May 09, 2003

Update: CERT warns of Mother's Day threat

E-mail-borne threat could allow attacker to run malicious code

BOSTON -- The CERT Coordination Center is warning Internet users to beware of a new e-mail-borne threat that could allow an attacker to run malicious code on a victim's computer.

The new threat, known as "Peido-B," "VBS/Inor.B" or "Mother's Day Virus" arrives in an e-mail that masquerades as an administrative message.

The e-mail contains the text "THIS IS A WARNING MESSAGE ONLY YOU DO NOT NEED TO RESEND YOUR MESSAGE" and contains an executable attachment named "sys_con.hta," according to an alert posted by Sophos PLC.

When recipients launch the attachment, a trojan program known as "Troj/DLoader-BO" is installed on the user's system. Trojan programs are malicious software, often masked as legitimate programs, that secretly compromise computer security.

Troj/Dloader-BO downloads and executes a file from the Web site http://masteraz.hypermart.net within three days of being run for the first time and modifies the configuration of the Microsoft Windows operating system so that the program is started along with Windows, according to Sophos.

The warning from CERT appeared on the organization's Web page under the heading "Current Activity," which CERT said is reserved for "frequent, high-impact types of security incidents currently being reported to the (CERT Coordination Center)." CERT is based at the Software Engineering Institute at Carnegie Mellon University in Pittsburgh.

Despite that fact, Sophos, one of the few antivirus companies that did issue an alert for Peido-B, said that it had received only "a small handful" of reports of individuals who had been infected by it, said Carole Theriault, an antivirus consultant at Sophos in Abingdon, England.

The alert was issued in response to a number of calls from individuals and organizations on Wednesday, according to Brian King, Internet security analyst at CERT.

The Current Activity page is a "very informal" list of threats and is intended more for the use of the CERT community, King said.

"It's where we put information that may become advisories in the future. If we get a fair number of calls, we put it up there to help our staff... even if it's not that significant an Internet threat,"  he said.

CERT requires reports from multiple, dispersed sources before issuing any kind of notice or alert, King said.

While the timing of the Peido-B virus may loosely coincide with the celebration of Mother's Day in the U.S. on Sunday, neither the e-mail message nor the attachment that installs the trojan program seem tailored to the holiday, calling into question CERT's characterization of the new threat as a "Mother's Day Virus."

The mention of a Mother's Day virus came from individuals who called CERT Wednesday to report the new virus, according to King.

Those users reported hearing rumors of a Mother's Day virus that matched the description of the Peido-B e-mail, he said.

CERT encouraged users to install antivirus software and to update their virus information files, if necessary.

Companies should also consider other measures such as filtering files with an .hta extension and monitoring outgoing HTTP (Hypertext Transfer Protocol) for attempts to retrieve executable files, CERT said.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.