Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

NIBU.D TROJAN: “Osama Bin Laden Captured” email

Please note this message containing a hostile URL has been spammed extensively on the Internet.  I personally got a number of these and the hostile URL noted could load a trojan or process an exploit.  Please delete these messages and do not visit the web site noted in the actual message.

NIBU.D TROJAN: “Osama Bin Laden Captured” email
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nibu.d.html

Osama Bin Laden Captured -- An email is circulating on the internet today that claims to be from CNN or BBC. The email utilizes this exploit to download a file pics.chm that in turn contains and executes a Trojan. McAfee has identified this as Exploit-MhtRedir.gen and Norton identifies it as Backdoor.Nibu.D. The Trojan once executed attempts to steal passwords and bank account information.

An example I found in my in-box this morning:

Subject: Osama Bin Laden Captured. 
Date: Fri, 23 Apr 2004 19:49:29 +0500 

Just got this from CNN Osama Bin Laden has just been captured! A video and some pictures have been released. Goto the link below for pictures, I will update the page with the video as soon as I can:

http://<hostile web site URL>/pics/

God Bless America!