Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

The Worm in CNN's Headlines: Trojan keylogger awaits news junkies
January 21, 2005 | InternetNews

Posted on 01/21/2005 10:50:14 PM PST by Inkagnitow

Getting headline news sent via e-mail is a common activity that a new worm in the wild is hoping to take advantage of. Security firm Sophos this week reported the discovery of a worm that takes headlines from the CNN Web site and attempts to install a Trojan on the recipient's PC.

Sophos has called the worm Crowt-A(W32/Crowt-A). In addition to taking the subject from the CNN news site, it also takes message text, which further helps create the facade of legitimacy. As with many worms, the malicious code is contained in an attachment that is used to deploy its payload.

In the case of Crowt-A that payload is a Trojan keylogger that logs and then sends the user's keystrokes to a remote address. The Trojan also provides a backdoor allowing an attacker remote access to the infected machine.

The worm propagates by its own e-mail engine to addresses found in the Windows address book or even the Windows internet cache folder. The forged headers that the worm creates, however, make it appear as though the e-mail was sent via Microsoft Outlook Express.

"Virus writers are always looking for new tricks to entice innocent computer users into running their malicious code; this latest ploy feeds on people's desire for the latest news," said Carole Theriault, security consultant at Sophos, in a statement. "Many people subscribe to legitimate e-mail news updates, but the message is simple -- businesses need to make sure their anti-virus detection is constantly updated, and users need to be suspicious of all unsolicited e-mail whether it's promising celebrity pictures or news updates."


TOPICS: Miscellaneous
KEYWORDS: cnn; computersecurity; keylogger; lowqualitycrap; malware; microsoft; news; virus; windows

1 posted on 01/21/2005 10:50:14 PM PST by Inkagnitow
[ Post Reply | Private Reply | View Replies]

To: Inkagnitow

They should have named the trojan W32/AaronBrown.A


2 posted on 01/21/2005 10:52:31 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Inkagnitow

Just renewed my Norton 2005 antivirus. Not that I'd go on CNN website anyway.


3 posted on 01/21/2005 10:55:23 PM PST by 12 Gauge Mossberg (I Approved This Posting - Paid For By Mossberg, Inc.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BigSkyFreeper

4 posted on 01/21/2005 11:07:41 PM PST by Inkagnitow
[ Post Reply | Private Reply | To 2 | View Replies]

To: Inkagnitow

Thanks for the info..I have to disable Norton to even get to CNN..I over modified and ad to block it...( No computer genius here..LOL)


5 posted on 01/22/2005 12:54:07 AM PST by MEG33 (GOD BLESS OUR ARMED FORCES)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce; backhoe; Ernest_at_the_Beach

tech ping


6 posted on 01/22/2005 9:02:56 AM PST by JoJo Gunn (More than two lawyers in any Country constitutes a terrorist organization. ©)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Inkagnitow; admin

Here's the link:

http://www.internetnews.com/security/article.php/3462851


7 posted on 01/22/2005 9:09:29 AM PST by JoJo Gunn (More than two lawyers in any Country constitutes a terrorist organization. ©)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoJo Gunn
Thanks for that link.........looking at this:

*********************************************

Feeling the Need for RSS Feeds

Feeling the Need for RSS Feeds
Experts say Really Simple Syndication (RSS) will provide respite from the spam nightmare, offering new ways to publish and access content online. Can this format change the rules?

8 posted on 01/22/2005 11:23:56 AM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson