You are here: silicon.com > Software > Malware

Malware

Sick virus writer exploits London bomb blast

Trojan creates bot-net for sending spam...

By Will Sturgeon

Published: 9 July 2005 21:37 GMT

A virus has been spotted in the wild which attempts to exploit concerns surrounding the bomb blasts which rocked London last Thursday and left at least 50 people dead. Warning levels are currently low but that makes the attempt to infect no less tasteless.

An email purporting to offer a link to amateur video footage of the events on the London Underground in the aftermath of the bomb blast will install a Trojan on users' machines if they click on the attachment.

It's the latest instance of sickening social engineering as virus writers prey upon topical and occasionally disturbing incidents to make their attachments appeal to curious minds.

The Asian tsunami, the war in Iraq and also the 9/11 attacks on New York saw similar social engineering attempts.

According to UK email security firm MessageLabs the email appears as a mocked-up html newsletter from CNN with the subject line 'TERROR HITS LONDON'.

The sender's email address appears as breakingnews@CNNonline.com. Although that address could easily have been spoofed, the domain is not an official CNN domain and is registered to a firm in Florida.

The email asks recipients to 'See attachments for unique amateur video shots'.

The file name, 'London Terror Moovie.avi' appears a valid film clip bar the typo in 'movie', however after 124 character spaces there is the real .exe file name, though even this has been disguised as 'Checked By Norton Antivirus.exe'.

When executed the attachment copies itself to /Windir/winlog.exe and modifies the Windows registry key HKLM/Software/microsoft/Windows/CurrentVersion/Run so that it runs automatically on start-up, according to MessageLabs.

The Trojan then uses the compromised PC and the SMTP servers which it is configured to use to send out large volumes of spam email.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Service Desk/Support Incident Progression

To recommend and exploit service improvement and cost saving opportunities. Also identifying and suggest opportunities to exploit remote resolution ...

Tivoli Managment Systems Manager

The suitable candidate will be responsible for providing 2nd line technical support functions across the entire Management Systems portfolio of ...

IT Security Analyst

Respond when alerted to security events, whether in real time via monitoring tools or through log analysis.Work individually and with other incident ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: