
SonicWALL UTM Research team discovered a new MSN Messenger based threat starting April 29, 2009. There are 2 types of IM threats: those that arrive through "send a file" functionality of the instant messaging client, and those that arrive through link-spamming. This attack is of the latter type, as it arrives in form of links via MSN messenger messages pretending to be pointing to image files.
Sample MSN instant message looks like:
It performs the following activity on the victim machine:
The screenshots of the sample messages are shown below:
SAMPLE MESSAGE #1
SAMPLE MESSAGE #2
If the user clicks on the link, it downloads the malware executable file that has an icon disguised as a JPEG image file and it looks like this:
When the user tries to open the file, it opens up the following windows dialog box saying Picture can not be displayed:
The Trojan is also known as Virus.Win32.Trojan , BackDoor.IRC.Wisdom , and Win32:Trojan-gen
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: IRCBot.EMSN (Trojan) signature.
Share This Article

An Article By
An Article By
Security News
Security News