Malware outbreak with Trojan horse masquerading as a media file free RSS feed from Security Park
(08/05/2008)

McAfee Avert Labs has reported the most significant malware outbreak in three years with more than 500,000 detections of a Trojan horse masquerading as a media file.

Since Friday May 2nd, more than half a million instances of the Trojan have been detected on consumer PCs running. The malicious MP3 music or MPEG video files have appeared on popular file-sharing services such as Limewire and eDonkey.

McAfee rates the threat "medium" risk. No other malware has received that risk rating since 2005. All other threats since then were rated lower on the severity scale.

"This is one of the most prevalent pieces of malware in the last three years," said Craig Schmugar, threat researcher at McAfee Avert Labs. "We have never before had a threat this significant that arrives as a media file."

Cybercrooks loaded hundreds of rigged MP3 and MPEG files onto file-swapping services. The files are all named differently in multiple languages and vary in size to make them appear like legitimate music or video files. Attempting to play one of the malicious files will trigger the download of an application named "PLAY_MP3.exe" that will serve ads to the infected computer.

McAfee identifies the Trojan horse as "Downloader-UA.h."

Some of the sample names used by the malicious media files include "preview-t-3545425-adult.mpg" ; "preview-t-3545425-changing times earth wind .mp3" ; "preview-t-3545425-girls aloud st trinnians.mp3" ; "preview-t-3545425-jij bent zo jeroen van den.mp3" ; "t-3545425-lion king portugues.mpg" and "t-3545425-los padres de ella.mpg"

Consumers should take care downloading content from untrusted sources and use security software to protect against malicious files.

Related topics:  Virus, Worm, Email security, spyware and malware 

print versionPrint version | email this to a friendEmail to a friend | related articlesRelated articles

 

Other Security news and resources

IT Security white papers and research library

Access Control  Authentication  Data Management  Data Security  Digital Signatures  Email Security  Identity Management  Internet Security  Intrusion Prevention  Network Security  Remote access security  Security Management  Security Policies  Security Software  Security Threats  Virus Detection Software  Virus Protection  VPN  Vulnerability Assessment  Wireless Security 

Security books, guides, standards and toolkits

RFID and Smart Cards books, guides and reference documents  Biometric books, guides and reference documents  CCTV books, guides and reference documents  Intruder alarms and intrusion detection systems books, guides and reference documents  Monitoring and surveillance books, guides and reference documents  IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits  Fire, Health & Safety books, guides and reference documents





Ensure that you conduct an effective information security risk assessment that is in line with ISO 27001 by purchasing vsRisk™ Risk Assessment Tool

Need a
reference book?
Find it on Amazon:
Security books and magazines in association with Amazon.co.uk

Article search

Directory search


add your company
Google

Accelerate your ISO27001 project and develop an ISO27001-compliant Information Security Management System (ISMS) with the help of this toolkit
Home | About us | Contact us | Submit an article | Advertise | Newsletter | RSS Newsfeed | SEARCH