Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    October 2006
    S M T W T F S
    « Sep   Nov »
    1234567
    891011121314
    15161718192021
    22232425262728
    293031  
  • About Us
    Malware Blog > 2006 > October> 24

    Archive for October 24th, 2006




    The recent months have seen a lot of zero-day exploits targeting Microsoft Word– what with MDROPPER variants becoming a perennial mainstay in the Trend Micro Malware Advisoriespage (TROJ_MDROPPER.CT being the most recent detection).


    It is a bit surprising, therefore, when new malware exploiting old vulnerabilities suddenly appear virtually out of nowhere. W97M_KUKUDRO.AB and W97M_LAFOOL.AO– detected just almost two days apart — both take advantage of MS vulnerabilities dating as far back as 2001 and 2003, respectively. We all know that the threat landscape has changed dramatically since then. And using macros? That is soooancient.


    And yet, they still proved effective — even almost getting detected as new exploit Trojans. Why? Because of the mere fact that they areancient. Something old, yet something new. In a time when Microsoft (and perhaps even the antivirus industry) are chasing proof-of-concept and zero-day malware like cats to anything shiny, seemingly unassuming grandpa exploits may just slip in quietly. The same goes for computer users who may be panicking for the latest security fixes… and forgetting the older patches in the process.


    Perhaps malware authors are trying to check if we have strained our necks forward for so long that we cannot look back anymore. Fortunately, we love stretch our muscles once in a while.

     
    Posted in Uncategorized | 1 TrackBack »


    Oct24
    3:29 am (UTC-7)   |    by

    As of this writing, we are getting a lot of samples of a malware that Trend Micro is going to detect as TROJ_DLOADER.GAF (pattern has already been created and is now on the testing phase). The malware is currently being spammed as an attachment, the filenames and md5 of these files are different. Some of the filenames are:



    • doc.zip
    • test.zip
    • document.zip
    • body.zip
    • text.zip
    • Update-KB-x86.zip
    • file.zip
    • readme.zip
    • data.zip
    • message.zip
    • test.txt.pif
    • text.txt.pif

    The extensions vary ranging from zip, exe, pif, and cmd. The filesize of these attachments also vary from 12,430-12,758 bytes. Upon extraction of the file it will drop an executable file imitating however a notepad icon. Please reconsider opening emails with attachments having these filenames or as of today at least, opening attachments with these extensions.

     
    Posted in Uncategorized | Comments Off


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice