Advertisement
Promo

Security threats Toolkit

Trojan variant plagues Skype

David Meyer ZDNet.co.uk

Published: 23 Mar 2007 16:08 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of a well-known Trojan horse virus is spreading through Skype's instant-messaging network, a security company has warned.

According to Websense Security Labs, a new set of the Warezov/Stration malicious code is currently making its way through Skype. The worm does not appear to be self-propagating, spreading instead through a URL sent to Skype users. When users activate it, it then passes the URL to all their Skype contacts.

"Skype users receive a message that says 'Check up this', with a URL containing a hyperlink. When users click on the link, they are redirected to a site that is hosting a file named file_01.exe," a statement from Websense read, which also noted that the vulnerability was not within Skype itself.

If file_01.exe is run, other files are downloaded and run, which can open a backdoor to the user's system and download further code. It also seems that the worm makes an abortive attempt to "notify the attacker that a certain machine has been infected", by trying to connect to an inactive Yahoo mail server to send an SMTP message.

The first variant of Warezov/Stration was reported in September last year by Symantec. F-Secure first reported its spread into Skype at the end of February.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
20 out of 20 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters