Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Get Spam. Got the Message?

    Sep14
    6:59 am (UTC-7)   |    by

    We have received a number of cases today regarding the verification of the following New Zealand Web sites:

    • hxxp://www.msncheckstatus.tk
    • hxxp://www.real-msn.tk
    • hxxp://www.instant-messenger.tk
    • hxxp://www.msndelete-contacts.tk
    • hxxp://www.get-contacts-messenger.tk

    Once visited, these sites direct users to hxxp://www.get-messenger.com, a site for Get Messenger. It is a tool capable of logging into MSN Messenger® servers as a regular instant messaging (IM) client. It authenticates users using the user account and password, retrieves his or her contact list, analyses it and shows which contacts removed the user from the contact list.

    Screenshot of Get Messenger Web site

    The following is stated in the site’s FAQ page:

    Is Messenger-Tips a Worm?

    Definition: A computer worm is a self-replicating computer program. It uses a network to send copies of itself to other nodes (computer terminals on the network) and it may do so without any user intervention. Unlike a virus, it does not need to attach itself to an existing program. Worms always harm the network (if only by consuming bandwidth), whereas viruses always infect or corrupt files on a targeted computer.

    Messenger-Tips does not send copies of itself, it does not work without user intervention and it does not harm the network or any computer. Messenger-Tips is not a worm.

    Screenshot of Get Messenger Screen

    However, the authentication method in delivering the account credentials, such as the user�s name and password, is not secure. Using Follow TCP Stream, an ethereal packet capture tool, we�re able to capture an instance when a user name and password are being sent to the program server. Below is the image capture:

    Follow FTP Stream Capture

    This type of insecurity can easily expose a user�s account information to online identity thieves.

    Credits to Trend Threat Analyst Lordian Mosuela!





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice