Malware distributors incorporate well-known brands in their email spam to deliver dangerous programs to unwitting victims

15 July 2010
An ongoing campaign where malware distributors use email spam to deliver dangerous programs to unwitting victims has begun to change its tune, switching the scam to incorporate different brands. In the latest scam, the message appears to be an order confirmation from Amazon.com for the purchase of an expensive consumer electronics item, or a contract (spelled, tellingly, 'conract') for expensive home improvement work, purportedly to be done on the recipient’s home.

A few weeks ago, the emails switched from a “shipping confirmation” hook to one which claims the contents of the attachment include a code worth $50 on Apple’s iTunes online store.

The spam messages for several months have included a .Zip compressed attachment. The file inside the .Zip, which looks like a Microsoft Word document, is a malicious program we classify to the definition Trojan-Downloader-Tacticlol.

An extremely dangerous downloader, the Web sites and domains from which Tacticlol (aka Oficla or Sasfis) retrieves its payloads have been remaining online longer than normal. Typically the download site is shut down within a few days, effectively neutralizing the downloader and preventing it from retrieving anything. Recent variants, however, have use Web domains that remain online for weeks or even months.

Malicious sites that remain active only increase the danger that someone who inadvertently opens the attachment a few weeks after the message arrives will still infect their computer.

In addition, the payloads delivered by the download site Tacticlol contacts are being rotated as the days go on. In the initial infection period, within about 36 hours after the spam messages arrive, the download sites deliver a number of different payloads, including the Trojan-Backdoor-Zbot keylogger, the Trojan-Pushu (aka Pushdo) spam bot, and rogue antivirus installers.

After a week, the payloads switch to the installers for botnets, which zombify the infected machines and turn them into longer-term hacker workhorses. Recent payloads have included a “dead man switch” which can render the infected computer unbootable.

You should always avoid opening any attachment that arrives through email unless you can confirm - by telephone, or some other method - that the attached document is legitimate and was deliberately sent to you. Also, train yourself to avoid opening any attachment with an .exe file extension, regardless of its appearance or origin.

 

Latest Personal and Home security articles

 Three and a half years prison sentence for rogue locksmith

 W32 Stuxnet-B rootkit can install itself automatically from a USB memory stick onto a fully-patched PC

 Norbain adds Cascade Electronic Systems to its range to ensure intruder solutions are available for all budgets

 The security message about encryption is finally getting through

 Siemens Security provides an effective and dependable solution to ensuring the security of a safe house

 The use of POTS for alarm communication will come to an end but each country is progressing at a different rate

 HAL-Locate recovers stolen caravan

 Google delivers twice the amount of malware than Twitter, Yahoo and Bing combined

 Cloudmark's Cloudfilter protects Digiweb's customers from spam

 Police crack down on burglaries in West Oxfordshire and South Buckinghamshire with SelectaDNA

...[view more articles on Personal and Home security]...

 

Other security websites:

Personal and Home security links

Security agencies to take over CWG venues tomorrow Security agencies to take over CWG venues tomorrowSecurity agencies to take over CWG venues tomorrow

HOME OF ENGLISH INTL HOME OF ENGLISH INTL. Est. 1997. Children’s English School Grades 1-12. American curriculum Elementary &High School programs. Pre-school for kids 3-6. #30 St. 282, P.P.

Kabul Bank Security Tight as Afghan Finance Chiefs Plan Response Armed security officers guarded Kabul Bank’s headquarters as finance officials prepared to outline steps to restore confidence in Afghanistan’s biggest private lender after reports of losses triggered withdrawals.

One security guard killed in armored van robbery in Cavite mall One security guard was killed and another was wounded after armed men allegedly robbed an armored-van at a mall in Dasmariñas town in Cavite province before noon Monday.

Security, availability drive APAC private cloud interest More Asia-Pacific CIOs are looking at private clouds as concerns over security risks as well as availability and performance of the services provided by public clouds linger, an IDC analyst reveals.

GS Home Shopping Falls After Woori Says Earnings Will Be Below Consensus GS Home Shopping Inc. fell the most in more than three months in Seoul trading after Woori Investment & Securities Co. said the company’s third-quarter earnings will fall short of analysts’ estimates. The South Korean operator of a cable-television shopping channel and Internet mall lost 3.2 percent to 92,100 won as of 9:18 a.m. on the Korea Exchange, headed for the biggest drop since May 24 ...

Security Guard Shot on Poospatuck Reservation A security guard was shot on the Poospatuck Reservation in...

directory of Personal and Home security suppliers
Search directory Register your company
Personal and Home Security books:

SEARCH NEWS
DIRECTORY
Google