PDA

Click to See Complete Forum and Search --> : Heads Up**W32.Gruel@mm


Und3ertak3r
July 15th, 2003, 02:04 PM
Hi Guy's,

This one is a classic example of the use of Social enginering..
And catch the size of this sucker..

Details from Symantec (http://securityresponse.symantec.com/avcenter/venc/data/w32.gruel@mm.html)

Wild: Low
Damage: High
Distribution: High

This means this sucker when executed can fu><or your Windbloze 9x/xp box

W32.Gruel@mm is a worm that spreads by email and file-sharing networks. Its payload includes changing user passwords, hiding drive C, and making numerous changes to the system registry.

The email has the following characteristics:
Subject: Microsoft Windows Critical Update.
Attachment: Windows Critical Update 088562.exe




Type: Worm
Infection Length: 102,400 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Windows 3.x, Microsoft IIS, Macintosh, OS/2, UNIX, Linux


Catch the social enginering
Attempts to mail itself to all the addresses in the Microsoft Outlook Address book.
The email is formatted as follows:

Subject: Microsoft Windows Critical Update.

Message body:
Critical Update: The Microsoft Windows updates found on this patch include fixes to following Windows operating systems: Any update that is critical to the operation of your computer is considered a Critical Update, and is automatically selected for installation during the scan for available updates. This patch is provided to help resolve known issues, and to protect your computer from known security vulnerabilities and all kinds of viruses. Whether a patch applies to your operating system, software programs, or hardware, it is listed in the Critical Updates category, like this patch attached. For Support please contact us at support@microsoft.com.

Attachment: Windows Critical Update 088562.exe



Cheers

manicchester
July 15th, 2003, 07:14 PM
Thanks a lot for the info there Und3ertak3r, I'll have to be sure to get that critical update...You think this one has the potential to spread around quickly? Just curious of course...Thanks again.

Und3ertak3r
July 16th, 2003, 04:03 PM
I'll have to be sure to get that critical update...You think this one has the potential to spread around quickly?

bewarned:
1/ Microsoft DON'T Email Updates...
2/ Never execute/open any attachments on email's that claim to be updates for microsoft products.
3/ only download new M$ updates from microsoft..(check if they are applicable Before doing so)
4/ number one is always true..

The spread on this one will only be great once the momentum is gathered by ppl executing the attachment.. and if the virii writer (god forbid) improves the code..

..

I wasn't sure of the seriousness of your reply..


Cheers

manicchester
July 16th, 2003, 04:49 PM
Hey, thanks for the info....yeah, I was aware that Microsoft never sends anything for updates through email...I've actually had few problems with viruses only because I don't open anything that doesn't look familiar...plus having Norton 2003 scanning all my incoming mail helps too. Thanks again for letting me know of it though.

Und3ertak3r
July 18th, 2003, 03:42 PM
Note another thread on the same virus in the Microsoft Security Threads (http://www.antionline.com/showthread.php?s=&postid=644561&t=556#post644561)


Cheers