AplusWebMaster
Topic Starter
FYI…
- http://www.viruslist.com/en/weblog?weblogid=208187339
March 22, 2007 ~ "This morning we saw a massive malware run in the Netherlands. The emails were purportedly sent by the Dutch ABN-AMRO bank. Of course, as I’ve said before, phishing attacks on users of Dutch banks are relatively rare. Prior to this mailing, we’ve only seen basic phishing runs which try and persuade the user to clink on a link. But this morning gave us a first - an email in Dutch, claiming to be from a Dutch bank, and containing malware - Trojan-Spy.Win32.Banker.cmb, an online banking Trojan…"
- http://www.viruslist.com/en/weblog?weblogid=208187342
March 23, 2007 ~ "…This Banker variant has two main payloads: it accesses PStore to harvest passwords, and captures all information submitted via web forms. Banker.cmp watches for traffic relating to citibank(.de) and bankofamerica. So it's kind of strange that this malware was sent to Dutch ABN-AMRO users. I would guess the cyber criminals are aiming to get any passwords they can, and see Citibank and BankofAmerica data as a bonus…"
- http://www.f-secure.com/weblog/archives/ar…7.html#00001149
March 23, 2007 ~ "We last posted about a Nurech run on February 19th using Ikea Deutchland as their supposed front. This time the Nurech gang is riding on 1&1, an Internet hosting provider. We have received reports of a large amount of e-mails in Germany. It seems that the gang is monitoring the success of their trojan. As soon as the antivirus industry caught up with the first downloaded malware (Trojan-Spy.Win32.BZub.IJ), they changed it to another one. We detect the current downloaded file as Trojan-Spy:W32/BZub.IK … The downloader itself ( Trojan-Downloader:W32/Small.EJK )…"

- http://www.viruslist.com/en/weblog?weblogid=208187339
March 22, 2007 ~ "This morning we saw a massive malware run in the Netherlands. The emails were purportedly sent by the Dutch ABN-AMRO bank. Of course, as I’ve said before, phishing attacks on users of Dutch banks are relatively rare. Prior to this mailing, we’ve only seen basic phishing runs which try and persuade the user to clink on a link. But this morning gave us a first - an email in Dutch, claiming to be from a Dutch bank, and containing malware - Trojan-Spy.Win32.Banker.cmb, an online banking Trojan…"
- http://www.viruslist.com/en/weblog?weblogid=208187342
March 23, 2007 ~ "…This Banker variant has two main payloads: it accesses PStore to harvest passwords, and captures all information submitted via web forms. Banker.cmp watches for traffic relating to citibank(.de) and bankofamerica. So it's kind of strange that this malware was sent to Dutch ABN-AMRO users. I would guess the cyber criminals are aiming to get any passwords they can, and see Citibank and BankofAmerica data as a bonus…"
- http://www.f-secure.com/weblog/archives/ar…7.html#00001149
March 23, 2007 ~ "We last posted about a Nurech run on February 19th using Ikea Deutchland as their supposed front. This time the Nurech gang is riding on 1&1, an Internet hosting provider. We have received reports of a large amount of e-mails in Germany. It seems that the gang is monitoring the success of their trojan. As soon as the antivirus industry caught up with the first downloaded malware (Trojan-Spy.Win32.BZub.IJ), they changed it to another one. We detect the current downloaded file as Trojan-Spy:W32/BZub.IK … The downloader itself ( Trojan-Downloader:W32/Small.EJK )…"