Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > ‘Classmates Reunion’ Used as Malware Ploy

    Class reunion invitations (supposedly from classmates.com) are being seen inĀ  spam recently — recipients of these messages are asked to click on a link found in the message to get the details of the “reunion” and also see a related video.

    Looking at the IP origins of sample spam messages, it appears that these have been sent out by spam bots using dynamic IPs from different dialup and broadband ISPs.

    Sample bogus message supposedly from classmates.com
    Figure 1. Sample spammed message.

    Clicking on the link would actually direct users to a malicious webpage. In this page, a message prompts users to update their Adobe player to be able to view the reunion video, thus tricking them into executing a malicious file.

    Trend Micro detects the file as TROJ_AGENT.ADB.

    Snapshot of the malicious website
    Figure 2. Malicious website.

    The Trojan connects to a remote URL to download TSPY_AGENT.AHCN. This spyware gathers information, MS IE FTP Passwords, and WinInetCacheCredentials, which are Protected Storage items. It uses HTTP post to send the information it has gathered to certain URLs.

    This information-stealing routine risks the exposure of victim’s sensitive information, which may then be used by cybercriminals for malicious purposes. TSPY_AGENT.AHCN also has rootkit capabilities that enable it to hide its files and processes from a user.

    The Trend Micro Smart Protection Network already blocks these spammed messages and detects the Trojan and the spyware, keeping users PCs safe from infection. Non-Trend Micro users are always cautioned against trusting unsolicited email messages. Clicking links and downloading files from unknown locations almost always lead to malware.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    One Response to “‘Classmates Reunion’ Used as Malware Ploy”

    Trackbacks

    1. Rich_at_Dell (Richard Bernier)


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice