Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hotlan Trojan - Attacks Free Email Account To Generate Spam


  • Please log in to reply
No replies to this topic

#1 harrywaldron

harrywaldron

    Security Reporter


  • Members
  • 509 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Roanoke, Virginia
  • Local time:02:06 AM

Posted 07 July 2007 - 08:55 PM

This new attack isn't circulating extensively at this point and folks should stay up-to-date on AV protection plus watch for any unusual activity in Internet usage or in their free email services.

Hotlan Trojan defeats captcha
http://news.zdnet.co.uk/security/0,1000000...39287905,00.htm

A new Trojan horse that sends spam through Hotmail and Yahoo email accounts has antivirus companies worried that the commonly used "captcha" system, used to prove new members are real people, may have been compromised. Captcha systems typically use a selection of alphanumeric characters that have been distorted and presented in a graphic with other elements designed to confuse character-recognition software. The idea is that, as only a person can read it and type in the correct sequence, spam bots and other malware can be stopped from automatically setting up accounts. The new threat was highlighted on Thursday by BitDefender Labs, which has dubbed it Trojan.Spammer.HotLan.A.


McAfee - Spam-HotLan (DAT 5070 offers detection/protection)
http://vil.nai.com/vil/content/v_142646.htm

This is a spam trojan which downloads a remote script to log into various free webmail accounts, in order to send spam. The script then tries to contact a second site, which contains details about the spam emails to send. At the time of writing, this second site returned nothing. This trojan does not install itself to the local system - once a system is rebooted, it will not restart itself.


BitDefender - Trojan.Spammer.HotLan.A
http://www.bitdefender.com/VIRUS-1000154-e...r.HotLan.A.html

There aren't any obvious symptoms of this malware, except increased internet activity.



BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users