Pamela Anderson, Michael Jackson and Harry Potter used as bait for spreading the Downloader.SQV Trojan

2/20/2008.

PandaLabs has detected the mass-mailing of messages with sensational subject fields to spread the Downloader.SQV Trojan. Subjects used include two supposed earthquakes in the USA, the third divorce of Pamela Anderson or the release of the film “Jumper”.

The email format is the same in all cases, only the subject field varies. Yet it always involves some kind of sensational title, such as:

Pamela Anderson divorces in third times!!!

Michael Jakson glued up a person a plaster

CIA tortures prisoners!!!

Harry Potter was purchased by pentkhaus!!!

Two powerful earthquakes happened in the USA!!!

Princess Diana ´Could be have been killed by MI6´ - conclusions of experts!!!

The variable subject of the email also appears in the text body, along with the text: “New Video!” and a link with the words “Download Now”. Any user clicking the link will be redirected to a web page that will infect their computer with Downloader.SQV. This Trojan then downloads two other Trojans: Spammer.AGF and KillFiles.BU. The first is designed to resend the emails, using the infected computer as a server, while the second prevents certain system functions from operating correctly.

“Malware creators frequently use sensational headlines or celebrities as lures to distribute malware. This is known as social engineering, and it is generally an effective technique”, explains Luis Corrons, technical director of PandaLabs.

To avoid falling victim to these malicious codes, PandaLabs advises users not to click links in emails from unknown sources. It is also advisable to have a good security solution installed and up-to-date to protect against both known and unknown threats.

More information about this issue is available at the PandaLabs Blog.


 

  • Feed RSS para notas de prensa

  http://www.pandasecurity.com/virus_info/exports/rss/pandaes.xml

 

  • Añade esta noticia a MyWeb

 

 

About PandaLabs

Since 1990, its mission has been to analyze new threats as rapidly as possible to keep our clients safe. Several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc), work 24/7 to provide global coverage. To achieve this, they also have the support of TruPrevent® Technologies, which act as a global early-warning system made up of strategically distributed sensors to neutralize new threats and send them to PandaLabs for in-depth analysis. According to Av.Test.org, PandaLabs is currently the fastest laboratory in the industry in providing complete updates to users. More information is available in the PandaLabs blog.

For more information: http://www.pandasecurity.com/homeusers/security-info/

Related Press Notes
2/7/2008 . Use of worms to steal confidential data increasing in 2008
2/14/2008 . Banker trojans detected in 2007 increased by 463%
For more information:

International Communication
E-mail: communication@pandasecurity.com
Phone Number:  + 34 91 806 37 00
Fax: + 34 91 806 37 00

   
Panda Security Internacional. Communication
E-mail: communication@pandasecurity.com
Phone Number + 34 91 806 37 00
Fax: + 34 91 804 35 29

Ronda de Poniente, 17 Tres Cantos
28760. Madrid.
 
 
RSS - Antivirus - PANDA SECURITYRSS - News coverage on virus and intrusion prevention | TWITTER - PANDA SECURITY Our Cloud Twitter | Web Map | Contact | Affiliates