Forum Moderators: phranque

Message Too Old, No Replies

New Storm Trojan variant spreads in blogs, forums, Webmail

son of Storm Worm has a "really neat twist"

         

phranque

11:53 am on Feb 28, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



from Computerworld [computerworld.com]:
An initial infection is still carried out via e-mail, which touts a link that when clicked downloads a number of malware components to a victimized machine. Once on a PC, however, the malicious code injects itself into the network stack as a rootkit and analyzes all outbound Web traffic

"It has hooks for boards, e-mail, and blogs," said Alperovitch. When a user on an infected PC posts a message to a forum or blog, or sends a message via popular Web-based mail services such as Hotmail, Gmail, and Yahoo Mail the Trojan adds text to the entry or message.

resulting in new links to more malware...

phranque

7:21 am on Mar 1, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



apparently the following may be vulnerable.

im clients:
AOL Instant Messenger
Google Talk
Yahoo! Messenger

webmail from the following providers:
AOL
Bellsouth
Care2
Comcast
Earthlink
FastMail
Gmail
Hotmail
Lycos
mail.com
mail.ru
Rambler
Tiscali
Yahoo

forum solutions:
phpBB
VBulletin

jatar_k

1:39 pm on Mar 1, 2007 (gmt 0)