Trojan horse
Latest Trojan exploits 'window of exposure'

Trojan tests antivirus response time

Quick burst of two million emails to test the waters

Written by Iain Thomson

A Trojan writer has been testing the response times of antivirus companies with malware that has been spammed out to over two million web users.

Managed security provider BlackSpider Technologies estimated that more than 2.4 million emails containing the Win32.small.cfg Trojan downloader were sent to UK businesses last night.

The malware was sent out in emails claiming to be about an unpaid invoice for a firm in Nottingham.

The message reads: 'Dear client! We are unable to obtain the bill payment from your bank account. We recently received a report of e-banking use associated with this account. As a precaution, we have limited access to your account in order to protect against future unauthorized transactions. You can check your transaction details in attachment.'

The attachment purporting to contain the invoice deposits the Trojan on the machine when opened.

The Trojan was spammed out from 9pm on 26 January and was specifically designed to exploit the time between a virus being released and antivirus vendors issuing a patch. The virus stopped shortly after Symantec responded at 0:45am on 27 January.

"This Trojan was successful in achieving what appears to be its main purpose of reaching as many inboxes as possible before the antivirus industry could react," said James Kay, chief technical officer at BlackSpider Technologies.

"Last year we saw many attempts to infect PCs during this 'window of exposure' and that trend looks set to continue in 2006.

"Businesses that are not using proactive intelligent threat prevention technology to tackle new viruses are leaving themselves at serious risk from infection, as this outbreak shows."

Tags:

Further reading

Trojan masquerades as Microsoft patch

Beware updates bearing URLs   More...

Sick Trojan exploits London bombings

Promised eyewitness videos carry nasty payload   More...

Big danger from Small Trojan

Virus targets specific companies with malicious executable   More...

Related articles

Adware tops February malware chart

Kaspersky warns of Virtumonde Trojan downloaders   More...

Obfuscated malware tops list in August

Threats include runtime packing, polymorphism and junk code injection   More...

Criminal hackers turn on Mac users

Windows malware not the only game in town   More...

Angelina Jolie 'nudes' fuel malware spike

Oldest trick in the spammers' book   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement