R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Worm mutants spoof Internet Explorer

Alarm bells ring again as Dumaru worm launches bogus Microsoft website

Robert Jaques, vnunet.com 28 Jan 2004
ADVERTISEMENT

MyDoom.A is not the only virus users should be aware of, as three mutant modifications of the recently discovered Dumaru worm were identified in the wild.

Versions J, K and L of the email worm are rapidly creating a fresh global outbreak, despite using much the same techniques as the original infections, security firm Kaspersky Labs has warned.

Key to its spread is the worm's multi-tier propagation method. Initial dissemination is achieved by the mass mailing of a message purportedly from Microsoft in which users are - somewhat ironically - offered updates to their virus protection.

But in reality the message contains a Trojan URL spoof which, once activated, pops up an Internet Explorer window with a spoofed Microsoft website.

To make this site appear genuine the URL spoof uses a vulnerability in Explorer that allows the worm to display www.microsoft.com in the address bar, even though the user is actually at another site.

While the user is browsing this bogus site, the compromised PC is transformed into a Dumaru carrier from which the worm initiates its mailing process.

"This outbreak has once again demonstrated that virus writers and spammers are joining forces," said Eugene Kaspersky, head of antivirus research at Kaspersky Labs, in a statement.

"Virus [writers] are using spamming techniques more and more in order to increase propagation speed, [and] spammers are using viruses to create networks of infected machines for use in mass-mailing campaigns."

Although Dumaru was first detected late last year it has remained among the most active malicious programs ever since, according to Kaspersky.

The original worm was written in Russia, but subsequent versions which contain only minor modifications appear to come from Germany.

See also:

VirusFirst variant more dangerous than the original, warns antivirus firm  29 Jan 2004
MyDoomWorm hits 15 per cent of global email traffic in first 24 hours  28 Jan 2004
virusMydoom.A mass-mailer scheduled to launch DoS attack on SCO website via P2P network  27 Jan 2004
virus alertDumaru-Y spreads via .zip file named 'myphoto.jpg.exe'  26 Jan 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Skills Summary: Core Java/J2SE (Multi-threading), Java 6, Spring 2, UNIX, Linux, Shell-scripting, Python, Perl, Sybase. A position for a solid Core Java/J2SE Developer at a leading Investment Bank that has done exceptionally with profits in ... more >
| Evolution Recruitment Solutions
German Speaking Technical Support Translators, Poole, Bournemouth are required for my telephony services client. You will need to be IT literate and able to respond to technical queries in German fluently (native speaking ideally). Role ... more >
| Evolution Recruitment Solutions
French Speaking Technical Customer Support officers - Poole, Dorset required for my telephony services client. You will need to be IT literate and able to respond to technical queries in French fluently (native speaking ideally). ... more >
| Evolution Recruitment Solutions
Danish Speaking Technical Customer Support officers - Poole, Dorset required for my telephony services client. You will need to be IT literate and able to respond to technical queries in Danish fluently (native speaking ideally). ... more >
More job opportunities