PC Pals Forum

Technical Help & Discussion => General Tech Discussion, News & Q&A => Topic started by: Clive on July 17, 2006, 15:30

Title: Trojan downloader uses Zidane lure
Post by: Clive on July 17, 2006, 15:30
A different kind of viral email

By John Leyden
Monday 17th July 2006 13:28 GMT

Nefarious virus writers are using continued interest in Zinedine Zidane's infamous headbut in the World Cup final in order to distribute malware via a malicious website (screen shot here) that poses as an official FIFA World Cup 2006 website.

Surfers straying on the site are exposed to a Trojan horse downloader, which uses Windows exploits in a bid to install malware on vulnerable PCs. If successful, additional malware payloads are downloaded on to victimised machines.

According to web security firm WebSense, the US-based site uses the underground "Web Attacker" toolkit, a malware package available from a Russian website at anywhere between $20 and $300.

The appearance of the site coincides with the continued circulation of humourous emails satirising Zidane's headbut outrage.

The latest hacker attack is a "viral email" of a very different type, that illustrates, once again, how hackers frequently look to topical events in order to propel the distribution of malign code. ®


http://www.theregister.co.uk/2006/07/17/zidane_trojan/
Title: Trojan downloader uses Zidane lure
Post by: mistybear on July 17, 2006, 16:49
That's a little scary or am I being paranoid. I just ran a scan and Hijackthis.
Title: Trojan downloader uses Zidane lure
Post by: Simon on July 17, 2006, 17:24
Well, unless you've been to the website, there's nothing to worry about.  

Here's the screenshot referred to in Clive's post.

(https://www.pc-pals.com/smf/proxy.php?request=http%3A%2F%2Fwww.websense.com%2Fsecuritylabs%2Fimages%2Falerts%2Fworld_cup_web_attacker.PNG&hash=42afc1f401972c88f8fd9c6f3792ebc7e43331e0)
Title: Trojan downloader uses Zidane lure
Post by: mistybear on July 18, 2006, 04:12
I was worried that it had something to do with this.

http://blogs.smh.com.au/mashup/archives/005184.html

I posted that in the Footy Forum section.
Better to be paranoid than sorry. :laugh: