Entries categorized as ‘Internet Security’
Check this email out. It came from our Trend Micro support rep. They are acting like the reported Electronic Jihad virus might be catastrophic, even though they don’t know if it will work. Their last sentence is the most bizarre because of its alarmist overtone and misspelling. Let paranoia reign!
Dear PSP Customer,
Real-world terrorists are once again threatening to take their jihad (Holy War) to cyberspace. The notorious Al-Qaeda has threatened to launch a Web attack on Western anti-Muslim Web sites on the 11th of November, according to DEBKAfile, an online military intelligence magazine. An attack like this could be unleashed via the Electronic Jihad Version 2.0 software, which is not actually new and has been around for about three years now. The said software is capable of distributed denial-of-service (DDoS) attacks. It is also configurable and flexible, which makes it easy for cyber-terrorists to be more effective in the said attacks. Detailed Malware description: http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=HKTL%5FDAHIJ%2EA&VSect=Td
Researchers across the industry have raised quizzical eyebrows as similar threats have turned out to be a dud, like the cyber attack that never happ ened against U.S. banks and financial institutions in December 2006. However, such software was recently discovered by Trend Micro researchers. The hacking tool, which is detected as HKTL_DAHIJ.A, arrives as an installer package and may be downloaded from a remote site. This hacking tool connects to a URL for verification purposes. After successfully establishing a connection, it downloads a list from several URLs. The said list, which contains another set of URLs, is used by the affected system to launch Denial-of-Service (DOS) attacks for the so-called e-jihad.
Law enforcers and other experts say that threats such as these should not cause much of a fuss as Web threats happen on a regular basis. Eli Alshech, Director of the Jihad and Terrorism Studies Project at the Middle East Media Research Institute, considers these e-jihadists as more of a nuisance than a threat. But with these terrorists, we will never know what they will do next. Is 11/11 going to be another date to remember?
The next big Web attack may unfold on the 11th of Novemb
Thank you,
Trend Micro Premium Support
Categories: Computers · Internet · Internet Security
We’ve been getting sporadic, but steady reports of the TROJ_DLOADER.SPI virus being detected on machines. Trend Micro claims it’s not “in the wild.” That’s not true. I haven’t seen this many virus reports for XP in a long time. Trend Micro’s fix is to update DAT’s and scan the machine. I’ve tried to figure out what other anti-virus program providors are calling this virus to see if they recommend a different fix. The virus appears to come from webpages. Here’s a sample error:
Threat Alert from Anti-Virus ServerOfficeScan detected TROJ_DLOADER.SPI on PCname in my domains.
File: C:\Documents and Settings\<username>\Local Settings\Temporary Internet Files\Content.IE5\XFE1E8MF\_YzFvdDRpbmc_NzI4X2FvXzM5NThfMF8xMDIyOF9hb18_a2V5aW4_[1].exe
Detection date: 11/13/2007 14:33:05
Action: Virus successfully detected, cannot perform the Quarantine action
I’ll keep an eye on this. Let me know if you see anything.
UPDATE: I got some more info on this. Some of our SA’s have been tracking it. The virus alerts come up when people visit a certain media industry website. The site either pops up another site, or somehow redirects to “malware-scan.com”. Don’t go to that site unless you want to get infected. You should consider blocking that site using Websense or other tools. I hope this additional info helps.
Categories: Internet Security · PC's · Windows
An alert just came in from Trend Micro that says they are concerned about a potential Internet attack. This is vague and I know it sounds like it’s coming from the US Department of “Homeland Security.” Here it is:
High Probe Traffic Seen on ServerProtect Port 5168
PSP Announcement - 8/23/2007 6:53:13 AM - Proactive Notification: High Probe Traffic Seen on ServerProtect Port 5168 - Dear All:ICS [1] has reported a spike in the probe traffic on port 5168 which is used by ServerProtect. This might be an indication that hackers are preparing to launch an attack against this port. At this point however, we have not received any reports or samples which demonstrate the exploit.Please ensure that your Server Protect Systems have applied security patch 4 to ensure that known vulnerabilities are patched.
Please download the latest Server Protect Patch from the Trend Micro URL:
http://www.trendmicro.com/download/product.asp?productid=17
spnt_security_risk_notification_aug232007.pdf
Categories: IT · Internet Security · PC's · Technology · Windows