Pages

Showing posts with label Email Infected. Show all posts
Showing posts with label Email Infected. Show all posts

Tuesday, November 24, 2009

Win32:Banker - Trojan horse

Win32:Banker is a family of Trojans capable of monitoring user activity and stealing private information. Win32:Banker monitors user’s internet access. If certain websites (banking, payment system) are visited, Win32:Banker will log user’s activity. Win32:Banker will than send all the stolen details to the attacker.

Description

Win32:Banker is a family of Trojans capable of stealing private information such as account numbers, passwords and banking credentials. Many variants can wait in the background and monitor user's internet activity. A logging procedure starts when a certain website is accessed, or if the address of an accessed website contains certain words. Many variants may supplement legitimate banking or payment system websites to get user details.

Wednesday, November 4, 2009

Win32/Zafi.B - Email Worm

Win32/Zafi.B (Other names: W32.Erkez.B) is a worm spreading via e-mail and P2P networks. It runs on Windows 95 and higher versions. Its size is 12800 bytes compressed by the FSG utility. After its decompression its size is 49 kB.

Note: In following text a symbolic inscription %windir% is used instead of the name of directory in which Windows operating system is installed. Of course, this may differ from installation to installation. The subdirectory System or System32 placed in %windir% has a name %system%.

The worm arrives in an e-mail message with randomly selected subject line and body from the pre-defined subject lines and bodies specified in the worm code. The text in the subject line might be for example:

eIngyen SMS!

And the message body:

Tuesday, November 3, 2009

Phishing scam - Hacker

Known types and aliases: HTML/Smithfraud.gen, HTML/Tcfbankfraud.gen, HTML/Bankfraud.gen, Phish-BankFraud.eml, HTML/Phishing.gen

This is a so-called "phishing scam". It is a counterfeit e-mail message, mass-mailed by various groups of hackers, that deceives gullible users into disclosing credit card numbers, bank account information and various personal details. The professionally crafted e-mail message claims to come from a bank, financial institution or an ISP and usually demands the confirmation of personal data. After clicking the link, users are sent to a fraudulent site, which looks just like the institution's web site and are asked for various sensitive information.

Virus hoaxes

A virus hoax is typically distributed by e mail to warn' recipients of a new threat to computer systems security. After detailing how this new virus is a serious threat, the email advises you to forward the message to everyone you know. This 'chain letter' effect causes one kind of real harm.

Virus hoaxes can circulate widely. Suppose a recipient distributes it to 10 people and each of those 10 people distribute it to 10 more people, and so on down the line. After only six generations, one million bogus e-mail messages will circulate throughout the Internet. By the seventh generation the number reaches 10 million, and by the eighth generation - 100 million e-mail messages that serve no purpose are clogging up networks worldwide. This effect can cause servers or routers (specialized computers that route Internet traffic) to slow down or even crash.

WORMS

Worms are similar to viruses in that they re self replicating. They reproduce themselves across networks without human assistance, such as e-mail sending. A worm, though, doesn't need another executable program to be distributed.

Worms usually affect networks more than individual computers on the network. Their selfreplicating behavior can overload network resources, causing slowdowns in data
transmission by consuming massive bandwidth normally used to forward normal traffic.
Network systems that route Internet traffic are just specialized computer hardware and software. They, too, can be affected by malware.