BleepingComputer.com: New Storm Tactic: Kitty Greeting Card

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New Storm Tactic: Kitty Greeting Card

#1 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,511
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 12 October 2007 - 09:29 AM

websense.com/securitylabs

See link for sample email text and screenshot.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#2 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

  Posted 12 October 2007 - 10:00 AM

^ Thanks QM ... additional links below ...

New Storm Worm - Kitty Greeting Card

This new HTML based attack is socially engineered well and may trick folks. It's always a best practice to avoid every URL present in an email message (even to opt out of spam), unless you are absolutely sure it's safe.

New Storm Worm - Kitty Greeting Card
http://www.websense.com/securitylabs/alert...php?AlertID=807
http://www.f-secure.com/weblog/archives/00001291.html
http://www.avertlabs.com/research/blog/ind...killed-the-cat/

Quote

Websense® Security Labs™ has received several reports of a new Web site that is being distributed in spam sent out by those running the Storm attacks. This site poses as a free Ecard Web site. No exploit is on the site itself. However, when users click any of the URLs, they are prompted to download and run a file called "SuperLaugh.exe." This file contains the Storm payload code.


#3 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

Posted 12 October 2007 - 01:32 PM

below a sample from my in-box with the malicious URL removed ... This one is out there :thumbsup:

Date:	Fri, 12 Oct 2007 11:51:12 -0400 
From:	*** EMAIL ADDRESS REMOVED ***  
To:	  HARRY 
Subject: You won't believe this greeting! 
	
Click here to view your laughing kitty card online. 

*** MALICIOUS URL REMOVED ***


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users