"email Trojans Threaten To Block Email Accounts


Recommended Posts

2 December 2008, 10:46

"Email Trojans threaten to block email accounts

A new wave of trojans is rolling through the net. This time, the emails bearing the Trojan warn that the recipient's email account will be blocked within a few hours:

Subject: The email address [email protected] is being blocked

Ladies and Gentlemen,

Due to misuse, your email address "[email protected]" will be blocked within the next 24 hours. We have received 98 complaints of spam being sent from it.

Details and possible ways to ublock your account can be found in the attachment.

The subject and text contain the recipient's address, though the wording and the number of alleged complaints varies. The attached zip file contains the executable file blocking.exe along with the malicious program. These emails should be deleted unread, because most virus scanners are powerless to deal with them. Only a few such programs can currently recognize the culprit: Sophos calls it Mal/EncPk-GH, Microsoft knows it as Win32/Emold.C or Win32/Obfuscator.CT, depending on the mutation, while FProt says it's W32/Trojan3.MX.

An analysis by heise Security has shown that the malware installs itself as the default debugger for the Explorer.exe process, so that it is activated after a reboot. This unusual self-starting mechanism has already been used by the "account-rendered" Trojan, which appeared in users' inboxes exactly a week ago, claiming to be an invoice, a collection order or a warning of non-payment."

source - Heise security: http://www.heise-online.co.uk/security/Ema...s--/news/112120

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...