ScamFraudAlert  


Go Back   ScamFraudAlert > News - Security Threats & Alerts
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News - Security Threats & Alerts This thread focuses on Malawares, Malicious Website, Trojan horse and other threats and alerts in circulation

   

Citizen Media Law Project: Legal Resources for Citizen Journalists
Reply
 
Thread Tools Rate Thread Display Modes
  #1  
Old 02-22-07, 05:50 AM
Scrub's Avatar
Scrub Scrub is offline
Administrator
 
Join Date: Feb 2005
Location: CyberWorld
Age: 63
Posts: 22,065
Rep Power: 10
Scrub is on a distinguished road
WSLabs, Malicious Website / Malicious Code: Trojan Crimeware using Google Maps

WSLabs, Malicious Website / Malicious Code: Trojan Crimeware using Google Maps
Inbox
from Websense Security Labs <DoNotReply@websensesecuritylabs.com> hide details Feb 19 (3 days ago)
to ScamFraudAlert@gmail.com
date Feb 19, 2007 9:50 AM
subject WSLabs, Malicious Website / Malicious Code: Trojan Crimeware using Google Maps

Websense Securitylabs(TM) has received reports of a Trojan which is related to an email that has been distributed, claiming that the Australian Prime Minister had suffered a heart attack.

The Trojan is formed by several different components. It basically monitors all your accesses to web pages and keeps track of them, keylogging everything you do. It contains a special module which it uses for phishing. At the time of this alert there were more than 2500 infected victims.The affected banks are:

Westpac (Australia)
Kasikorn Bank (Thailand)
Banco de Valencia (Spain)
Commonwealth Bank (Australia)
BBVA (Spain)
Caja Madrid (Spain)
Bank of America (USA)
Unicaja (Spain)
Wells Fargo (USA)
Sparkasse (Germany)
Deutsche Bank (Germany)
Gad (Germany)
Commerz Bank (Germany)
Post Bank (Germany)

On the other hand, it installs a web server on the affected machine which allows the attacker to access that machine every time it is online. To achieve that, he/she has a control panel where he/she can have a full list of all the infected machines including IP address, country, ports he/she can use to access the machine to using different protocols, and even a link to google maps which will exactly point out where that IP is located.

We thank the AusCERT for providing the sample.

Screenshots of Google Maps and Attacker Statistics panel within full alert.

For additional details and information on how to detect and prevent this type of attack:
http://www.websensesecuritylabs.com/...hp?AlertID=741



__________________
Your Computer Is At Risks
Get McAfee Free SiteAdvisor


McAfee, Inc

Reply With Quote
Reply

Bookmarks

Tags
code , crimeware , google , malicious , maps , trojan , website , wslabs

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT -5. The time now is 03:31 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Page generated in 0.08481 seconds with 10 queries