ScamFraudAlert  


Go Back   ScamFraudAlert > News - Security Threats & Alerts
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News - Security Threats & Alerts This thread focuses on Malawares, Malicious Website, Trojan horse and other threats and alerts in circulation

   

Citizen Media Law Project: Legal Resources for Citizen Journalists
Reply
 
Thread Tools Rate Thread Display Modes
  #1  
Old 05-03-07, 01:02 AM
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Feb 2005
Posts: 2,102
Rep Power: 10
admin has disabled reputation
Malicious Web site / Malicious Code: Malcode found on Mexican .Gov site

Websense® Security Labs™ has discovered malicious code hosted on a government body's official Web site. The victim is Comisión Federal de Telecomunicaciones, a division of Mexico's government (equivalent of the FCC in the United States). The main page of this Mexican government Web site does not contain anything malicious. However, when a user visits http://prospectiva.cft.gob.mx/, an .scr file is downloaded. After execution, the .scr file drops a suspiciously named executable into the Windows startup directory for all users. The executable downloaded from this government site is malicious. The newly-installed malware collects user information and sends it back to the original source of the executable. Screenshot: The exact path to the .scr file is: C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\MY_LOVE.EXE Screenshot: The author of this malicious executable took an additional step in disguising this file by adding company version information and claiming to come from “Microsoft Corporation”. At the same time this file is dropped, an SMTP connection to one of Gmail's server is made. Screenshot:

More...
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT -5. The time now is 03:33 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Page generated in 0.08003 seconds with 10 queries