About Me

Kevin McGhee

Kevin McGhee
Research Scientist

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Breaking News… NOT!

Friday, June 20, 2008 at 4:18am by Kevin McGhee
Kevin McGhee

There mustn’t be much going on in the world today as the Nuwar spammers have moved from jumping on real news of natural disasters and current affairs to creating their own fictional events! This high volume spam campaign is using some wacky subjects to lure people into clicking on the links:

Subject: Britney found hanged in locker room
Subject: White House hit by lightning, catches fire
Subject: Oprah found sleeping the streets
Subject: Eiffel Tower damaged by massive earthquake
Subject: Donald Trump missing, feared kidnapped
Subject: Lastest! Obama quits presidential race

This clever social engineering technique plays on peoples inquisitiveness in news of natural disasters and celebrities. The emails also follow the simple format of some text and a link that looks fairly harmless to the uneducated user.

All the links go to a fake pornotube page hosted on legitimate sites that have been hacked. If you click on the video (that’s actually just an image) it tries to download a .exe file. This is detected as BackDoor-DNM and the spam is also currently detected with our Anti-Spam products.

So it goes without saying.. NEVER click on links in an email unless you are sure of its origin, keep your Anti-Virus software up-to-date and if you have a website make sure its properly secured so you’re not hosting stuff like this.

Bookmark and Share

Tags: , ,

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (3)

  • michael lee October 2, 2008 4:50AM

    yes I have that dang thing in my system can u help me??

  • secure June 24, 2008 7:05AM

    sir,

    This is our problem pls solve this

    In our customer site as our customer request when we scan with the mcafee 8.5 (with latest update DAT:5323 Scan Engine:5200)
    it is not detect any virus, but when we scanthe same computer with E trust antivires it will detect virus. it’s name is Win32/Armax.I trojan, Win32/Armax.G trojan
    but mcafee anti vires did not find above virus

    F:\Dictionary\Dictionary .exe – Win32/Armax.I trojan. Deleted.
    F:\System\System .exe – Win32/Armax.I trojan. Deleted.
    F:\System\DriveGuard\DriveGuard .exe – Win32/Armax.I trojan. Deleted.
    pls solve our problem asoon as possible otherwise it will became the best marketing tool for the other antivirus vendors

    thank you,

  • Robin June 23, 2008 1:16AM

    Hello, thanks for the info.
    Would like to ask about Vista Antivirus 2008. All of the sudden, today, I have been told of all these ‘infected’ items that McAfee is not picking up. And now for some reason I can not get rid of Vista Antivirus 2008 creating a pop-up window every few minutes telling me that I am under ‘attack’, and being threatened by the ‘Blaster/Sasser.variant worm’. I have checked the Threat Center and have not found anything with this name. Can you please help me with this problem, and/or lend some insight into how I can deal with this trojan!
    R.