ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

New Trojan appears to attack VeriSign

Andrew Colley ZDNet Australia

Published: 02 Oct 2003 14:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sophos' antivirus team has confirmed that it is in the preliminary stages of analysing a new Trojan that may be linked to an organised attack on VeriSign's domain name servers. Paul Ducklin, head of technology, Sophos Asia-Pacific, said the Trojan, dubbed Qhost1, seduces the user into going to a Web site that exploits a security vulnerability in Internet Explorer and inserts malicious code onto the victim's personal computer.

Sophos's revelation coincides with unconfirmed reports from a source within the technical ranks of one Australia's major ISPs of a spike in support calls from customers whose DNS server settings had been tampered with, in what appears to be an orchestrated attack on Internet security giant VeriSign.

"It's changing the IP address of the DNS servers from ours [domain name] across to VeriSign's to launch a DoS attack on them," said the source.

The source told ZDNet Australia that the activity appeared to be promoted by a virus or Trojan-like entity targeting Windows 2000 and Windows XP systems.

Ducklin said was unable to confirm that the new Trojan was implicated in the activity described by the source but confirmed it appeared that Qhost1 was designed to alter the DNS setting of its victim PCs.

"This particular Trojan messes up your DNS so in theory it could be targeted against anyone," said Ducklin

"What I can say is that in the light of what [ZDNet Australia] has told us, it has made us interested in looking at this particular sample so that we can match it up if further samples come in and, if appropriate, there will be further notifications on our Web site," he said.

Sophos expected to have a new definition file posted to its Web site within the hour.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
77 out of 176 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment