NEWS FROM THE LAB - Thursday, July 7, 2005

Two Trojan-Downloaders seeded this morning Posted by Patrik @ 14:44 GMT

Two new Trojan-Downloaders were seeded early this morning. Both downloaders were sent in e-mails that looked like this:

Subject: Spam report

Your e-mail account was used to send a huge amount of unsolicited spam
messages during the recent week. If you could please take 5-10 minutes
out of your online experience and confirm the attached document so you
will not run into any future problems with the online service.

If you choose to ignore our request, you leave us no choice but to
cancel your membership.

Virtually yours,
Network Administrator Team

Attachment: report.log.exe

The difference between the two downloaders is that they download additional malicious components (keylogger and backdoor) from two different webservers. F-Secure detects the downloaders and the additional components with update [2005-07-07_03].