Archive for June, 2009

WARNING: Michael Jackson Spam Distributes Malware

The article below was originally posted by the Internet Storm Center.

As we anticipated in our yesterday’s diary, spammers are starting to exploit attention-grabbing headlines of recent celebrity deaths. Sophos described one such message, with the subject “Confidential===Michael Jackson”, in their blog posting. Today we’re starting to see reports of these messages directing individuals to websites that distribute malicious software.

For example, Steve Basford emailed us a link to his blog posting, where he discusses a spammed fake news item invites the victim to download a “video” to download. The message said: “As redes de televisão americanas CBS e ABC também estão noticiando a morte do cantor, assim como a versão online do jornal New York Times e da revista Variety…” (See screen shot below.)

The victim was asked to download the “video” file is named “Michael.Jackson.videos.scr” was actually a malicious program–a downloader that would start the infection chain. See the VirusTotal report.
Update: Websense is reporting that they are seeing this campaign as well in their blog posting, and offer a few additional details.

– Lenny

Lenny Zeltser – Security Consulting

Lenny teaches malware analysis at SANS Institute. You’re welcome to follow him on Twitter. You can also track new Internet Storm Center diaries by following ISC on Twitter.

Post to Twitter Post to Delicious Post to Digg Post to Facebook Post to StumbleUpon

WARNING: Michael Jackson death SPAM

With the reported death of Michael Jackson today, it is likely only a matter of hours before we will start seeing SPAM relating to the subject.   So here is a reminder that mail from unknown sources should not be opened and links should not be clicked.

If you do see any of the SPAM relating to this drop us a quick note.

Post to Twitter Post to Delicious Post to Digg Post to Facebook Post to StumbleUpon

Web security company Panda Security contacted Mashable.com to warn that malware links have started to invade Twitter’s Trending Topics. Click here to read the full article.

Post to Twitter Post to Delicious Post to Digg Post to Facebook Post to StumbleUpon

Microsoft has issued a Security Bulletin Advance Notification indicating that the June release cycle will contain ten bulletins, six of which will have a severity rating of critical. The notification states that these critical bulletins are for Microsoft Windows, Office, and Internet Explorer. There will also be three important bulletins for Microsoft Windows and one moderate bulletin for Microsoft Windows. Release of these bulletins is scheduled for Tuesday, June 9.

Network Logix will provide additional information as it becomes available.

Post to Twitter Post to Delicious Post to Digg Post to Facebook Post to StumbleUpon