SIRT Handler Premium Member Joined: Nov 20, 2003 Posts: 2899
Posted: Tue Feb 05, 2008 12:45 am Post subject: "The video is crazy!"
One of a series of spams linking to a website that will download "iclk.html." About 50/50 detection, but I think it's particularly dangerous because although people know that .exe files are dangerous, they may not suspect an html file ... well, presuming there are people who get porn video links in email from strangers and aren't suspicious. And the google redirection fools the spamcop parser.
Jotti:
Scanner results
Scan taken on 05 Feb 2008 00:22:24 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Crypt.FKM.Gen
ArcaVir
Found nothing
Avast
Found Win32:Agent-RUB
AVG Antivirus
Found Generic9.AXKW
BitDefender
Found Trojan.Downloader.Exchanger.A
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Trojan-Downloader.Win32.Exchanger.b
Fortinet
Found W32/Dload.B!tr.dldr
Ikarus
Found Trojan-Downloader.Win32.Exchanger.b
Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.Exchanger.b
NOD32
Found probably unknown NewHeur_PE (probable variant)
Norman Virus Control
Found W32/DLoader.FMCK
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found Troj/Dload-BA
VirusBuster
Found nothing
VBA32
Found nothing
Spam:
Quote:
Paris Hilton New Video Auditioning Topless.
The video is crazy!
Only 1 day trial - get this full video now!
Download it now! [links to http://www.google.com/pagead/iclk?sa=3Dl&ai=3Dtrailhead&num=3D698=
03&adurl=3Dhttp://58.65.239.98/download.php]
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You cannot download files in this forum