Skype worm spreads, using LOL trick to infect unwary users

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Sophos said:
Skype users are warned to be on their guard, regarding malicious instant messages that have been sent through the service, designed to infect Windows computers.

A malicious worm is taking advantage of the Skype API to spam out messages similar to the one below:

lol is this your new profile pic? http://goo.gl/[REDACTED]?img=[USERNAME]

Clicking on the suspicious links leads to the download of a ZIP files (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC.

The Trojan horse opens a backdoor, allowing a remote hacker to take control of infected PCs, communicating with a remote server via HTTP.

Read more: http://nakedsecurity.sophos.com/2012/10/08/skype-worm-spreads/
 

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
MalwareCenter said:
I can upload samples if you want.

As far as I've understand, the malware is a Ransomware and its delivered via a black exploit kit 2.0 right?
 

Malware1

Level 76
Sep 28, 2011
6,545
I don't know where you read that it's delivered via exploit. Last sample is delivered by Skype, this is shortened by goo.gl, the malicious file is hosted at hotfile.com.

http://goo.gl/QYV5H?img=Name

redirected to:

http://hotfile.com/dl/175082698/230fce5/skype_05102012_image.zip.html

but this file has been now deleted and these links aren't malicious.

After opening malicious files, file with uTorrent icon is dropped

EDIT: Samples: http://malwaretips.com/Thread-Win32-Dorkbot-Skype-Worm
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
Won't they have to add you for this to happen?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top