From today's SANS NewsBites Vol. 9 Num. 4
WORMS, ACTIVE EXPLOITS, VULNERABILITIES & PATCHES
--Malware Purveyors Prey on Users' Morbid Curiosity
(11 & 8 January 2007)
Not surprisingly, people's fascination with the macabre is being
exploited to spread malware. There are reports of email messages
claiming to offer footage of Saddam Hussein's execution; when users
click on the provided link, they are directed to a site that tries to
download a Trojan horse program. Similar emails have been detected that
use attachments rather than links within the body of the message.
Several different pieces of malware that try to download keystroke
loggers
have been detected accompanying messages about the execution.
http://www.vnunet.com/vnunet/news/2172307/saddam-videos-hiding-trojan
http://www.informationweek.com/management/showArticle.jhtml?articleID=196801963
[Editor's Note (Ullrich): This is an important reminder that while we
like to focus on vulnerabilities in software, a lot of malware is still
installed by the user without any help from software vulnerabilities.]
Doc
WORMS, ACTIVE EXPLOITS, VULNERABILITIES & PATCHES
--Malware Purveyors Prey on Users' Morbid Curiosity
(11 & 8 January 2007)
Not surprisingly, people's fascination with the macabre is being
exploited to spread malware. There are reports of email messages
claiming to offer footage of Saddam Hussein's execution; when users
click on the provided link, they are directed to a site that tries to
download a Trojan horse program. Similar emails have been detected that
use attachments rather than links within the body of the message.
Several different pieces of malware that try to download keystroke
loggers
have been detected accompanying messages about the execution.
http://www.vnunet.com/vnunet/news/2172307/saddam-videos-hiding-trojan
http://www.informationweek.com/management/showArticle.jhtml?articleID=196801963
[Editor's Note (Ullrich): This is an important reminder that while we
like to focus on vulnerabilities in software, a lot of malware is still
installed by the user without any help from software vulnerabilities.]
Doc