On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Apr 4, 2005 5:28:00 PM

A worm that first disguised itself as an e-mail from computer vendors is now attempting to trick MSN Messenger users into executing malicious files.

The Chod.B worm, which was first discovered on April Fools' Day, spreads via e-mail purportedly from Microsoft and security companies Symantec and Trend Micro.

When using the MSN Messenger instant-messaging client as its propagation tool, the virus sends out messages to contacts from the infected user's address book, warning them that they are about to receive a file. The virus then sends a file designed to infect the recipient's system.

Adam Biviano, Trend Micro's senior systems engineer, said the development is "alarming" because the technique mimics the behavior of a real IM user.

"The virus will send you a message first saying, 'Check out what I just found on the Internet,' and then sends you (the malicious) file. It is not just sending files out of the blue anymore--it is trying to imitate what a friend in your contact list would do," he said.

Chod.B also contains a tool that allows it to steal passwords from a number of IM applications--including America Online's AIM, ICQ Lite, Miranda, MSN Messenger Trillian and Yahoo Messenger, Biviano said.

He said that because the virus author has included a way to communicate with the virus, it could mean that in the future the same virus could be instructed to infect more than just MSN Messenger users.

However, even when using e-mail to spread, Chod.B spoofs the "from" field of the e-mail so it appears to have been sent from either security@microsoft.com, security@trendmicro.com or securityresponse@symantec.com.

According to Biviano, viruses in the past have tried to look like they were sent by Microsoft but this is the first time that virus writers have tried to pass off a virus as a message from an antivirus company.

"We have seen them in the past from Microsft.com, but not specifically from the other two addresses. It is just another social engineering attempt to try and trick users into executing the files," Biviano said.

Biviano said although Chod.B is cleverly designed, it is unlikely to become a widespread threat.

MSN Messenger--which has previously been targeted by virus writers--isn't the only instant messaging service to be exploited. Last week, phishers took aim at Yahoo's Messenger service, attempting to steal usernames, passwords and other personal information. The Internet giant confirmed that attackers were sending its members links to fake Web sites that mimicked a Yahoo site and asked people to log in by entering their username and password.

Security company Websense has warned that hackers are increasingly using IM applications to fool users into installing malicious code and revealing personal information.

Munir Kotadia of ZDNet Australia reported from Sydney.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 84 Talkback(s)
Don't be silly.
You don't know what your talking about. There are tons of Linux viruses out there, and as its popularity increases, so will the # of viruses.

Just because hackers don't target somethingd DOE... (Read the rest)
Posted by: TysonZwicker Posted on: 04/15/05 You are currently: a Guest | | Terms of Use
How many times to we have to worry about Worms/Viruses  matrixdomain | 04/04/05
Do you honestly believe...  PA-ITGuy | 04/04/05
this virus/worm code does NOT EXECUTE IN LINUX  matrixdomain | 04/04/05
NWOR  PA-ITGuy | 04/04/05
I hear Jack Nicholson....  Xunil_Sierutuf | 04/04/05
No You Just Have to Worry About Your Linux Worms!  kdaulton | 04/04/05
When someone makes one  jrepin | 04/04/05
can anyone say rootkit  net2dave | 04/04/05
Only if..  Patrick Jones | 04/04/05
sorry... try again  kergan | 04/04/05
Foot in Mouth  golowenow | 04/04/05
this virus/worm code does NOT EXECUTE IN LINUX  dogman01@... | 04/04/05
We heard the same thing  lengua99 | 04/05/05
Maybe they will...  PA-ITGuy | 04/05/05
I believe...  Patrick Jones | 04/04/05
So that would mean...  PA-ITGuy | 04/04/05
No..  Patrick Jones | 04/04/05
common end-user installation  net2dave | 04/04/05
No, I don't..  Patrick Jones | 04/04/05
Point taken  PA-ITGuy | 04/04/05
Root Schmoot  osreinstall | 04/04/05
User accounts  Linux User 147560 | 04/04/05
I would image just in case of hard drive failure.  osreinstall | 04/04/05
RAID  Linux User 147560 | 04/04/05
There is still a single point of failure  Hugh Jass | 04/04/05
Very Recent  osreinstall | 04/04/05
Imaging is a WinBlows solution  lengua99 | 04/05/05
Whatever you say Marc  osreinstall | 04/05/05
A subtle difference  Sxooter_z | 04/04/05
A good, active,  bony tryan | 04/04/05
FWIW  PA-ITGuy | 04/04/05
No worries on Linux  jrepin | 04/04/05
Linux is not the all inculsive answer.  djcanter | 04/04/05
quick books  Sxooter_z | 04/04/05
QuickBooks  djcanter | 04/04/05
Here..  Patrick Jones | 04/04/05
Quickbooks alternatives..  widge_z | 04/04/05
and to think all the CPA firms i work with...  Monkey_MCSE | 04/04/05
No problem runing bussines with Linux  jrepin | 04/04/05
HERE HERE!!!  mdsmedia | 04/04/05
Agreed and NEVER will be  golowenow | 04/04/05
never used a Mac recently have you?  Monkey_MCSE | 04/04/05
I know I shouldn't feed the troll, but  whogoesthere | 04/04/05
First off  lengua99 | 04/05/05
there are lots of Applications for Linux  matrixdomain | 04/04/05
Linux is not the all inculsive answer.  richdave | 04/04/05
Linux provides all the computing needs  matrixdomain | 04/04/05
Did you try to use  lengua99 | 04/05/05
What ???  GetReal-mac.com | 04/04/05
*cough Lion, Slapper cough* (NT)  Loverock Davidson | 04/04/05
Lion and Slapper?  Zogg | 04/04/05
The answer is ten!  cdgoldin | 04/04/05
The switch to Linux saved at least 35%  matrixdomain | 04/04/05
RE: The answer is ten!  Linux User 147560 | 04/04/05
How many times...?  Wolfie2K3 | 04/04/05
So we should all switch to Linux?  strask | 04/05/05
Don't be silly.  TysonZwicker | 04/15/05
From on insecure MS application to another..!  Xunil_Sierutuf | 04/04/05
Mac OSX!  Reverend MacFellow | 04/04/05
RE: Mac OSX!  richdave | 04/04/05
What is this "great" OS  T25 | 04/04/05
Re:What is this "great" OS  richdave | 04/04/05
Linux viruses hardly exist because:  osreinstall | 04/04/05
RE: Linux viruses hardly exist because:  Linux User 147560 | 04/04/05
I knew you would post to this.  osreinstall | 04/04/05
Set a trap, eh?  Hugh Jass | 04/04/05
Not what I was driving at  osreinstall | 04/04/05
IM Worm's  southern 2 | 04/04/05
This is interesting  Linux User 147560 | 04/04/05
Windows Viruses/Worms can cost you $90,000  matrixdomain | 04/04/05
Yeah yah..  Wolfie2K3 | 04/04/05
LOL!!! Hysterical!  whogoesthere | 04/04/05
Why don't you Linux freaks go crawl in ur box and hide?  zookeeperz@... | 04/04/05
I use w2k as well  JasonL31 | 04/04/05
"downgrade"?  CobraA1 | 04/05/05
I do not use MSN - so nope, not a worry here  JasonL31 | 04/04/05
ms biggest problem  JasonL31 | 04/04/05
IM Virus  soulcircus | 04/04/05
this worm did some things I tell you  Sakkara1331 | 04/05/05
Bounty on Virus writers and other malicious software creators  patrickthered | 04/05/05
You said it!  Roger Ramjet | 04/05/05
Shoot the Messenger  Songirl15@... | 04/05/05
What about other clients?  jcgcompute | 04/06/05
Well we all knew it was comeing  jwick | 04/14/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here