Tuesday, December 26, 2006

A Strange ICQ Message

Today, I received a very strange ICQ message from one of my friend:
Hi, you've just received a postcard.

To view the postcard click this link or copy it to your browser's address bar.
http://cards.vertionpilinhertunfendsa.com/1/show.xml?id=201e624becfd36e0b7663089da805de0

The postcard will be kept for 10 weeks.
The link in the message points to an executable file named "postcard_flash.exe". Why does a postcard need to be executable? It most likely is a virus or a worm. From the Internet, I found some information about this kind of virus:
http://www.sophos.com/security/analyses/w32mydoomal.html
A very "clever" worm which spreads via email and ICQ messages. The worm tries to disable the firewall, as well as anti-virus program. Moreover, the worm changes the HOST file to prevent the compromised computer connecting to anti-virus and security web sites.... So what! I am using Linux.

No comments: