• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

Storm for Rent

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Storm for Rent

    Malicious intent may be involved as malware authors use the Brazilian telecom carrier TIM in their latest scam to deliver malware. Trend Micro researchers have come across the following sites, supposedly from the telecom company:
    • http://{BLOCKED}rfilho.sites.uol.com.br/___
    • http://www.{BLOCKED}m.com.br/downloads/MMS/VideoMensagens/VideoMensagem.html
    The sites invite the user to see a video clip sent to him/her by the video message service offered by TIM. However, the sites try to download an ActiveX component that most probably contains malicious code. The source of the downloaded file is deeply buried within obfuscated code.

    After further analysis, it has been discovered that the malware connects to an FTP server where it downloads files having a .MOD extension. The downloaded files are then modified and installed on the infected system.

    What’s even more surprising is that an HTML file included in the download contains an iFrame connecting to http://{BLOCKED}rrychristmasdude.com/ind.php — one of the URLs previously associated with the infamous Storm botnet. Surprise, surprise!

    It is not excluded that, the Storm botnet has been rented out to some Brazilian Trojan Bancos group, as one may argue. Christmas-themed URLs may be way out of season but its spirit lives on, –especially for malware creators– in any part of the world, in any time of the year, ready to serve and deliver malicious content. And its guise of an innocent-looking legitimate telecom site may be just to reach out to more unsuspecting victims.

    Roderick Ordoñez

View our Terms and Conditions

LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
Working...
X