Xombe Trojan poses as Microsoft warning

By Munir Kotadia
13 January 2004 09:30 AM
Tags: xombe, windows, trojan, xp, munir, kotadia, windows xp, execute
An e-mail disguised as a message from Microsoft's security team contains a dangerous Trojan horse called Xombe.

Xombe, also known as Trojan.Xombe, Downloader-GJ and Troj/Dloader-L, was being distributed on Friday. It poses as a critical update for the Windows XP operating system. When executed, it attempts to download a malicious backdoor component from the Web.

It appears to be an imitation of one of last year's most successful worms, the mass-mailed Swen, which also masqueraded as a security warning from Microsoft.

However, Xombe has yet to repeat the success of Swen. While the former failed to make the top 10 threats intercepted by e-mail security company MessageLabs on Monday morning, Swen was at No. 2, with some 7,000 instances captured in the past 24 hours.

Ken Dunham, malicious code intelligence manager at security company iDefense, said that the success of Swen has encouraged virus writers to create e-mails and Web sites that appear official in order to fool more people into executing malicious code.

The e-mail, which appears to have been sent from windowsupdate@microsoft.com, has the subject line "Windows XP Service Pack 1 (Express) - Critical Update" and directs users to execute the attachment, called winxp_sp1.exe, in order to fix some vulnerabilities in Microsoft's Internet Explorer, Outlook and Outlook Express.

Dunham said that once executed, the attachment downloads a file called msvchost.exe that alters the Windows Registry and opens certain ports in order to listen out for commands from a hacker.

Most antivirus companies have already updated their signatures, but users without up-to-date antivirus applications could be infected, helping the Trojan's author to take control of large numbers of PCs. Dunham said that once a "large army of zombie computers" has been built up, attackers could use them for serious crimes such as ID theft and banking fraud.

Microsoft was not immediately available to comment.

Although Xombe is only likely to be opened by Windows XP users, it affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT and Windows Server 2003 systems, as well as Windows XP, according to security company Symantec.

Advertisement

Talkback 1 comments

    Amazing people would fall for ...Anonymous -- 13/01/04

    Amazing people would fall for this considering company updates are never (ever?) sent by email ...

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Phil Dobbie A guide to the future of the internet
    Last week we looked at the history of the internet in Australia. It's been around for 20 years and changed our lives in so many ways. Imagine what it could do given another 20 years.
  • Array Carelessness busts Linux security
    No operating system can ever properly protect a computer from trojans as long as users continue to do silly things. Just because Linux is immune to your standard drive-by viruses it does not mean that it can escape trojan horses.
  • Array Sun shining on Ajnaware
    Graham Dawson talks about the future of iPhone app development and augmented reality.
  • More blogs »

Tags

Back to top

Featured