Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Panda Software Weekly virus report

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 11:55 AM
Original message
Panda Software Weekly virus report
Posted in GD as a public service.

The poster is not an employee of, or in any way associated with Panda Software.
---

"Knowledge is of no value unless you put it into practice."
--Anton Chekhov (1860-1904), Russian dramatist and short-story writer.

Weekly virus report

Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, November 22, 2003 - Today's report will focus on two worms -variant J of Mimail and variant E of Lohack-, and a Trojan called Banbra.B.

Mimail.J spreads via e-mail in a message with the subject IMPORTANT and an attached file called w w w.paypal.com.pif. This worm uses so-called social engineering techniques to trick users and spread to as many computer as possible, like the I variant, the message carrying Mimail.J refers to the PAYPAL payment system.

When it is run, this malicious code shows an image on screen that simulates the home window of a financial entity. Then, Mimail.J collects the information entered by the user and sends it out via e-mail. In computers with Windows Me/98/95 installed, it runs as a service so that it does not appear in the Task Manager.

Mimail.J looks for e-mail addresses in all the files that do not have any of the following extensions: COM, WAV, CAB, PDF, RAR, ZIP, TIF, PSD, OCX, VXD, MP3, MPG, AVI, DLL, EXE, GIF, JPG and BMP, and saves them in a file called el388.tmp. This malicious code then sends itself out to all the addresses it has found, using its own SMTP engine, and connects to the IP address 212.5.86.163, which belongs to a Russian e-mail server.

Today's second worm, Lohack.E, spreads via e-mail, across computer networks and through the peer-to-peer (P2P) file sharing program KaZaA. It does this using messages that have extremely variable characteristics. In order to trick users into opening them, many of these messages refer to the Spanish Information Society and E-mail Services Law. Furthermore, Lohack.E spoofs the sender's address so that it seems to have been sent from a trustworthy source, such as the Ministerio de Ciencia y Tecnología (Ministry of Science and Technology) or Panda Antivirus.

Lohack.E automatically activates when the message carrying this worm is viewed in the Preview Pane in Outlook. It does this by exploiting the Exploit/Iframe vulnerability, which affects versions 5.01 and 5.5 of Internet Explorer and allows files attached to e-mail messages to run automatically.

We are going to finish today's report with Banbra.B, a Trojan that obtains user's account numbers and passwords for accessing bank accounts with the following financial entities: Internet Banking Caixa, Bradesco Internet Banking and Banco do Brazil. Similarly, it monitors the web pages that the affected user accesses. When the user visits the website of any of the entities mentioned above, Banbra.B displays a fake login interface in order to trick the user into entering confidential information, which will then be sent out via FTP to the creator of the Trojan.

For further information about these and other malicious code, visit Panda Software's Virus Encyclopedia at: http://www.pandasoftware.com/virus_info/encyclopedia

Additional information

- FTP (File Transfer Protocol): A mechanism that allows files to be transferred through a TCP/IP connection.

- Network: Group of computers or other IT devices interconnected via a cable, telephone line, electromagnetic waves (satellite, microwaves, etc.), in order to communicate and share resources.

More definitions of virus and antivirus terminology at: http://www.pandasoftware.com/virus_info/glossary/default.aspx

NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.
Printer Friendly | Permalink |  | Top
BJ Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 11:58 AM
Response to Original message
1. Why does KaZaa get high marks from the filesharing folks?
Seems like it's full of viri, worms and assorted computer nasties.
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 12:03 PM
Response to Reply #1
2. KaZaa is NASTY. Stay away from it. Instead, get
KaZaa LITE. It has most of the functionality, minus the spyware crap.

Better yet, ditch p2p altogether and go the Usenet music groups route. Much safer!
Printer Friendly | Permalink |  | Top
 
newyawker99 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 02:32 PM
Response to Reply #2
3. kick
:kick:
Printer Friendly | Permalink |  | Top
 
classics Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 02:33 PM
Response to Original message
4. This is an advertisment.
If you want to post computer news thats fine but we dont need weekly advertisments for Panda Software.
Printer Friendly | Permalink |  | Top
 
Don_G Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 02:37 PM
Response to Reply #4
5. It's Not An Ad
It's just a weekly bulliten of the new virii that's out and a reminder to update the Anti-Virus program of your choice.

A DUer I know didn't and now has to take her computer to have it disinfected.
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 09:25 PM
Response to Reply #4
6. Been posting these for a while now, and
I've received many comments of appreciation for them. I post these because I happen to be subscribed to their bulletins. I don't personally (or professionally) use their software, but they are an EXCELLENT research group and their bulletins are timely and precise.

If Mr. Skinner decides it would be more appropriate for me to post elsewhere, then by all means let him say so. In fact, during the first several postings, my disclaimer included the following: "Mods, please move or lock if this post is deemed inappropriate for this forum." No one moved or locked them, so I discontinued typing that portion.

If you have a better source of timely information, then by all means have at it. I'll be the first one in line to read your posts!
Printer Friendly | Permalink |  | Top
 
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-23-03 09:29 PM
Response to Original message
7. Linux users can download bitdefender, Linux edition, for free.
http://www.bitdefender.com/bd/site/products.php?p_id=16#

Just a little program I stumbled upon...
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 07:02 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC