© 2008 Websense, Inc. All Rights Reserved.
Blog
Department of Justice Trojan Horse
12.03.2007 - 1:42 PMPrevious Posts
December 2007| 12/21/2007 | ARP spoofing HTTP infection malware » |
| 12/07/2007 | "Automated JavaScript Deobfuscation" at PacSec 2007 » |
| 12/06/2007 | AVAR 2007 in Seoul » |
| 12/05/2007 | 2008 Security Predictions » |
| 12/03/2007 | Department of Justice Trojan Horse » |
+ November 2007
+ October 2007
+ September 2007
+ August 2007
+ July 2007
The message claims that a complaint to the USDOJ has been filed against the recipient's company. The email informs the reader that a copy of the original complaint has been attached to the email. The attached "complaint" is a Trojan .scr file with an MD5 of 083cdcb8b8cac465dc130348f88ac48d. The .scr drops a file named xp2007.dat in c:\ which is then silently added as a BHO in IE.
At the time of our discovery, none of the major anti-virus vendors had detected the malicious code.
Websense Security customers are protected from this threat.
Email screenshot:
Infected desktop screenshot:
Post a Comment:







