Register | Forgot password?
Switch to Arabic
Monday, November 9 - 2009

Fake email zip download from known contact infects user PCs

  • United Arab Emirates: Tuesday, August 19 - 2008 at 11:23
  • PRESS RELEASE

IronPort Systems, a Cisco business unit and a leading provider of enterprise spam, virus, and spyware protection, has announced that its Virus Outbreak Filters (VOFs) were able to detect and block a new "Pandex"-variant Trojan Horse program 15 hours and 30 minutes before major anti-virus vendors.

Article continues below
  • Graphic demonstrating the Virus outbreak timeline.
    Graphic demonstrating the Virus outbreak timeline.
Caught by the VOFs at exactly 11:18 pm on June 28, 2008, the Pandex variant was spread via emails which seemed to come from someone the recipient had previously communicated with.

The emails came with the subject "Hot Pictures" or "Hot News" and contained an attachment titled "censored.zip."

Once launched, the zip file installed a Trojan that collected email addresses and allowed remote hackers to manipulate the infected computer.

The first anti-virus signature for the attack from a major anti-virus (AV) vendor was released at 2:49 pm the following day, June 29, 2008, more than 15 hours after IronPort was able to capture and resolve the new threat.

"Our VOFs were able to identify and control the Pandex variant attack within minutes of its release onto the internet; such efficiency and speed prove that our VOF is by far the most effective tool against today's quickly spreading, dangerous trojan and virus threats. This also showed the inadequacy of totally relying on traditional tools for detecting and handling malicious web-based programs,"


said Ray Kafity, Regional Sales Manager - Middle East, North Africa and Pakistan, IronPort Systems.

From June 28th to June 30th, cyber criminals sent out emails with the Pandex Trojan, also known as Pushdo and Cutwail.

Users fooled into opening the embedded attachment triggered the illegal harvesting of email addresses from Microsoft Outlook, email backup, mail address book, appointment database, and text files, and web and active server pages.

Hackers took over the compromised computers to send spam and host spyware or install key loggers and screen scrapers to steal personal, confidential financial information without the user's knowledge.
Also consider reading:
Log in to request more information from IronPort Systems

Notes and media contacts

Contact:

DNA Communications
P.O. Box 191117
Dubai, UAE
Tel.: 04 3988490
Fax: 04 3988491

Disclaimer:

Articles in this section are primarily provided directly by the companies appearing or PR agencies which are solely responsible for the content. The companies concerned may use the above content on their respective web sites provided they link back to http://www.ameinfo.com

Any opinions, advice, statements, offers or other information expressed in this section of the AMEinfo.com Web site are those of the authors and do not necessarily reflect the views of AME Info FZ LLC / Emap Limited. AME Info FZ LLC / Emap Limited is not responsible or liable for the content, accuracy or reliability of any material, advice, opinion or statement in this section of the AMEinfo.com Web site.

For details about submitting your stories, please read the guide - all content published is subject to our terms and conditions