This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Not-So-Fun Video Postcard

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://preview.tinyurl.com/ypcez2
February 26, 2007 ~ "A variety of bulletin boards are being spammed with the message to visit mailfreepostcards . com (DO NOT GO THERE) for a fun video. However, when visiting that site, users are prompted to download an executable. Message board spam is nothing new, but what is different about this message board spam is the spam text is actually integrated into legitimate messages posted by real users. Posters are infected with an updated version of Trojan.Mespam, which is downloaded by Trojan.Peacomm. This threat has the ability to watch all your network traffic via a layered service provider (LSP) and when it notices you posting to a bulletin board, it modifies your posting to include the spam text. Trojan.Mespam can not only inject text into your outgoing forum posts, but also in Web mail provided by Tiscali, Earthlink, Comcast, Bellsouth, Gmail, Rambler, FastMail, Care2, mail.com, Hotmail, Yahoo, Lycos, AOL, and mail.ru. In addition, the updated threat still injects messages into outgoing instant messages for Gtalk, Yahoo Messenger, AIM, and ICQ. The Trojan has the ability to update the message and the URL, so the actual URL will likely change soon—especially as soon as we are able to close down that domain. In the meantime, don't click on unrelated links in forum postings, email, or IM, and definitely avoid executing any files you receive from unsolicited links. If you notice that in your own email, forum postings, or IMs you are sending out odd additional text or URLs, you are likely infected…"

:ph34r:
More on same…

- http://preview.tinyurl.com/36dl9k
February 27, 2007 ~ (Computerworld) "A new variant of the "Storm" Trojan is injecting its come-on into blogs, Web-based message forums and Webmail as part of an effort to spread itself to an ever-widening net of PCs… An initial infection is still carried out via e-mail, which touts a link that when clicked downloads a number of malware components to a victimized machine. Once on a PC, however, the malicious code injects itself into the network stack as a rootkit and analyzes all outbound Web traffic. "It has hooks for boards, e-mail, and blogs," said Alperovitch. When a user on an infected PC posts a message to a forum or blog, or sends a message via popular Web-based mail services such as Hotmail, Gmail, and Yahoo Mail the Trojan adds text to the entry or message. "It inserts 'Have you seen this link?' along with a link to what seems to be a video," Alperovitch said. Anyone clicking on the link will only find their system infected… Secure Computing has seen evidence of the bogus posting on messages forums, including one for Men's Health, as well as "thousands of blog entries," said Alperovitch. The Trojan has been making the rounds since January… Since then, it has been collecting compromised PCs into a botnet of zombies that can be used for sending spam. Other malware downloaded to infected machines tries to steal passwords or uses the PC to launch distributed denial-of-service (DDoS) attacks…"

:ph34r: