Instant Messaging worm exploits new WMF vulnerability

Hacking, cracking and bluejacking. Discussions on how to keep your stuff secure and private here.

Moderators: Andy, fac51, 117

Post Reply
117
Lowly Janitor Guru
Posts: 12548
Joined: Sat Jun 14, 2003 12:23 pm
Location: a destination a little up the road

Instant Messaging worm exploits new WMF vulnerability

Post by 117 »

t was only a matter of time, the first IM-Worm exploiting the wmf vulnerability has been spotted.

We have received multiple reports from the Netherlands about an IM-Worm which spreads via MSN using a link to "http://[snip]/xmas-2006 FUNNY.jpg".
This may well turn out to become a local epidemic(in NL), however so far it has not become big.(Not even 1000 bots at this moment)

The jpg is actually an HTML page with a (link to a) malicious wmf file which is heuristically detected as Exploit.Win32.IMG-WMF by Kaspersky Anti-Virus.
This wmf will download and execute a .vbs file which is detected as Trojan-Downloader.VBS.Psyme.br which in turn will download an Sdbot. The IRCBot is detected as Backdoor.Win32.SdBot.gen by KAV.
full story
Image
Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

nice
Image
User avatar
Vlammetje
Sexy Guru
Posts: 6569
Joined: Sat Jun 21, 2003 12:52 pm
Location: Den Haag
Contact:

Post by Vlammetje »

yup heard of that, although I know nobody who's actually been infected.
guess it was just a matter of time before IM would be used
www.vlammetje.com
117
Lowly Janitor Guru
Posts: 12548
Joined: Sat Jun 14, 2003 12:23 pm
Location: a destination a little up the road

Post by 117 »

i have IM protection with ZoneAlarm Security Suite so should be protected anyways :)
Image
Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

nice indeed
Eamonn

Image
Post Reply