SatyaLive α

In the name of CNN, comes the malware

Posted in Internet, Security, Technology by thelastpaladin on August 7, 2008

Mail in the name of CNNI trust my mail provider to filter all the spam, but I regularly check the spam folder to avoid false positives. Any way false negatives show up in Inbox.

Email scams are normal, I’ve learnt to live with it. This is a recent scam that I saw. The email says “CNN.com Daily Top 10″ which has a lot of links (all pointing to the same page). It’s very appealing with the recent news headlines or celebrity names in the links.

The links lead to a rogue site that asks you to install an activex control. Even if you press cancel, it asks you again and again and it’s almost a DoS attack on your browser. You gotta kill the browser or install the malware.

Rogue site asks permission to install ActiveX control I love Microsoft (and other browser guys) for this. What if the default setting is to automatically install ActiveX controls with out asking the user. How many of the users would change the default setting.

The minds behind this might be trying to create a bigger botnet. You definitely don’t want your computer to be a part of a world wide botnet that can pull down websites and cause a havoc on the Internet. Recently Georgia president’s website was subject to similar DDoS attack through a botnet.

Spam in the name of CNN Do not install any ActiveX with out properly knowing what it does.

Update: Another variant of the mail, which is more convincing mail with one link to cnn.com and one link to a different rogue site. Be careful when clicking links. Even your computer can be affected by this.

One Response

Subscribe to comments with RSS.

  1. Amy Roskilly said, on August 8, 2008 at 4:13 am

    Good to know. I’ve had tons of those emails and luckily haven’t opened any. Thanks!


Leave a Reply