Security Site Forum  

Go Back   Security Site Forum > Off Topic > Chatter Box

Reply
 
Thread Tools Display Modes
New XP Trojan
Old
  (#1 (permalink))
SSF Active Member
 
spaceghost's Avatar
 
Status: Offline
Posts: 442
Join Date: Dec 2003
New XP Trojan - 01-16-2004, 11:26 PM

Xombe Trojan poses as Microsoft warning
Last modified: January 12, 2004, 9:48 AM PST
By Munir Kotadia
Special to CNET News.com

An e-mail disguised as a message from Microsoft's security team contains a dangerous Trojan horse called Xombe.

Xombe, also known as Trojan.Xombe, Downloader-GJ and Troj/Dloader-L, was being distributed on Friday. It poses as a critical update for the Windows XP operating system. When executed, it attempts to download a malicious backdoor component from the Web.

It appears to be an imitation of one of last year's most successful worms, the mass-mailed Swen, which also masqueraded as a security warning from Microsoft.



However, Xombe has yet to repeat the success of Swen. While the former failed to make the top 10 threats intercepted by e-mail security company MessageLabs on Monday morning, Swen was at No. 2, with some 7,000 instances captured in the past 24 hours.

Ken Dunham, malicious code intelligence manager at security company iDefense, said that the success of Swen has encouraged virus writers to create e-mails and Web sites that appear official in order to fool more people into executing malicious code.

The e-mail, which appears to have been sent from [Only registered and activated users can see links. ], has the subject line "Windows XP Service Pack 1 (Express) - Critical Update" and directs users to execute the attachment, called winxp_sp1.exe, in order to fix some vulnerabilities in Microsoft's Internet Explorer, Outlook and Outlook Express.

Dunham said that once executed, the attachment downloads a file called msvchost.exe that alters the Windows Registry and opens certain ports in order to listen out for commands from a hacker.

Most antivirus companies have already updated their signatures, but users without up-to-date antivirus applications could be infected, helping the Trojan's author to take control of large numbers of PCs. Dunham said that once a "large army of zombie computers" has been built up, attackers could use them for serious crimes such as ID theft and banking fraud.

Microsoft was not immediately available to comment.

Although Xombe is only likely to be opened by Windows XP users, it affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT and Windows Server 2003 systems, as well as Windows XP, according to security company Symantec

Just sharing what I find. If you like it, rate it
Thanks

Last edited by spaceghost : 01-16-2004 at 11:29 PM.
   
Reply With Quote
 
Old
  (#2 (permalink))
SSF Active Member
 
listboxes's Avatar
 
Status: Offline
Posts: 1,047
Join Date: Dec 2003
01-17-2004, 06:14 AM

LMFAO only idiots get caught in the shit.


DER MEISTER
   
Reply With Quote
Old
  (#3 (permalink))
SSF Silver Member
 
tdh2028's Avatar
 
Status: Offline
Posts: 849
Join Date: Apr 2002
01-18-2004, 04:24 AM

I think it's about time i get a mac!!
   
Reply With Quote
Old
  (#4 (permalink))
SSF Active Member
 
Sako's Avatar
 
Status: Offline
Posts: 18
Join Date: Jan 2004
01-18-2004, 09:32 AM

Pfft. People who get caught by these probably shouldn't be using the internet anyways. ;-)
   
Reply With Quote
Old
  (#5 (permalink))
Super Moderator
 
phileditin's Avatar
 
Status: Offline
Posts: 3,562
Join Date: Nov 2003
01-18-2004, 04:52 PM

what one man makes, another man can break, otherwise you guys wouldn't be able to crack websites, but I'm damned glad you can.



[Only registered and activated users can see links. ]
[Only registered and activated users can see links. ]
[Only registered and activated users can see links. ]
[Only registered and activated users can see links. ]
[Only registered and activated users can see links. ]
   
Reply With Quote
Old
  (#6 (permalink))
SSF Active Member
 
Kangta's Avatar
 
Status: Offline
Posts: 75
Join Date: May 2002
01-19-2004, 02:07 PM

I dunno, i've gotten some weird virus's before.
   
Reply With Quote
Old
  (#7 (permalink))
SSF Advanced Member
 
jacobson's Avatar
 
Status: Offline
Posts: 259
Join Date: Sep 2002
01-20-2004, 07:25 AM

I wish i could write code like that lol
   
Reply With Quote
Old
  (#8 (permalink))
Moderator
 
DethPhunk's Avatar
 
Status: Offline
Posts: 3,438
Join Date: Aug 2002
Location: Security Site Forum
01-20-2004, 06:35 PM

I doubt if can that trojan get its work pass the Zone firewall?

As for switching to Mac.......Why not Linux? Or Lindows for that matter...

Macs I believe will die out someday, eventually in the Linux-Windows OS struggle for dominance, probably surviving only on art or graphic related areas.


There is no significant of Life itself without Rock and Metal!

-----------------------------------

Definition of Hot Girls

[Only registered and activated users can see links. ]
   
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Powered by vBulletin® Version 3.6.8 PL2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.

...... XXX adult password pass board forum
Stand With Haiti

Page generated in 0.11444592 seconds (62.59% PHP - 37.41% MySQL) with 15 queries