Jump to content

New email attack


Humpty

Recommended Posts

Websense? Security Labs? has discovered a new email attack that uses a spoofed email claiming to be from the United States Department of Treasury. This is similar to previous attacks claiming to originate from the IRS, Better Business Bureau, and Department of Justice. We have been tracking all of these attacks, and reporting them as they are discovered.

 

The message claims that a complaint to the Department of Treasury has been filed against the recipient's company. The email informs the reader that a copy of the original complaint has been attached to the email.

 

The attached "complaint" is a Trojan downloader with some backdoor capabilities. It is a ".pif" file with an MD5 of 9e19d23f27ebf9cfe1b9103066a3019e. It appears, however, that different versions of the Trojan are sent, based on the targeted recipient or company.

Websense Article

Link to comment
Share on other sites

There's also new warning for 'Opera Web Mail' users. (i think it applies to some other mail services as well.)

 

Virus warning! Mails that contain attachments and claim to be from the Opera Mail staff are infected by the W32.Beagle.J@mm worm, and should be deleted. Read more about W32.Beagle.J@mm for detailed information.

 

W32.Beagle.J@mm info

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.