Malware Outbreak During New Year – Dref-V and Trojan downloader Tibs-jy

The New Acunetix V12 Engine


Social Engineering again, someone praying on xmas spirit and good will to spread their filthy malware.

It quite often happens during festive times, someone hatches a new worm and sends it out packaged as a jolly xmas card or game.

A significant worm outbreak over the new year festivities has put paid to the notion we’ve seen the end of mass mailing worms just yet.

The Luder email worm (AKA Dref-V and Trojan downloader Tibs-jy, first seen on 30 December, poses as an electronic postcard and clogged up email in-boxes over the last two days after successfully duping the gullible into opening executable email attachments with names such as postcard and Greeting Card.exe. Subject lines such “Happy New Year!”, “Fun Filled New Year!” and “Happy 2007!” have been enough to convince the unwary that the messages were electronic greetings celebrating the new year rather than malware.

This time it’s about new year, but same old story packaged as a greeting card with rotated subject lines and various executable names.

Same concept as usual.

It’s far from the first instance of malware authors attempting to exploit seasonally dulled senses in a bid to spread malware. Two years ago a worm called Wumark-D spread across the net, net security firm Sophos notes. The attachment of infected emails launched a graphic image of nude men and women contorting to form the words “HAPPY NEW YEAR” whilst silently downloading malicious code onto compromised machines, which became agents in spreading the infection.

Once again a message for people to be vigilant, especially when receiving executables from anyone (even someone you know) unless you are expecting it.

Just drop a note back and ask did they mean to send it to you.

Source: The Register

Posted in: Malware

, , , , , ,


Latest Posts:


BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.


Comments are closed.