Ms. Polinka wants your bank account Posted by Mikko @ 11:00 GMT | Comments (3)

There's been a banking trojan spam run in four European countries this morning. The targeted countries are The Netherlands, Switzerland, Latvia and Finland.

The mails claim to be from a Russian student girl looking for a local sex partner - or failing that, just a friend. The mail urges the recipient to check her photos at a site called livejournalhelper.cn (in China).

Unfortunately, the site only has thumbnails on Ms. Polinka's pictures; when you try to view them in larger size you get an error message of a missing plug-in which you'd need to see the pictures. The plug-in of course if the malware itself - a manual man-in-the-middle banking trojan.

Here's what the sites look like in different languages:

polinka

polinka

polinka

polinka

This malware is very closely related to the so called "Mikkeli" case, found in February.

We detect the malware as Trojan-Spy:W32/Zbot.KZ. More information is available in the virus description.



資料來源 www.f-secure.com/weblog/archives/00001413.html
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()