BugTraq
First WMF mass mailer ItW (phishing Trojan) Feb 16 2006 02:43PM
Gadi Evron (ge linuxbox org) (1 replies)
The first worm (mass mailer) to (ab)use the WMF 0day is now spreading in
Australia.

Our initial reports indicate the worm is not massive, however it steals
financial information from users (Phishing Trojan from a known group) it
infects and is causing quite a buzz in Australian media. We expect it to
break as a full-blown media hype this morning, tops tomorrow morning.

The worm *does* do the said damage, but as we said does not seem to be
widely spread. No reports outside of Australia have been received as of
yet.

The emails themselves do not contain the payload, but rather a URL to
sites that will infect users. Both the sites who did this are now down, I
expect the next one to be up soon (or the bad guys will just get a new
variant out in a few days). Abusing websites is mostly how WMF is
exploited, but no much in the way of emails before today.

(almost) All anti virus vendors do not detect this worm (it?s new), a
couple detect it heuristically. (almost) All anti virus vendors detect the
attachment regardless because of the WMF exploit detection routines.

Hopefully, all AV companies will detect this soon. I know most will.

If you are in Australia, you already heard about this for sure.. but not
clearly. Otherwise, this is it before the media gets their hands on it.

"Regular Phishing" as we all know it, asking us for information by means
of simple email is alive, kickin` and will still be with us 10 years from
now. However, it is slowly decreasing in volume while Phishing Trojan
attacks are getting more and more common.

We will update as necessary when we know more. The Australians have done a
good job on this.

If necessary I will also update on this in real time over at
http://blogs.securiteam.com where this text is located.

Gadi

[ reply ]
Re: First WMF mass mailer ItW (phishing Trojan) Feb 17 2006 07:02PM
Lance James (bugtraq securescience net) (2 replies)
RE: First WMF mass mailer ItW (phishing Trojan) - think singularities Feb 21 2006 08:00PM
Ken Kousky (kkousky ip3inc com) (1 replies)
Re: First WMF mass mailer ItW (phishing Trojan) - think singularities Feb 21 2006 10:48PM
Lance James (bugtraq securescience net)
Re: First WMF mass mailer ItW (phishing Trojan) Feb 20 2006 04:51AM
Lance James (bugtraq securescience net)


 

Privacy Statement
Copyright 2010, SecurityFocus