English   German
  #1  
Old 06-12-2005, 13:33
AMessler AMessler is offline
-= TeamSpeak Addict =-
 
Join Date: Aug 2005
Location: Phoenix, Az
Posts: 249
AMessler is a name known to allAMessler is a name known to allAMessler is a name known to allAMessler is a name known to allAMessler is a name known to allAMessler is a name known to all
Send a message via AIM to AMessler Send a message via MSN to AMessler Send a message via Yahoo to AMessler
New AIM worm

Malware authors just opened their own holiday season. We received couple of reports of a new AIM worm spreading. The worm is simple and doesn't exploit any vulnerability; instead it relies on social engineering.

The user will receive the following AIM message:

"This AIM user has sent you a Greetings Card, to open it visit: http://greetings.aol.com/index.pd?so...ristmas_card.C OM"

Instead of going to the AOLs site, this link actually points to a different site (http://<REMOVED>.<REMOVED>.134.156/My_Christmas_Card.COM) from which the user will download the worm. This file is a SDBot variant and at the moment the most popular AV programs detect it generically.



Update: There is also a variant going around that redirects to the same IP, but downloads, My_Christmas_Card.SCR. Note, that many of the AV vendors identify this as a variant of SDBot.
Reply With Quote
  #2  
Old 13-12-2005, 21:54
0wn4g3 0wn4g3 is offline
-= TeamSpeak User =-
 
Join Date: Nov 2005
Location: DontWorryAboutIt
Posts: 17
0wn4g3 is on a distinguished road
Thanks for the update. I remember about 2-3 months ago various buddies on my aim buddy list would send me I'Ms with a link and if I hover over the link the end of the link would not be html it would be .com which is warning sign #1. Was SDbot the culprit earlier?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 05:10.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Add to Bookmarks   |   Printview   |   Contact Us   |   Legal Notices