x10Hosting Forums

Corporate Free Hosting for the Masses.


x10Hosting wishes you a great Year!

Register

Closed Thread
 
LinkBack Thread Tools Display Modes
x10Hosting Member

Join Date: Oct 2006
Posts: 51
Credits: 586
Mind-Designers is on a distinguished road
Location: The Netherlands

Send a message via MSN to Mind-Designers Send a message via Yahoo to Mind-Designers
 
08-17-2007, 04:35 AM
Greetings! Someone Has Sent You an E-Card Virus

Think you got a cheery greeting card from a friend via e-mail?

Well, think again, and be careful before opening it. A new form of fake e-card notification e-mails are unleashing nasty viruses and virus-carrying Trojan horses on unsuspecting users.

While e-card-triggered viruses and Trojan horses are not new, the latest versions are becoming more difficult for typical antivirus and antispam defenses to detect, according to alerts issued today by security software vendors Avinti Inc. and F-Secure Corp.

The new complication, said Dave Green, chief technology officer at Lindon, Utah-based Avinti, is that the latest slew of fake e-card e-mail notifications are using plain text in their messages, which don't get scanned and scrutinized by antivirus and antispam defense applications. While the e-mails don't contain pasted links or attached files that a recipient can click on to get a computer infection, many e-mail clients automatically convert the included text into a clickable link when the e-mail clients recognize a Web address in the text.

"It appears they have done that to get around a lot of the parsing used by antivirus and antispam applications" to fight such attacks, Green said. "It's an interesting cat-and-mouse game between the bad guys and the good guys."

"Apparently, they've found that they can be very successful in getting these through by not having it be formatted as an HTML message," Green said.

All recipients have to do to trigger the virus is to click on the link created by the e-mail client once they have read the message, he said.

Adding to the confusion and the potential seriousness of the problem, he said, is that the perpetrators sending these e-mails are using the names of some of the most popular electronic greeting card companies in their messages and Web links.

Avinti said it has updated its Avinti Isolation Server product to protect against such attacks, while other vendors are still updating their own products.

Avinti's alert said the links to the fake e-greeting cards lead to IP addresses in various locations, including the U.S. and Eastern Europe, and many are registered to U.S. Internet service providers. The damaging payload files are new variants of the Storm Worm virus that was first detected in January, the company said.

In its alert today, Helsinki, Finland-based security vendor F-Secure said the fake e-card messages from one group of online criminals appear to have changed since last night, when they dropped the use of attached files and went to plain-text messages.

An included link then tells the recipient to install a free "Microsoft Data Access" application to retrieve the e-card, but that file -- msdataaccess.exe -- is a damaging virus. F-Secure said it has identified the virus as Email-Worm.Win32.Zhelatin.gg.

Danny Allan, director of research at security analysis vendor Watchfire Corp. in Waltham, Mass., said he has seen similar all-text e-greeting mailings before, but the numbers have increased lately.

For antivirus and antispam vendors, the theory had been that if the message includes plain text without links and attachments, it could cause no harm, he said. That approach has to change, Allan said.

User need to be cautious and not click on links they find in e-mails, Allan said. Instead, they should go directly to a Web site by typing its address into a Web browser and go there on their own, bypassing links that could be malicious.

Vendors will have a tough time making the problem go away completely, he said, because they can't devise ways of evaluating every Web link or instance in an e-mail. However, they can improve detection of suspicious encoded characters and domain names in messages.

"If there was a silver bullet that could solve the problem, the antivirus companies would have done it," Allan said.

Zully Ramzan, a senior principal researcher at Cupertino, Calif.-based security vendor Symantec Corp.'s security response team, said Symantec has seen plain-text attacks before and doesn't view them as a new problem.

"There's been a bit of a resurgence lately" with e-card notification messages, possibly because of last month's July 4 holiday or because criminal groups have been organizing mailing campaigns, he said.

Andrew Jaquith, a security analyst at Boston-based Yankee Group Research Inc., said the latest e-greeting attacks are an example that criminals "are going to be coming up with more and more ingenious ways of tricking people or exploiting ways of tricking your e-mail client. This is just one of any number of ways that these guys are going to try to lure users to do something they shouldn't."

Computerworld
For more enterprise computing news, visit Computerworld.
Story copyright © 2007 Computerworld Inc. All rights reserved.

Bron: PCWorld
__________________

Mind-Designers is offlineReport Post
Retired

Spartan Erik's Avatar

Join Date: Aug 2005
Posts: 3,361
Credits: 2,900
Spartan Erik is a glorious beacon of light
 
08-17-2007, 09:38 AM
Re: Greetings! Someone Has Sent You an E-Card Virus

Hah that's clever; I dump half the email I get anyway, so no big concern there!
Spartan Erik is offlineReport Post
x10 Elder

Join Date: Mar 2006
Posts: 815
Credits: 13,770
noerrorsfound has a reputation beyond repute
 
08-18-2007, 01:25 PM
Re: Greetings! Someone Has Sent You an E-Card Virus

I've been getting these, and it's weird because I've never gotten spam mails in my Gmail account before, because I always obfuscate my address in some way when posting it anywhere.

I'm immune to this, anyway, because I'm on Linux. :D
__________________
noerrorsfound is offlineReport Post
x10Hosting Member

Join Date: Aug 2007
Posts: 44
Credits: 810
rockthecasbah is on a distinguished road
 
08-22-2007, 04:00 PM
Re: Greetings! Someone Has Sent You an E-Card Virus

I've been flooded with those in my gmail inbox! Luckily it goes straight to spam.

I don't get that spam in my hotmail inbox but I find hotmail's "filters" a joke. You can barely configure them to be intuitive and you can't block mail from senders with certain words, just example@hotmail.com type filtering in the from section.
rockthecasbah is offlineReport Post
x10 Sophmore

chewett's Avatar

Join Date: Aug 2007
Posts: 109
Credits: 1,838
chewett is on a distinguished road
 
08-30-2007, 07:15 AM
Re: Greetings! Someone Has Sent You an E-Card Virus

yes the best filtering i have found is by configuring microsoft outlook with a pop3 email address. then i use my norten antivirus to scan every email i recive and it gives me a warning ratiing and such but because of that 99% of my messages go into norten internet security folder
chewett is offlineReport Post
x10Hosting Member

Join Date: Aug 2007
Posts: 40
Credits: 657
darkstang is on a distinguished road
Location: Springfield, IL

Send a message via MSN to darkstang
 
08-30-2007, 09:57 AM
Re: Greetings! Someone Has Sent You an E-Card Virus

I haven't gotten any of these yet. *checks spam box* Lots of people still want to sell me viagra though.
__________________
http://www.darkstang.com
darkstang is offlineReport Post
x10Hosting Member

Join Date: Aug 2007
Posts: 98
Credits: 1,099
Despistado is on a distinguished road
 
08-31-2007, 04:42 AM
Re: Greetings! Someone Has Sent You an E-Card Virus

Thank you very much for the tip , Ill take care more about those message
Despistado is offlineReport Post
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Beware Of The Jackson Suicide Virus stealth_thunder Scripts & 3rd Party Apps 7 06-30-2005 12:13 PM
Types of computer viruses Skyline4life Off Topic 6 06-27-2005 04:45 AM
Whats in your wallet? Skyline4life Off Topic 18 06-25-2005 11:26 AM
Creating a Card Game Script Rhianna Scripts & 3rd Party Apps 17 05-30-2005 04:12 AM
Spyware & Virus stealth_thunder Scripts & 3rd Party Apps 0 05-19-2005 02:45 AM


All times are GMT -5. The time now is 06:13 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC7
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios