funsec mailing list archives

Turn Your Computer into a Zombie: Try to Unsubscribe from this Cell Ph one Dating Service Scam


From: "Fergie" <fergdawg () netzero net>
Date: Wed, 19 Jul 2006 12:19:37 GMT

I ran across a consumer alert article, which pointed me to this
double whammy.

Scammers never sleep. :-)

Via the IC3.

[snip]

The FBI has been alerted to a newly discovered malware located at
www.irrealhost.com. Malware is software designed to infiltrate or
damage a computer system without the owner's consent.

The identified malware lures victims to the site through the receipt of
an SMS message on their cellular phone. An SMS message is a Short
Message Service that permits the sending of short messages, also known
as text messages. The message thanks the recipient for subscribing to a
dating service, which is fictitious, and states the subscription fee of
$2.00 per day will be automatically charged to their cellular phone
bill until their subscription is canceled at the online site.

Recipients visiting the site www.irrealhost.com to cancel their
subscription are redirected to a screen where they are prompted to
enter their mobile phone number, then given the option to run a program
which is supposed to remove their subscription to the dating service.

When the run option is selected on the Web site, the executable adds
several files to the host and changes registry settings to open a
backdoor port and lower Windows security settings. The host file is
modified to prevent the victim from browsing to popular anti-virus Web
sites. The executable also turns the infected computer into a "zombie"
network, which can be remotely controlled by the hackers.

[snip]

Link:
http://www.ic3.gov/media/2006/060628.htm

- ferg


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: