Warning: Work in Progress...
This is a discussion on 'Storm' Trojan horse taps into YouTube fever within the Internet, Web, Network & Security forums, part of Computer World category; Hackers bent on spreading the Storm Trojan horse have changed tactics again and are now trying to dupe users into clicking on links posing as YouTube videos, security vendors warn. ...

Advertisement
Want to advertise? Learn how to remove ads

Notices

Tags : storm, youtub
Thread Tools   Switch to Linear ModeSwitch to Hybrid ModeSwitch to Threaded Mode
BLooD's Avatar
BLooD
BLøøÐ 4 LìFE
Posts/Threads: 1,111/95
Thanks: 170
Thanked 445 Times in 270 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Rep Power/Points: 269/21023
BLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond repute
Lightbulb 'Storm' Trojan horse taps into YouTube fever, Posted August 31st, 2007, 10:05 PM #1 (permalink) |
Hackers bent on spreading the Storm Trojan horse have changed tactics again and are now trying to dupe users into clicking on links posing as YouTube videos, security vendors warn.
Storm, a.k.a. Peacomm and Nuwar, is now spreading via e-mail that includes a link that appears to be to a YouTube video, said Johannes Ullrich, chief research officer at the SANS Institute, on the Internet Storm Center's blog this weekend. "The link looks like a link to YouTube, but actually points to a 'numeric' URL like old Storm variants," said Ullrich.
Placing the mouse cursor atop the bogus YouTube link will show a numeric IP address rather than the expected www.youtube.com, a good indicator of a scam attempt.
Recipients who click on the link see a message that claims the video is loading in the background, said Vinoo Thomas, a researcher at McAfee Inc.'s Avert Labs. Actually, said Thomas, "an embedded obfuscated JavaScript routine attempts a cocktail of browser and application exploits." If any of those exploits are successful, Storm gets dropped on the PC.
Over the weekend, Roger Thompson, a researcher at Exploit Prevention Labs Inc., identified the multistrike exploit package as "Q406 Rollup," a collection that has made the rounds since late last year. Similar to other hacker kits such as Mpack, Q406 includes a dozen or more exploits.
Storm's markers have become well-known for their skill at adapting their pitches to get users to open attached files or click on e-mailed links. Last week, a Symantec Corp. researcher said the group was "very adept" at creating persuasive messages. "They have a knack for latching on to the latest newsworthy events and capitalizing on the public interest in them," said Hon Lu. "And if no newsworthy events are happening at the time, then they will just make them up." The Storm Trojan horse reportedly behind the summer's plague of malicious greeting card spam, and the machines it has infected -- by some accounts a massive botnet -- served as the launching pad for a huge wave of pump-and-dump stock scam spam earlier this month.
/|\ M3S$ WiD Da BE$t , D|3 LiKE t#E RE$T /|\
X•BLø0ЕX™ X•BLø0ЕX™
| Reply With Quote
The Following User Says Thank You to BLooD For This Useful Post:
tanna (September 1st, 2007)
Nishithiny's Avatar
Nishithiny
PaInS[in]SiDe
Posts/Threads: 447/47
Thanks: 231
Thanked 359 Times in 173 Posts
Nominated 1 Time in 1 Post
TOTW/F/M Award(s): 0
Rep Power/Points: 224/18391
Nishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond reputeNishithiny has a reputation beyond repute
Default Posted August 31st, 2007, 10:14 PM #2 (permalink) |
BLooD thanks for da information



| Reply With Quote
BLooD's Avatar
BLooD
BLøøÐ 4 LìFE
Posts/Threads: 1,111/95
Thanks: 170
Thanked 445 Times in 270 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Rep Power/Points: 269/21023
BLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond reputeBLooD has a reputation beyond repute
Default Posted August 31st, 2007, 10:16 PM #3 (permalink) |
Your welcome nishhy !
/|\ M3S$ WiD Da BE$t , D|3 LiKE t#E RE$T /|\
X•BLø0ЕX™ X•BLø0ЕX™
| Reply With Quote
Little Star's Avatar
Little Star
TaLeR SaThE SuR MiLO
Posts/Threads: 1,543/85
Thanks: 2,058
Thanked 711 Times in 407 Posts
Blog Entries: 1
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Rep Power/Points: 445/37542
Little Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond reputeLittle Star has a reputation beyond repute
Default Posted August 31st, 2007, 10:16 PM #4 (permalink) |
BLooD thanks for da information
| Reply With Quote
Reply  

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Display Modes
Linear Mode Linear Mode
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Advertisement
Want to advertise? Learn how to remove ads


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dust Storm Prova Nature & Animals 7 June 24th, 2007 02:20 PM
Spectacular Photos of Sydney Storm... Shakib Nature & Animals 8 May 16th, 2007 03:48 AM
Share ur Fever Experiance? Rio Health & Fitness 5 August 8th, 2006 12:32 AM
Trojan swaps porn sites for Koran text JUBAiR Internet, Web, Network & Security 0 September 7th, 2005 11:10 PM
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Copyright ©2005 - 2008, doshomik.net
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
All times are GMT +7. The time now is 12:45 PM.