Tuesday January 6, 2009 10:38 PM AEST
Latest Comments
"Discontinuing the issuance of MD5 certs is a good first step, but the real problem is that the ..."
by Scott | Jan 6, 2009 3:13 PM
 
"ineed nokia 6120c-1"
by Dipak Ahikari | Jan 6, 2009 2:04 PM
 
"My facebook profile has been hacked through one of these sites and they have changed my password ..."
by Ryan geen | Jan 3, 2009 3:51 PM
 
"http://impresser.com.au/category/security/ We need more websites like this. Security is an ..."
by Andrew Galdes | Dec 27, 2008 3:46 PM
 
"Um... what product were you really using???? documentation is supplied in printed form (aka a ..."
by Glen | Dec 23, 2008 12:11 PM

MSN Messenger spam contains Trojan

  • Email a Friend
  • Print Page
By Dan Raywood
Oct 16, 2008 10:20 AM
Tags: MSN | Messenger | spam | contains | Trojan
A fake update claiming to be from MSN Messenger contains a malicious Trojan.

Identified by the Websense Security Labs ThreatSeeker Network, the spam message is intended to lure users into downloading the Trojan. The claims that by downloading the application linked within the email, users can protect themselves against a virus that spams messages to a user's contacts.

The email offers an update to Live Messenger Plus which upon accessing downloads the Trojan (md5: 5F1D2521F6949F8B71B9FF93C17A8BE2), which Websense claims has a low antivirus detection rate.

The URLs provided in the email redirect the user to a two-stage downloader named dsc.scr. As a distraction for the user, a dialog box is displayed explaining that the user will be redirected to msn.com.br, a browser then opens pointing to this site.

The downloader first contacts hxxp://*snip*ario.com/games_06.jpg, and then hxxp://*snip*ario.com/games_04.jpg, adding the two files to the root of C:

A scheduled task is then created, and modifications are made to autoexec.bat to disable GBPlugin and other tools promoted by Brazilian banks to protect against such keyloggers and other malware.

The malware then goes on to conduct information-stealing activities.

See original article on scmagazineuk.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Messaging Whitepapers