The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
YOUR FEEDBACK
Cloud Envelops Exchange & SharePoint
the usr wrote: So... how about your prediction that SCO would prevail? 11/20/2008 565 - FINAL...
Nov. 22, 2008 07:46 AM
Cloud Computing Conference
November 19-21 San Jose, CA
Register Today and SAVE !..
Did you read today's front page stories & breaking news?
Live Google News by SYS-CON!

TOP THREE LINKS YOU MUST CLICK ON


From the Wires
'Heartworm' Targets MSN Messenger Users; Uses Hoax Cloaking Tactics as Elaborate Ruse to Steal Personal and Bank Data
FaceTime researchers uncover dangerous worm hosted on a Russian Web site using documented Internet hoax 'a virtual card for you'

By: PR Newswire
Sep. 22, 2006 03:49 PM

FOSTER CITY, Calif., Sept. 22 /PRNewswire/ -- Research experts at FaceTime Security Labs(TM), the threat research division of IM and greynet security leader FaceTime Communications, have discovered a new IM-borne threat targeting MSN Messenger users with a link that opens up a Web site that leads users to click on a "virtual card waiting for you." Users who click on this link see an image of a heart with a poem in Portuguese. The threat, known as W32.heartworm.a, installs files to steal a user's banking and personal data.

"The perpetrators have made a calculated move to tie this attack into numerous Web hoaxes, possibly to confuse infected users looking for help online," said Chris Boyd, director of malware research for FaceTime Security Labs. "Not only do they open up an image of a heart from a site dedicated to tackling online hoaxes, they also apparently named the attack after another online hoax -- a virtual card for you -- that has been in circulation since 2000. In this case, you really do receive a virtual card, but with a nasty additional 'bonus.'"

The infection spreads by running a file in circulation on Russian Web hosting sites claiming to offer a "virtual card" -- when the file is run, a picture of a heart containing a poem is launched, and the infected user will pass the infection link to their contacts on MSN Messenger with the phrase "olha o que eu fiz pra vc....curti ai...[url removed]

"The files are related to a certain strain of banking data Trojan particularly prevalent in Brazil, and are similar to those in the MW.Orc worm that plagued Google's Orkut social networking site earlier this year. (http://www.facetime.com/pr/pr060619.aspx )

Wayne Porter, senior director of special research at FaceTime Security Labs comments, "This is a form of cultural camouflage which we call 'hoax cloaking.' It is a defensive construct that adopts the very lore, memes, myth and culture of the Internet to serve as a self-preservation and cloaking mechanism. People using trusted search engines to verify the message will find most reputable security companies and hoax-debunking sites confirm it as a myth and disregard it as harmless."

Boyd, Porter and the FaceTime research team offer a detailed accounting of the W32.heartworm.a at http://blog.spywareguide.com/ .

Who is affected: Users of MSN Messenger instant messaging service, recently renamed Windows Live Messenger

Threat Type: Worm Risk Level: Medium How to protect against this threat

The initial file has the potential to infect MSN Messenger's more than 266 million users worldwide. (Instant Messaging Market Report, 2006-2010, The Radicati Group) Users can protect themselves by not clicking on links sent to them by other users, even if users appear on their contact list. Currently, most commonly used anti-virus programs do not provide protection from W32.heartworm.a.

Companies that use FaceTime Enterprise Edition and IMAuditor and have auto-update features activated are automatically protected against this threat. FaceTime also recommends activating the Day Zero Defense System within IMAuditor. The system utilizes anomaly detection techniques to analyze multiple characteristics of IM-borne worms and other malicious code against normal behavior, and provides patent-pending protection against many IM threats - in addition to traditional security signatures. FaceTime RTGuardian customers are automatically protected if they have auto update features enabled. FaceTime's X-Cleaner customers (formerly XBlock) should download the latest update and scan their PC for the worm.

About FaceTime Communications

FaceTime enables the safe and productive use of greynets like instant messaging, VoIP, Web conferencing and P2P file sharing. FaceTime Security Labs delivers the industry's first IMPact Index, which assesses "point-in-time" risks posed by viruses, worms and other malware propagating through greynet applications. FaceTime's award-winning solutions are used by more than 800 customers, among them nine of the ten largest U.S. banks. FaceTime supports or has strategic partnerships with all leading public and private IM network providers, including AOL, Google, Microsoft, Yahoo!, IBM, Reuters, Bloomberg, and Jabber.

FaceTime is headquartered in Foster City, California. For more information visit http://www.facetime.com/ or call 888-349-FACE.

NOTE: FaceTime, FaceTime Communications, IMAuditor, RTGuardian, GEM, Facetime Enterprise Edition, FaceTime Security Labs, IMPact Index, SpywareGuide.com, X-Cleaner and the FaceTime logo are registered trademarks and trademarks of FaceTime Communications, Inc. Other trademarks and registered trademarks are the property of their respective owners.

Contact: Emily Chamberlin of A&R Edelman, +1-650-762-2945, or echamberlin@ar-edelman.com, for FaceTime.

FaceTime Communications

CONTACT: Emily Chamberlin of A&R Edelman, +1-650-762-2945, or
echamberlin@ar-edelman.com, for FaceTime

Web site: http://blog.spywareguide.com/

Web site: http://www.facetime.com/

Published Sep. 22, 2006
Copyright © 2008 SYS-CON Media. All Rights Reserved.
About PR Newswire
Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  OpenWeb Developer Summit  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window