AplusWebMaster
Topic Starter
FYI…
- http://sunbeltblog.blogspot.com/2008/02/da…-greetings.html
February 13, 2008 - "Clicking on the spammed link takes you to a page that tells you that you need to update your Flash player to view the card. However, the cab file that downloads is actually malicious and installs a variant of small.lu (aka ntos or Monster Trojan). This is a very nasty data-stealing trojan. In fact, it’s an even more dangerous variant of Small.lu as it is using a rootkit to hide… The American Greetings page is convincing, and the Active/X install is signed… Very poor detection (4 out of 32 scanners) of the cab file itself (VT result here*), and poor detection (5 out of 32 scanners) of the actual binary, “update.exe” (VT result here**)…"
* http://www.virustotal.com/analisis/40b4fae…ce2e3ec744136a8
** http://www.virustotal.com/analisis/c43f7d8…1276e5628c5d54b
(Screenshots available at the Sunbelt URL above.)

- http://sunbeltblog.blogspot.com/2008/02/da…-greetings.html
February 13, 2008 - "Clicking on the spammed link takes you to a page that tells you that you need to update your Flash player to view the card. However, the cab file that downloads is actually malicious and installs a variant of small.lu (aka ntos or Monster Trojan). This is a very nasty data-stealing trojan. In fact, it’s an even more dangerous variant of Small.lu as it is using a rootkit to hide… The American Greetings page is convincing, and the Active/X install is signed… Very poor detection (4 out of 32 scanners) of the cab file itself (VT result here*), and poor detection (5 out of 32 scanners) of the actual binary, “update.exe” (VT result here**)…"
* http://www.virustotal.com/analisis/40b4fae…ce2e3ec744136a8
** http://www.virustotal.com/analisis/c43f7d8…1276e5628c5d54b
(Screenshots available at the Sunbelt URL above.)