|
||
5/2: Oscarbot Virus Spreads a Hyperlink Several variants/repackaged versions of W32/Oscarbot have been discovered in the last few days, according to McAfee. Additionally, similar Sdbot variants have been discovered recently that also use this AIM vector.
This threat "spreads" via a hyperlink that is received via AOL Instant Messenger. Recipients may receive a message such as:
Following the hyperlink results in users be prompted to save/run an executable file (such as pictures@gallery.com). If users choose to download and/or run this file, Oscarbot will contact a remote IRC server, logon to a specified channel and wait for further instructions. One of these instructions can result in the bot program sending the aforementioned hyperlink to all recipients on the infected users buddy list.
Technically not a worm, this threat requires a bot commander to initiate the "spimming" (IM spam) routine.
More information can be found at McAfee page.
|
||
|