
Maslan worm disguised as nude pics... very old skool!
Published: 10 December 2004 11:55 GMT
Antivirus vendors are warning users to be on the lookout for an email borne worm which is disguising itself as nude pictures of Playboy pin-ups, though they admit the threat level is still very low.
However, with Christmas on the horizon and some boozy lunches in the diary for many there's a chance such an attachment will appear tempting to any employees getting demob-happy ahead of the holidays.
The Maslan worm would appear to be politically motivated, with infected machines intended to launch a denial-of-service attack against websites owned by Chechen separatists, according to antivirus firm Sophos.
According to Symantec W32.Maslan.C@mm is a mass-mailing worm that opens a back door and exploits system vulnerabilities on the compromised computer. The worm also steals passwords using a keylogger. The worm also attempts to attack a series of firewalls and antivirus settings on an infected machine.
The email also controls which email addresses it spreads to, avoiding most webmail addresses and also any others which may report to antivirus or filtering companies, apparently a crude attempt to avoid detection. Antivirus firms Panda, Sophos and Symantec have all been blacklisted by the worm, along with words such as 'abuse', 'privacy' and 'spam' which, if appearing an email address may be an indication of an address used to report unsolicited or malicious mail..
Currently the email spreading in the wild has the subject line '123' or '12345' and an attached file called 'Playgirls2.exe' or 'Playgirls_2.exe'.
The political power of cyberattacks has long been a matter of concern in some quarters, and derided by others as scare-mongering.
Although some may seize upon examples such as this to prove growing support in terrorist ranks for digital attack, the methodology here is no different to a number of other viruses which have spread over the past couple of years and it seems likely it's somebody with an axe to grind rather than anything more serious or concerted.
Sophos' Graham Cluley said whatever the motive the "spreading a virus is clearly criminal behaviour".
According to Sophos the virus waits until the first day of every month and then will attempt to launch a denial-of-service attack, intended to swamp the targeted websites with internet traffic.
Security Engineer / Network Security Consultant will be focused (but not exclusively) on Symantec Endpoint Technologies like encryption, antivirus, ...
Salary: GBP35,000-GBP41,000 Dependant on experience Benefits: 20 days holiday + Bank Holidays + 3 extra days performance related ROLE: Primarily the ...
Microsoft (UK's largest licensing partner), Novell, Oracle, Quest, Sophos, Symantec, VMware, Xerox. JOB TITLE: Mid Market Account Manager-License ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Is Your Enterprise Architected for Tomorrow's Growth?
Improving IT service delivery through an integrated approach to software asset management...
TechRepublic Resource Guide: Software as a Service (SaaS) for Small and Midsize Businesses...
Download a Free Trial of SmartDraw: Learn why SmartDraw is the ideal alternative...
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy