Interview

iVK Mobiles Takes Bottom to Top Route...

iVK Mobiles Takes Bottom to Top Route...

Grass root level growth, that ' s what mobile com
Read More >

READ All

Analysis

Understanding the V-Word...

By Ajay Goel, Managing Director, India & SA
Read More >

READ All

US Military Actions Used as Decoy to Spread Malware

Posted on July, Monday 14, 2008 By ITVN News Service

Storm Worm infecting user as they look for information on the tensions in the Middle East.


BitDefender researchers have identified a new wave of spam messages that announcing an alleged attack of the US Army against Iran in order to trick users into downloading and installing malicious software onto their personal computers.

The webpage hosting the piece of malware – dailydotnews.com - is a simple, yet efficiently designed site with a top banner, a simple picture masquerading a YouTube player and three lines of text detailing the US operation in Iran. This spam approach is used on large scale as the spammer relies on a catchy heading and a link to the piece of malware in order to fuel users’ curiosity and trick them into downloading the piece of malware.

“The new spam wave relies on computer users’ curiosity regarding the conflict between the United States and Iran. Users are redirected to a fake news website, where they are shown a larger, inciting description accompanied by a movie player,” said Andra Miloiu, BitDefender Spam Analyst. “However, the alle

ged flash movie is an image depicting a movie player; when clicked, the image gives users a ‘Save image as’ option.”

Upon clicking on either the “movie” or the top banner, the user starts the download process of a binary piece of malware, called “iran_occupation.exe.” The file contains the same malicious code infecting the user with the Storm Worm. The authors have used timing as their advantage, as the recent tensions in the Middle East between the US and Iran have been escalating.

On the social side, the spam wave is targeting the increasingly worried US citizens looking for fresh news on Iran threatening to burn Tel Aviv down in response to possible US attacks on its nuclear facilities.

The BitDefender antivirus is currently filtering and detecting that both the spam message and the malicious code, “iran_occupation.exe” binary, are infected with Trojan.Peed.PM.

Discuss this Story

 


 Add a Comment

Reload Image



"ITVAR News welcome comments that advance the story directly or with relevant information. We try to block comments that appear to be spam or use offensive language. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of IT VAR News or Techplus Media. We cannot be held responsible for error and authenticity of details associated with comments. IT VAR News does not endorse the products or its specifications."

 Comments

Linda

Posted : April, Thursday 28, 2011

Image Exif data is quite useful to for image forensics. But EXIF data won\'t tell you too much - the user might have loaded the photo into something like Photoshop just to crop it the way he wanted. Site Photoshopped I