InvestorsHub Logo
Followers 23
Posts 1815
Boards Moderated 0
Alias Born 09/27/2008

Re: None

Wednesday, 12/08/2010 9:48:51 AM

Wednesday, December 08, 2010 9:48:51 AM

Post# of 334
WikiLeaks-related spam carries wormPosted on 08.12.2010
http://www.net-security.org/malware_news.php?id=1560&utm_source=feedburner&utm_medium=twitter&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29&utm_content=Google+Feedfetcher

Given the great attention that WikiLeaks' releases of diplomatic cables is garnering around the world, it was only a matter of time when malware pushers were going to misuse the users' curiosity regarding the matter to gain access to their computers.

An e-mail with “IRAN Nuclear BOMB!” in the subject line has been detected by Symantec, with a spoofed header to make it look like it cam from WikiLeaks.org, saying "OBAMA is and IMPOSTOR!" and offering an URL.

By clicking on it, the victim is taken to a site where a Wikileaks.jar file attempts to downloaded a worm on the victim's computer:




The worm in question opens a backdoor into the system by using a predetermined port and IP address, and allows the attacker to do all kinds of mischief: stealing, spying, routing traffic through the computer. It can also spread further by by copying itself to removable drives and the share folders of file-sharing programs.

In other words - be careful when on the lookout for information on WikiLeaks. Or, for that matter, for information on any topic that is very popular at that moment. Don't click on links in unsolicited e-mails, and opt for well-established news sites to get the latest news about the matter.

The worm in question opens a backdoor into the system by using a predetermined port and IP address, and allows the attacker to do all kinds of mischief: stealing, spying, routing traffic through the computer. It can also spread further by by copying itself to removable drives and the share folders of file-sharing programs.

In other words - be careful when on the lookout for information on WikiLeaks. Or, for that matter, for information on any topic that is very popular at that moment. Don't click on links in unsolicited e-mails, and opt for well-established news sites to get the latest news about the matter.

Not compensated in any manner for research and/or posts. Information should be construed as information only for discussion purposes. Always conduct your own dd. Just my opinion

Join the InvestorsHub Community

Register for free to join our community of investors and share your ideas. You will also get access to streaming quotes, interactive charts, trades, portfolio, live options flow and more tools.