Author Topic: Fake, infected media file attacks half a million victims in a week  (Read 885 times)

FrankZappa

  • the Bohr to your Einstein
  • Administrator
  • Hero Member
  • *****
  • Posts: 7666
Given the band in question I don\'t see this being a problem, but a good reason to update your spyware software everyone!



In what\'s being called the largest fake media file outbreak in three years, some 500,000 people have fallen prey to a phony music or video track that is actually a spyware-infested Trojan horse.

Usually purporting to be a music track with an MP3 file extension (in this case, an MP3 track from the UK group Girls Aloud), the file is actually an installer that claims to require a special codec and a special media player to play back the file.

Install the codec and what you really get is a computer screen full of pop-ups delivered through a variety of malware programs. You can see what the infection process looks like by checking out the video on this post. The attack is being distributed primarily through peer-to-peer networks.

This is hardly an original attack, but the scale is immense: Those 500,000 attacks occurred in the space of just one week. That\'s substantial.

The bright spot is that according to McAfee, which provided the data in the BBC report, only about 10 percent of those who downloaded the infected file actually installed it.

The infected file incorporates all manner of potential file names. Though the BBC story includes a half-dozen, the real list of names is exhaustive to the point where it would make little sense including it here. It\'s likely that that list will continue to grow, too, as the attack continues to develop.

You already know what you need to do now, but I\'ll say it again: Update your antivirus software, make sure it\'s running real-time scans, and keep off those peer-to-peer networks.

linky  Mclinkinstine
"i heard that after he crossed the finish line he proceeded to wrestle down and pin a full sized grizzly bear"- ds673488

"if i listened to the distance on repeat, i\'d be wearing yellow jerseys like a motherfucker" - zuke

tyzack

  • Hero Member
  • *****
  • Posts: 2153
    • http://
Fake, infected media file attacks half a million victims in a week
« Reply #1 on: May 14, 2008, 10:16:46 am »
Quote from: FrankZappa;189646
Given the band in question I don\'t see this being a problem, but a good reason to update your spyware software everyone!



In what\'s being called the largest fake media file outbreak in three years, some 500,000 people have fallen prey to a phony music or video track that is actually a spyware-infested Trojan horse.

Usually purporting to be a music track with an MP3 file extension (in this case, an MP3 track from the UK group Girls Aloud), the file is actually an installer that claims to require a special codec and a special media player to play back the file.

Install the codec and what you really get is a computer screen full of pop-ups delivered through a variety of malware programs. You can see what the infection process looks like by checking out the video on this post. The attack is being distributed primarily through peer-to-peer networks.

This is hardly an original attack, but the scale is immense: Those 500,000 attacks occurred in the space of just one week. That\'s substantial.

The bright spot is that according to McAfee, which provided the data in the BBC report, only about 10 percent of those who downloaded the infected file actually installed it.

The infected file incorporates all manner of potential file names. Though the BBC story includes a half-dozen, the real list of names is exhaustive to the point where it would make little sense including it here. It\'s likely that that list will continue to grow, too, as the attack continues to develop.

You already know what you need to do now, but I\'ll say it again: Update your antivirus software, make sure it\'s running real-time scans, and keep off those peer-to-peer networks.

linky  Mclinkinstine


If you don\'t install the codec, what happens?
Apartheid: A policy of segregation and political and economic discrimination.

FrankZappa

  • the Bohr to your Einstein
  • Administrator
  • Hero Member
  • *****
  • Posts: 7666
Fake, infected media file attacks half a million victims in a week
« Reply #2 on: May 14, 2008, 12:47:23 pm »
probably nothing, but why bother downloading it just to find out?
"i heard that after he crossed the finish line he proceeded to wrestle down and pin a full sized grizzly bear"- ds673488

"if i listened to the distance on repeat, i\'d be wearing yellow jerseys like a motherfucker" - zuke

jocelyn

  • Not in charge.
  • Hero Member
  • *****
  • Posts: 6294
    • http://www.myspace.com/cowwcowboogie
Fake, infected media file attacks half a million victims in a week
« Reply #3 on: May 14, 2008, 01:01:32 pm »
Quote from: FrankZappa;189708
probably nothing, but why bother downloading it just to find out?


In the spirit of Adventure, duh.
Masturbation in the MFA

SlimPickens

  • just the tip
  • Hero Member
  • *****
  • Posts: 4138
    • http://
Fake, infected media file attacks half a million victims in a week
« Reply #4 on: May 14, 2008, 01:26:58 pm »
Quote from: FrankZappa;189708
probably nothing, but why bother downloading it just to find out?


It burns when you pee

tyzack

  • Hero Member
  • *****
  • Posts: 2153
    • http://
Fake, infected media file attacks half a million victims in a week
« Reply #5 on: May 14, 2008, 02:13:11 pm »
Quote from: FrankZappa;189708
probably nothing, but why bother downloading it just to find out?


No, I wanted to set up this statement:

Most viruses require some "stupid" action by the user to enable. This one requires two;
1.) Download the file
2.) Allow the file to download a codec that you don\'t know about.

Think about this, why would an mp3 need to download and install a 3rd party codec? The mp3 format is no longer anything new so you shouldn\'t to be downloading stuff to it. I could see if maybe they used an mp4 format, or shn or ogg or any lesser known type that people might need to download support for.

Given the amount of trouble (and stupid mistakes) that a user would have to go through in order to be infected, I don\'t think that this is that much of a threat.

The internet is like drugs; if you use it smartly, you won\'t get hurt.
However, if you are stupid about your use, then it can fuck you up royally.
Apartheid: A policy of segregation and political and economic discrimination.

Todd

  • Available to shoot porn
  • Hero Member
  • *****
  • Posts: 9291
    • http://TKAPhotos.com
Fake, infected media file attacks half a million victims in a week
« Reply #6 on: May 14, 2008, 02:58:28 pm »
People are stupid!! (for the most part)
Light travels faster than sound. That is why some people appear bright...until you hear them speak.

Jim Cobb

  • RailroadBuilder/RugPee-er
  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4077
    • http://www.urban-fetch.com
Fake, infected media file attacks half a million victims in a week
« Reply #7 on: May 14, 2008, 03:08:24 pm »
:that:
Postcount +1.