MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

NIBU.D TROJAN: “Osama Bin Laden Captured” email

Please note this message containing a hostile URL has been spammed extensively on the Internet.  I personally got a number of these and the hostile URL noted could load a trojan or process an exploit.  Please delete these messages and do not visit the web site noted in the actual message.

NIBU.D TROJAN: “Osama Bin Laden Captured” email
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.nibu.d.html

Osama Bin Laden Captured -- An email is circulating on the internet today that claims to be from CNN or BBC. The email utilizes this exploit to download a file pics.chm that in turn contains and executes a Trojan. McAfee has identified this as Exploit-MhtRedir.gen and Norton identifies it as Backdoor.Nibu.D. The Trojan once executed attempts to steal passwords and bank account information.

An example I found in my in-box this morning:

Subject: Osama Bin Laden Captured. 
Date: Fri, 23 Apr 2004 19:49:29 +0500 

Just got this from CNN Osama Bin Laden has just been captured! A video and some pictures have been released. Goto the link below for pictures, I will update the page with the video as soon as I can:

http://<hostile web site URL>/pics/

God Bless America!

Only published comments... Apr 24 2004, 09:04 AM by Harry Waldron

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems