Register a free account

ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Security Alerts and vulnerabilities
The Software Store

Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 01-17-2005, 12:49 PM
pmf45's Avatar
pmf45 pmf45 is offline
Junior Member
 
Join Date: Jan 2005
Location: Windsor, Ontario, Canada
Posts: 12
Tsunami disaster donation plea is really a virus.

Virus experts at Sophos have discovered a mass-mailing worm that poses as a plea for donations to help with the Indian Ocean tsunami disaster.

The W32/VBSun-A worm spreads via email, tempting innocent users into clicking onto its malicious attachment by pretending to be information about how to donate to a tsunami relief effort. However, running the attached file will not only forward the virus to other internet users but can also initiate a denial-of-service attack against a German hacking website.

Emails sent by the worm have the following characteristics:

Subject line:
Tsunami Donation! Please help!

Message text:
Please help us with your donation and view the attachment below! We need you!

Attachment name:
tsunami.exe

W32/VBSun-A is a simple mass mailing worm written in Visual Basic. It attaches itself to emails with the following characteristic:

Subject line: Tsunami Donation! Please help!

Message text:
Please help us with your donation and view the attachment below!
We need you!
Attachment name: tsunami.exe
W32/VBSun-A will attempt to send itself to addresses found in the victim's outlook address book.
W32/VBSun-A will drop the following files in the Windows folder:
crssr.exe
raz32.exe
tsunami.exe
The following registry entry will be created so that the worm is run when a user logs on to Windows:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
CaptionMgr32
W32/VBSun-A will also attempt to carry out a DoS against [Only Registered and Activated Users Can See Links. Click Here To Register...].
Reply With Quote
Sponsored Links

  #2  
Old 01-17-2005, 12:54 PM
Mobo's Avatar
Mobo Mobo is online now
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,615
Send a message via MSN to Mobo
They will stoop to any level won'y they... :censored:
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zotob Suspects Arrested Mobo News & Announcements 0 09-05-2005 10:30 PM
Mytob Worm LJM Master Security Alerts and vulnerabilities 0 03-31-2005 02:04 PM
Cellery worm Mobo Security Alerts and vulnerabilities 0 01-13-2005 08:42 AM
Santy.a Worm Mobo Security Alerts and vulnerabilities 0 12-21-2004 01:07 PM
Mass mailing Worm Mobo Security Alerts and vulnerabilities 0 11-19-2004 09:54 AM


All times are GMT -5. The time now is 10:10 PM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved