A new Storm site advertises a networking application. That site looks like this:

zhelatin-ke (89k image)

However, a mere visit to the site using an unpatched system will trigger an exploit to automatically download and execute a malicious file. Patched systems are protected but only if the users do not choose to download the file (with filename krackin.exe) and execute it themselves.

The webpage is detected as Trojan-Downloader.JS.Agent.kd while the file is detected as Email-Worm.Win32.Zhelatin.ke.

This is one network you wouldn't want to join, so make sure to keep your databases updated.


Posted by Ian @ 20:32 GMT | Comments
http://www.f-secure.com/weblog/archives/00001296.html
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()