Peaches Posted September 30, 2009 Report Share Posted September 30, 2009 Sep29. 2009Tropical Storm Leads to FAKEAV by Jessa De La Torre (Threat Response Engineer) Cybercriminals leveraged on the tropical storm, Ondoy (International name: Ketsana) that hit the Philippines and killed around 140 people. Senior Threat Analyst Joseph Pacamara found several malicious sites that appeared each time the users search the strings, "manila flood," "Ondoy Typhoon," and "Philippines Flood," among others. The said sites emerged as one of the top search results. Once the user clicks the URL, they will be redirected to several landing pages where they are asked to download an EXE file, soft_207.exe. Trend Micro detects it as TROJ_FAKEAV.BND. This attack does GeoIP checks, which mean it only targets specific regions or location (one of the landing sites is hxxp://{BLOCKED}uterbestscan11.com More details & screenshots at TrendLabs - http://blog.trendmicro.com/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.