'Vandalism complaint' new WMF trojan

Share this article:

A new trojan, which claims to be from a Yale University professor disturbed by New Year’s vandalism, is exploiting the recently exposed Microsoft Windows metafile vulnerability.

The fraudulent email, purportedly from "Professor Robert Gordens" at Yale, claims to link to a Comcast cable company website containing photos of the vandalism.

F-Secure warned administrators to block access to the malicious website, http://playtimepiano.home.comcast.net/, at gateways.

"When curious readers follow the link to a web server under comcast.net, they are hit with a WMF file that immediately downloads a botnet client via tftp and runs it," the security firm said. "In case the WMF exploit wouldn't work, the front page of the site also contains an exploit against older versions of Firefox."

F-Secure's site informed users on Wednesday that the firm is using the unofficial patch from Ilfak Guilfanov, which can be downloaded at http://www.hexblog.com, on its PCs.

"We've tested it and audited it and can recommend it," the firm said.

The website also advised users to maintain antivirus services and apply the work-around Microsoft has recommended.

Malicious users have set up attack websites to exploit the image vulnerability, from which they can execute arbitrary code, cause a denial of service condition or take complete control of an infected PC, the U.S. Computer Emergency Readiness Team and multiple security firms warned late last month.

The Redmond, Wash., computer giant said this week that a fix for the WMF vulnerability would be included as part of its monthly "patch Tuesday" bulletin, due out next Tuesday.

Microsoft said on Tuesday that it does not believe the scope of attacks on the flaw - which can result in PC shutdown - are widespread, adding that "customers who follow safe browsing best practices are not likely to be compromised by any exploitation of the WMF vulnerability."

Share this article:
You must be a registered member of SC Magazine to post a comment.

Next Article in News

Sign up to our newsletters

More in News

Beazley: employee errors root of most data breaches, but malware incidents cost ...

Insurance firm Beazley analyzed more than 1,500 data breaches it serviced between 2013 and 2014.

Apple issues seven updates, fixes more than 40 vulnerabilities in iOS 8, OS 10.9.5

Apple issues seven updates, fixes more than 40 ...

In one of its infrequent "Update Surprisedays," Apple plugged holes, boosted security and added features.

Canadian telecom co. Telus unveils first transparency report

The company received more than 100,000 government requests for customer data last year.