NIBU.D TROJAN: “Osama Bin Laden Captured” email
Please note this message containing a hostile URL has been spammed extensively on the Internet. I personally got a number of these and the hostile URL noted could load a trojan or process an exploit. Please delete these messages and do not visit the web site noted in the actual message.
NIBU.D TROJAN: “Osama Bin Laden Captured” email
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nibu.d.html
Osama Bin Laden Captured -- An email is circulating on the internet today that claims to be from CNN or BBC. The email utilizes this exploit to download a file pics.chm that in turn contains and executes a Trojan. McAfee has identified this as Exploit-MhtRedir.gen and Norton identifies it as Backdoor.Nibu.D. The Trojan once executed attempts to steal passwords and bank account information.
An example I found in my in-box this morning:
Subject: Osama Bin Laden Captured.
Date: Fri, 23 Apr 2004 19:49:29 +0500
Just got this from CNN Osama Bin Laden has just been captured! A video and some pictures have been released. Goto the link below for pictures, I will update the page with the video as soon as I can:
http://<hostile web site URL>/pics/
God Bless America!