Malware distributors incorporate well-known brands in their email spam to deliver dangerous programs to unwitting victims
A few weeks ago, the emails switched from a “shipping confirmation” hook to one which claims the contents of the attachment include a code worth $50 on Apple’s iTunes online store.
The spam messages for several months have included a .Zip compressed attachment. The file inside the .Zip, which looks like a Microsoft Word document, is a malicious program we classify to the definition Trojan-Downloader-Tacticlol.
An extremely dangerous downloader, the Web sites and domains from which Tacticlol (aka Oficla or Sasfis) retrieves its payloads have been remaining online longer than normal. Typically the download site is shut down within a few days, effectively neutralizing the downloader and preventing it from retrieving anything. Recent variants, however, have use Web domains that remain online for weeks or even months.
Malicious sites that remain active only increase the danger that someone who inadvertently opens the attachment a few weeks after the message arrives will still infect their computer.
In addition, the payloads delivered by the download site Tacticlol contacts are being rotated as the days go on. In the initial infection period, within about 36 hours after the spam messages arrive, the download sites deliver a number of different payloads, including the Trojan-Backdoor-Zbot keylogger, the Trojan-Pushu (aka Pushdo) spam bot, and rogue antivirus installers.
After a week, the payloads switch to the installers for botnets, which zombify the infected machines and turn them into longer-term hacker workhorses. Recent payloads have included a “dead man switch” which can render the infected computer unbootable.
You should always avoid opening any attachment that arrives through email unless you can confirm - by telephone, or some other method - that the attached document is legitimate and was deliberately sent to you. Also, train yourself to avoid opening any attachment with an .exe file extension, regardless of its appearance or origin.
Print version |
Email to a friend |
View other articles
Latest IT, computer and network security articles
Cloud-based Infrastructure as a Service save up to 55 percent of IT operations spend
IronKey helps Orbotech ensure all high value company and customer data is secure
Passwords are past their sell-by-date
RandomStorm appointment signals European and worldwide expansion
India and Russia are the biggest producers of viruses
Misconfigured networks are the easiest IT resource hackers exploit
The Return of Ransomware and Do-it-Yourself Botnets
Atos Origin secures and manages the IT systems for Singapore 2010 Youth Olympic Games
Djigzo partners with Comodo to provide email encryption and authentication solution
...[view more IT, computer and network security articles]...
Other IT, computer and network security Resources
Security websites for specific products:
Access control and RFID systems - Burglar alarm, intruder alarm and fire alarm systems - Biometric recognition and identification systems - CCTV cameras and systems - IT, computer and network security systems - Health and safety - Security guard services - Surveillance and remote monitoring systems
Security websites for specific markets:
Bank and financial security - Corporate security - School and education security - Sport event and live venue security - Healthcare and hospital security - Hotel restaurant and casino security - Industrial and manufacturing security - Infrastructure and Utilities security - Home and personal security - Public sector security - Retail security - Small Business security - Transport security

