Websense Security Labs detects new email threat
Websense Security Labs has reported a new email that is spoofed as a story about a group of soccer fans that have been killed by teenagers. The email includes the subject: “soccer fans killed by 5 teens” and includes an attachment called “soccer_fans.jpg.exe”.
If the attachment is run, a Trojan Horse downloader connects to a website that is hosted in the United States and was up at the time of this alert. The filename downloaded is called “dianaimag.exe”. When that file runs, it attempts to disable Microsoft’s Firewall and then visit another website to download code.
Both these websites are reported to host adult content. They may have been compromised, or may be a part of the authoring of the malicious code.
Del.icio.us
Cosmos
Digg