PDA

View Full Version : "Osama Has Been Captured" Email Virus



SpursWoman
08-09-2005, 05:03 PM
Here's an email we got from our IT guys at work.....they said it was checked out and it was a legitimate threat, so if you get one, don't open it. :)



Warning

Emails with pictures of Osama Bin-Laden hanged are being sent
and the moment that you open these emails your computer will crash
and you will not be able to fix it!!!

This e-mail is being distributed through countries around the
globe, but mainly in the US and Israel.

Dont be inconsiderate; send this warning to whomever you know.

http://urbanlegends.about.com/library/bl_osama_virus.htm

http://www.truthorfiction.com/rumors/o/osama.htm

http://www.snopescom/computer/virus/osama.asp

Origins: There are few headlines that would grab the attention
of more computer users around the world than "Osama bin Laden
Captured," and that's exactly what whoever created this lure was
counting on to snare unsuspecting victims who use Microsoft
platforms.

"Osama bin Laden Captured" isn't a virus in itself; it's the
text of a message that includes a link to a file called
EXPLOIT.EXE. When a message recipient clicks on this link to view
what he thinks are pictures of Osama bin Laden's capture, he can
end up downloading an executable trojan known as Backdoor-AZU,
BKDR_LARSLPA, Download.Trojan, TrojanProxy.Win32.Small.b,or
Win32.Slarp.< BR>
Clicking the embedded link in the "Osama bin Laden Captured"
message auto-executes a file called "EXPLOIT.EXE," which exploits
a known security hole to download the trojan.

According to McAfee Security:

The trojan opens a random port on the victim's machine. It
sends the port information to a webpage at IP address
66.139.77.145. The trojan listens on the open port for
instructions and redirects traffic to other IP addresses.
Spammers and hackers can take advantage of compromised systems
by using the infected computer as a middleman, allowing them to
pass information through it and remain anonymous.


Microsoft has made available updates that close the hole
exploited by this trojan.


This has been a friendly Public Service Announcement. :)