Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

MJ’s New Song Leaked Triggers Spam Attacks

Joji Hamada
October 13th, 2009
Tags: Endpoint Protection (AntiVirus), Security, Security Response
Facebook Twitter

Michael Jackson's new song "This Is It" premiered on MichaelJackson.com at midnight on October 12 where fans can listen to it for free. But apparently a 45-second preview of the song leaked onto YouTube the day before.

The spam below has been making rounds to trick folks into accessing the link included in the email to listen to the preview (obviously its not a real email from CNN nor is the ad a real ad from GAP!).

mj.PNG
 
Once the user clicks on the link, the browser opens a page on a site that's believed to be compromised and refreshes to the another site, which appears to be hacked as well, to execute a .hta file that is detected as Downloader.Psyme.

Once the .hta file is executed, a file called AutoCfg.exe (detected as Backdoor.Trojan by Symantec) and legitimate files Servmess.dll, Autoexnt.exe, and Instexnt.exe are downloaded. These legitimate files are normally used for administrator purposes, but in this case the malware uses them to run after every reboot even if there is no one logged on the computer. At this point, the computer can be remotely controlled and all the information on it is in the hands of the criminals.

A big thanks to the Symantec E-mail Security Group for providing the information.

0 votes
  • Joji Hamada's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com