Welcome Guest | |
Follow Us:
    
Newsletter Signup:
Michael Jackson Death Prompts Malicious Spam
The spam e-mail appears to offer a link to a YouTube video, but instead sends the recipient to a Trojan Downloader hosted on a compromised website NC News Network, June 30, 2009
      

Websense Security Labs ThreatSeeker Network has discovered spam e-mails offering recipients links to unpublished videos and pictures of singer Michael Jackson.


The spam e-mail appears to offer a link to a YouTube video, but instead sends the recipient to a Trojan Downloader hosted on a compromised website. The file offered is called Michael.Jackson.videos.scr, which is located on a legitimate website hosted in Australia belonging to a radio broadcasting station.


Upon executing the file, a legitimate website at http://musica.uol.com.br/ultnot/2009/06/25/michael-jackson.jhtm is opened by the default browser in order to distract the user by presenting a news article for them to read.


In the background, three further information-stealing components are downloaded and installed by the malware. One of the downloaded files is called michael.gif, which has low AV detection rates. The malware then installs a malicious BHO that is registered with the file %windir%\Dynamic.dll and this GUID {FCADDC14-BD46-408A-9842-CDBE1C6D37EB}. Another component is bound to startup at %windir%\system32\kproces.exe. A malicious file installed by the malware is %windir%\system32\fotos.exe.



blog comments powered by Disqus
Featured Videos


 
    
 
     Analytics & Reports
Tech Center : Understanding The Danger Within
Data Center Automation - 10 Questions to Ask Before Proceeding
Identity Management: 10 Questions to Ask
Tech Center: DBA Guide to Improved Security
Research: 2009 InformationWeek 500 Report
Inteorp Mumbai 2010
Interop Mumbai 2010