[LINK] Identity theft virus infects 10,000 computers

Jan Whitaker jwhit at melbpc.org.au
Sun Aug 13 08:38:33 AEST 2006


At 04:59 AM 13/08/2006, Rick Welykochy wrote:
>And still, even now, I see no reference in the advisory to either of
>(a) the operating system and related software which is affected by this 
>trojan; and
>(b) the name of the vendor of such software.

It's in the header:
===========================================================================
A  U  S  C  E  R  T                                           A  L  E  R  T

                        AL-2006.0068 -- AUSCERT ALERT
                                    [Win]
      Greeting card trojan contains Haxdoor credential-stealing malware
                               11 August 2006



But I agree that it's pretty small in this case, unlike many of their 
alerts that have a full section of the affected software and opsys.

The original one does identify the opsys's:

===========================================================================
A  U  S  C  E  R  T                                           A  L  E  R  T

                        AL-2006.0049 -- AUSCERT ALERT
                                    [Win]
           Malicious "National Bank bankrupt" email links to sites
                       targeting multiple web browsers
                                15 June 2006

===========================================================================

         AusCERT Alert Summary
         ---------------------

Operating System:     Windows
Impact:               Execute Arbitrary Code/Commands
                       Access Confidential Data
Access:               Remote/Unauthenticated




Jan Whitaker
JLWhitaker Associates, Melbourne Victoria
jwhit at janwhitaker.com
business: http://www.janwhitaker.com
personal: http://www.janwhitaker.com/personal/
commentary: http://janwhitaker.com/jansblog/

'Seed planting is often the most important step. Without the seed, there is 
no plant.' - JW, April 2005
_ __________________ _



More information about the Link mailing list