Malicious Spam Related to False Porntube Page

It seems that the activity of this type of spamtraps has increased since the first time we detected it last week.Like every spam message with malicious intentions, it tries to attract the user’s attention with interesting subjects so that they visit the attached link.Below we can see some of the subjects used:"Eiffel Tower suffers structural damage, collapse possible?""London rocked by gas attack, army on high alert?"Britney found hanged in locker room?Celtics disqualified from NBA title?China Earthquake claims 1 million lives?Dan Brown's latest novel?Nokia unveils revolutionary new phone design?Obama withdraws from elections?The attached links can be different regarding their domain, though those we have seen up to this moment make reference to a file /r.html, which is a fake website of Porntube.Once there, an error message will be displayed indicating the user that they need to install a component of Video ActiveX, which will install the file ideo.exe detected as Trj/Exchanger.GAlthough the malware is hosted in the same domains to which the link of the spam makes reference, it connects to an IP address located in Beijing [ CHINA ] from which the creator probably view the statistics of the infected computers.


original article

Tags: ,

Posted under Malware Alerts

This post was written by Ted on June 20, 2008

Tags: ,

Microsoft Security Advisory (954474): System Center Configuration Manager 2007 Blocked from Deploying Security Updates - 6/17/2008

Revision Note: June 17, 2008: Advisory updated to reflect availability of fix. Advisory Summary:Microsoft has completed the investigation into public reports of a non-security issue that affects environments with all supported versions of System Center Configuration Manager 2007 that deploy updates to Systems Management Services (SMS) 2003 clients. Microsoft has confirmed those reports and has released an update to correct this issue under Microsoft Knowledge Base Article 954474. Microsoft encourages customers affected by this issue to review and install this update.

Tags:

Posted under Microsoft Security Alerts

This post was written by Ted on June 18, 2008

Tags:

T2W –> Trojan to Worm

We have detected an application whose main function is to turn an executable file into a worm, giving it the capacity to spread itself. Even though it’s aim is to give a Trojan the spread capability of a worm, it works with any executable file.As you can see in the image below, it is an eye-catching tool and very easy to use. By checking different flags, you can design a worm with different functionalities, such as compress it with UPX, enable MuteX, select icons, etc.It also has advanced options to select a certain infection date, disable different options of the operating system, such as the Task Manager, the Windows Registry Editor, Folder Options, and different browsers such as Internet Explorer, Firefox or Opera. Additionally, the worms can be configured to display a message when they are run or activate themselves when Windows is started.One curious option is that you can avoid the infection of removable drives, such as PenDrives, indicating the username and the name of the drive.The tool seems to have been created in Spain. You can switch the language of the tool to English, Spanish, Portuguese and Catalan. As you can see, nowadays there are tools that allow any user, no matter their technical knowledge, to create malware very easily.Thanks to Oscar Anduiza for the information.
original article

Tags: , ,

Posted under Malware Alerts

This post was written by Ted on June 17, 2008

Tags: , ,