Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Rise of the Spam Zombies
Kevin Poulsen, SecurityFocus 2003-04-25

Pressed by increasingly effective anti-spam efforts, senders of unsolicited commercial e-mail are resorting to outright criminality in their efforts to conceal the source of their ill-sent missives, using Trojan horses to turn the computers of innocent netizens into secret spam zombies.

Comments Mode:
Rise of the Spam Zombies 2003-04-26
minas-beede
A good way to spot it 2003-04-27
Alan (2 replies)
Qualification 2003-04-28
Anonymous (2 replies)
Qualification 2003-04-28
Ryan Lambert
Qualification 2003-05-02
Daniel Basse
A good way to spot it 2003-04-30
Herr Mouse
Rise of the Spam Zombies 2003-04-27
Anonymous (1 replies)
Rise of the Spam Zombies 2003-04-28
Michael
Rise of the Spam Zombies 2003-04-28
WarpKat at NoIntegrity.Org (2 replies)
Rise of the Spam Zombies 2003-04-29
Anonymous
Rise of the Spam Zombies 2003-04-30
Jim (3 replies)
Rise of the Spam Zombies 2003-04-30
Anonymous
Rise of the Spam Zombies 2003-04-30
Anonymous
Rise of the Spam Zombies 2003-05-02
Anonymous
Rise of the Spam Zombies 2003-04-29
Bill Kennard
Rise of the Spam Zombies 2003-04-30
Mark Gruber
Take the spammers down 2003-05-01
Crypt0 tronic <crypt0tronic (at) hotmail (dot) com [email concealed]>
Rise of the Spam Zombies 2003-05-01
Anonymous (1 replies)
Intrestingly, my work was attacked recently and the server admin password was changed. Last summer I'd got a new PC and there was no personal firewall installed by IT on it. After the server was attacked, finally personal firewalls were installed on the PC's.

I'd had an incident where the computer rebooted itself some time ago which then meant that pressing CTRL+ALT+DEL didn't bring up the task manager. IT Dept never did anything about it but just made a shortcut to task manager on the desktop.

MSM kept popping up in the sys tray and ever time I tried to close it, it said it was in use and couldn't be closed. Minor annoyance and didn't stop me working.

After installation of the firewall, it was going bananas and kept trying to get out the firewall alarm was going mad as I had blocked it's outside access.

Doing some digging on it revealed it was a second copy of MSM that had been altered and placed in a new directory. Digging a bit further into it revealed it was an SMTP client; instead of using my email address though it seemed like a direct client. The user had full access to my machine it seems and had dumped a load of composed emails on the server to be sent out via my machine.

No more investigation was done on this after we used safe mode to remove the files from the directory (I requested they don't be deleted and should send them to symmantec soon) and since removal, we've had no more incidents of viruses and random crashes on other machines

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/4217/19696#19696
Rise of the Spam Zombies 2003-05-02
Anonymous
Rise of the Spam Zombies 2003-05-02
morning_wood







 

Privacy Statement
Copyright 2008, SecurityFocus