Blog
Potential Skype worm propagating.
12.18.2006 - 3:08 PMPrevious Posts
December 2006| 12/18/2006 | Potential Skype worm propagating. » |
| 12/15/2006 | 2027 Security Predictions » |
| 12/13/2006 | 2007 Security Predictions » |
| 12/08/2006 | MOTW: HTML/JS Obfuscation Part II » |
| 12/05/2006 | MOTW: Malware Collection: Passive Honeypots » |
+ November 2006
+ October 2006
+ September 2006
+ August 2006
+ July 2006
* users receive messages via Skype Chat to download and run a file
* the filename is called sp.exe
* assuming the file is run it appears to drop and run a password stealing Trojan Horse
* the file also appears to run another set of code that uses Skype to propagate the original file
* the file is packed and has anti-debugging routines (NTKrnl Secure Suite packer)
* the file connects to a remote server for additional code
* the original site has been black holed and is not serving the code anymore
* the number of victims is still TBD
* the original infections appear to be in APAC region (Korea in particular)
More details will be published later today when we get more details.
Special thanks to the Shadow Server for research assistance.
Post a Comment:






