Extremely aggressive worm chokes instant messaging
May 2010
IT in Manufacturing
New variant of Palevo blasts unprotected systems via fake photo gallery links.
The latest offspring of the Palevo family has begun spreading these days via a massive wave of automatically generated IM spam. The unsolicited message incites the recipients to click a link accompanied by a grinning smiley face, which purportedly leads them to an image or photo gallery.
Figure 1. The unsolicited IM spam that brings Palevo
Instead of opening the alleged image collection, the users are tricked into saving what seems to be a .JPG file, which is, in effect, an executable concealing the malicious payload – Worm.P2P.Palevo.DP.
Figure 2. The apparent .JPG is an .EXE file delivering the worm
Having an unprotected system infected with Palevo.DP is a synonym for mayhem. First and foremost, the worm creates several hidden files in the Windows folder: mds.sys, mdt.sys, winbrd.jpg, infocard.exe and modifies some registry keys to point towards these files in order annihilate the OS' firewall.
As its siblings, Palevo.DP holds a backdoor component, which allows remote attackers to seize control over the compromised computer and do whatever they want with it – from installing additional malware and swiping files to launching spam campaigns and malware offensive on other systems.
Palevo family is also able to intercept passwords and other sensitive data entered in Mozilla Firefox and Microsoft Internet Explorer Web browsers, which makes it extremely risky to users relying on e-banking or on-line shopping services.
The spreading mechanism also comprises the infection of network shares and removable USB storage devices, where it creates autorun.inf files pointing to its copy. When the removable disk or memory stick is inserted into machines with the Autorun feature enabled or unprotected by a security solution with on-access scanning capability, the system is automatically infected.
Palevo worms also affect users of the P2P sharing platforms, such as Ares, BearShare, iMesh, Shareza, Kazaa, DC++, eMule and LimeWire, by adding their code to the shared files.
“We recommend users to be extremely cautious and not to click any suspicious links they receive via IM clients before checking with their senders the validity of the Web sites towards which these links point. This Palevo offensive is highly aggressive and during the very beginning of the outbreak we have witnessed rates of infection which easily exceeded 500% growth per hour for countries like Romania, Mongolia or Indonesia”, said Catalin Cosoi, BitDefender senior researcher.
For additional information about e-threats and tools for defending your data and systems check www.malwarecity.com
For more information contact Alina Anton, senior PR & marketing coordinator, EMEA & APAC Business Unit, BitDefender, +40 212 063 470, [email protected], www.bitdefender.com
Further reading:
Why choose between Capex and Opex if you can Totex?
Schneider Electric South Africa
IT in Manufacturing
In a sector marked by cyclical demand, high capital intensity, and increasing regulatory and sustainability pressures, mining, minerals and metals (MMM) companies are re-evaluating how they approach procurement and investment.
Read more...
AI and the smart factory
Schneider Electric South Africa
IT in Manufacturing
Imagine walking into a factory where machines can think ahead, predict problems before they happen and automatically make adjustments to realise peak performance. This isn’t science fiction, it’s happening right now as AI continues to transform how we run industrial operations.
Read more...
Why your supply chain should be a competitive advantage
Schneider Electric South Africa
IT in Manufacturing
The last five years have placed unprecedented strain on global supply chains. Leading companies are turning the challenge into an opportunity to transform their supply chains into a competitive advantage.
Read more...
Why AI will never truly understand machines
Wearcheck
IT in Manufacturing
Cutting-edge technology and solutions powered by AI are embraced by specialist condition monitoring company, WearCheck, where the extreme accuracy of data used to assess and diagnose machine health is paramount.
Read more...
Buildings and microgrids for a greener future
Schneider Electric South Africa
IT in Manufacturing
Buildings are no longer passive consumers of power. Structures of almost every size are evolving into dynamic energy ecosystems capable of generating, storing and distributing their own electricity. Forming part of this exciting transformation are microgrids.
Read more...
Traditional data centres are not fit for purpose
IT in Manufacturing
Traditional data centre designs are falling short, with nearly half of IT leaders admitting their current infrastructure does not support energy or carbon-reduction goals. New research commissioned by Lenovo reveals that data centre design must evolve to future-proof businesses.
Read more...
AI agents for digital environment management in SA
IT in Manufacturing
The conversation about artificial intelligence in South Africa has shifted rapidly over the past year. Among the technologies changing the pace of business are AI agents - autonomous, task-driven systems designed to operate with limited human input.
Read more...
AI-powered maintenance in future-ready data centres
Schneider Electric South Africa
IT in Manufacturing
The data centre marketplace often still relies on outdated maintenance methods to manage mission-critical equipment. Condition-Based Maintenance (CBM) is powered by AI and is fast becoming a necessity in ensuring both competitiveness and resilience.
Read more...
Powering up data centre mega development
IT in Manufacturing
Parker Hannifin has secured a major contract to supply key equipment for nearly 30 aeroderivative gas turbines powering a new hyperscale data centre in Texas.
Read more...
Building resilient supply chains through smarter e-procurement
RS South Africa
IT in Manufacturing
In a time of constant disruption, from supply chain uncertainty to rising operational costs, businesses that embrace digital procurement are better positioned to stay competitive and resilient.
Read more...