Jump to:
Sweepstakes Advantage Online Forum
October 06, 2008, 12:06:31 PM *
Welcome, Guest. Please login or register.
News: Welcome to the SA Sweepstakes Forum!
 
  SA Main   Home   Help Arcade Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Trojan masquerades as IE 7 downloads  (Read 603 times)
0 Members and 1 Guest are viewing this topic.
greensthings
SA Member
SA Gold Member
****
Offline Offline

Posts: 2734



WWW
« on: April 01, 2007, 12:30:29 PM »

http://blogs.zdnet.com/security/?p=142&tag=nl.r25282
Quote
Spammers are using fake Internet Explorer 7 (Beta 2) downloads to lure Windows users into downloading a nasty backdoor Trojan.

The fake downloads are part of a massive spam run that includes an official-looking graphic (see image below) linked to Web sites that auto-launch an executable named "ie7.exe."

A copy of this spam that landed in my GMail inbox arrived from "admin@microsoft.com" with the subject line "Internet Explorer 7 Downloads."  Anti-virus vendors tracking the threat say the sender address and download locations are constantly changing as this spam run picks up steam.

As fast as these domains appear, get spammed, and get killed, they re-appear. If you run a network stream, you can easily look for “/IE7.0.exe” with a tool like ngrep or flowgrep and look at the download sites. This one is aggressive and is going to get a lot of play. AV detection was poor earlier in the day, and it’s not much better. Names like Agent.CL and Grum are being used, but even 12 hours later the detection for it is pretty weak. It’s got an unrecognized packer and some methods that seem uncommon.

 
Logged

Sweepstakes Advantage Online Forum
« on: April 01, 2007, 12:30:29 PM »

 Logged
ll1
Electrical Specialist
SA Mods
SA Gold Member
****
Offline Offline

Posts: 32943


TEXAS


« Reply #1 on: July 19, 2007, 07:55:44 AM »

this is one that everyone should be aware of make sure when you download anything that you do it @ the official site by typing the url in!
Logged

Sweepstakes Advantage Online Forum
   

 Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!