Home > Insights > Blogs 

CA Community

This Blog

Syndication

Calendar

<January 2009>
SunMonTueWedThuFriSat
28293031123
45678910
11121314151617
18192021222324
25262728293031
1234567

Another Mass-Mailing Worm and a Scam MS09-067 Fix!

Published: January 08 2009, 01:01 AM
by Methusela Cebrian Ferrer

Win32/Fruspam.A is a mass-mailing worm that harvests email addresses from the affected machine and uses them to communicate to remote SMTP servers for its spamming purposes.

This worm constructs spam messages like the one below by requesting images from legitimate sites – in this case, www.ikea.com.

-Example spam email sent by Win32/Fruspam.A

Aside from this typical email worm behavior, Fruspam also targets systems running servers with IIS (Internet Information Services). The worm attempts to modify or replace the legitimate file at %Root%\inetpub\wwwroot\index.htm with its own file.

The following ‘security warning’ displays the next time a website main page is accessed:

Example 'security warning' which, if clicked, executes a copy of the worm

Unfortunately, clicking on the "MS09-067" hyperlink could execute a file named “MS09-067.exe”, which is a copy of the worm.

Be aware of this trick and take the necessary security precautions to protect your system and network. Following these recommendations would be a good place to start:

  • Make sure your security scanner runs with the latest signature.
  • Avoid clicking dubious links and executing suspicious attachments. It is best to seek expert advice!
  • For networks running SMTP, make sure the SMTP relay is properly configured to prevent spammers from using your exchange server.
  • Enforce security permissions on IIS-sensitive content to prevent unwanted modification. 
A detailed description of Win32/Fruspam.A is also available in our Virus Encyclopedia:
http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77083 
Share this post: Email it! | bookmark it! | digg it! | reddit!

By: Methusela Cebrian Ferrer
Methusela Cebrian Ferrer is a Senior Research Engineer with the CA Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, she spent 5 years on the antivirus service team and R&D group for Trend Micro Internet Security Labs. She also worked with antivirus and anti...
Read More..

1 person has left a comment:

 
 
Page Tools