vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Portuguese spam attempts (https://vborg.vbsupport.ru/showthread.php?t=196238)

UKBusinessLive 11-14-2008 04:53 AM

Portuguese spam attempts
 
A new Portuguese spam messages attempts to dupe victims into downloading and installing a fake Symantec product. The spam messages were constructed using two images hosted on the popular imageshack.us site.

As usual for spammed links, despite the text shown in the message, the link actually points to a rogue URL, not a Symantec site. In this case it points to malware hosted on a compromised Czech site.

The file is a Trojan, written in Delphi. The file is a downloader Trojan (proactively detected as Mal/DelpDldr-C), that downloads two additional Trojans from the same compromised site. It also displays a fake error message when run.

This is just another illustration of the importance in effective proactive detection. Even if users fall for the social engineering and click on the link in the spam, proactively detecting the downloader and other Trojans used in the attack can significantly reduce the potential impact of the attack on the victim. In this case, to nil.

Sophos confirmed that the first of the downloaded executables (spool.exe) is proactively detected (as Mal/Behav-103). The second file (ashsert.exe) is an installer, which drops a banking Trojan proactively detected as Mal/DelpBanc-A.

Take care guys


All times are GMT. The time now is 12:30 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01137 seconds
  • Memory Usage 1,700KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (1)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete