSN Messenger Trojan is growing a botnet by hundreds of infected PCs per hour.

A Trojan is introducing malware into thousands of computer systems worldwide, and the number is growing by trojan.jpgthe hour.

The malware is being introduced by MSN Messenger files posing as pictures, mostly seeming to come from known acquaintances.

The files are a new type of Trojan that has snared several thousand PCs for a bot network within hours of its launch earlier on Nov. 18 and is being used to discover VNCs—remote PC connections—as a means of increasing its growth vector.

The eSafe CSRT (Content Security Response Team) at Aladdin—a security company—detected the new threat propagating around noon EST on Nov. 18. At 18:00 UTC (Coordinated Universal Time), eSafe had detected 1 operator and more than 500 on-command bots in the network. Less than three hours later, or by 2:30 EST, when eWEEK spoke with Ofer Elzam, eSafe director of product management, the number had soared to several thousand PCs and was growing by several hundred systems per hour.

eSafe is monitoring the IRC channel used to control the botnet. The only inhabitants of the network besides the operator are in fact infected PCs.

The Trojan is an IRC bot that's spreading through MSN Messenger by sending itself in a .zip file with two names. One of the names includes the word "pics" as a double extension executable—a name generally used by scanners and digital cameras: for example, DSC00432.jpg.exe. The Trojan is also contained in a .zip file with the name "images" as a .pif executable—for example, IMG34814.pif.

The files are infiltrating new systems by using either known contacts from which the Trojan has harvested instant messaging names, as well as from the systems of unknown users.

The infection vector—an IM program—isn't new. But the Trojan is the first that eSafe has tracked that has tried to scan for VNC (Virtual Network Computing) instances, likely in order to multiply the botnet's number of connections.

Elzam said that the Trojan shares common characteristics with other Trojans, looking like "a flexible Swiss Army knife" with multiple processes to steal passwords, to spread the infection and to deliver spam, for example.

PointerAre VM rootkits the next big threat? Click here to read more.

Given the familiar social engineering aspect of the attack, individuals are being urged to not open files sent unexpectedly from either friends or strangers.

eSafe hasn't determined what criminal activity the botnet is up to at this point.

source: eweek.com


Comments
Add NewSearchRSS
Write comment
Name:
Email:
 
Website:
Title:
UBBCode:
[b] [i] [u] [url] [quote] [code] [img] 
 
 
 
Security Image
Please input the anti-spam code that you can read in the image.

Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved.

 
< Prev   Next >
News Menu
Latest
General
Windows News
Torrent News
Vista
Windows7
Beta News
Software NewsFlash
How To News
Technology News
Space News
Gadget News
Gaming News
Music
FAQ
Windows XP
Windows Vista
Windows Live Messenger
Windows Info
Top Downloads
File Icon muBlinder 3.54 (81371)
(muBlinder Versions)

File Icon wpa_registry (19014)
(WGAFix)

File Icon WindowsLicence.rar (17938)
(WGAFix)

File Icon VistaLoaderV2.1.3 (17475)
(Vista Activation)

File Icon VistaSP1_Loader_3.0.0.1.zip (16256)
(Vista Activation)

File Icon Vista Activation (15971)
(Vista Activation)

Download Categories
muBlinder & blinders
XP Activation
Vista Activation
WGA Fix
Cool Utilities
Joomla Bits
Miscellaneous files
Games
Geek Code
--BEGIN GEEK CODE BLOCK--
GE/CS d++ s:++>: a+ C++ LU--- P++ L+ E---W++(+)
N++ o-- K w++ O--- M-- V PS PE Y PGP- t++
5X++ R->$ tv- b+ DI++ D G+ e++ h--- r+++ z+++

--END GEEK CODE BLOCK--
Syndicate
 
© 2008 wannabegeek.org
wannabegeek! Computer Guides, News and how to .
wannabegeek.Inc