Wednesday, November 28, 2007

Egyptian Vacation Photo Attack

If you recently received an e-mail with attached photos from the sender's vacation in Egypt, you probably want to take a pass.

As described by F-Secure in their blog, the e-mail has a new lure. The attachment is a ZIP file with multiple files. Most are JPGs, and there's a convenient "viewer_img.exe" program so that you can view the photos and infect your system with Russian malware.

When you run the program it loads the Russian version of pbrush.exe, or Windows Paint, to give you the sense that it has dome something legitimate. It also loads up a Russian data-stealing trojan horse named LdPinch.

No comments: