Quick Links: SpywareGuide Greynets Blog | SpywareGuide Product Database | SpywareGuide Company Database | SpywareGuide Categories
SpywareGuide powered by FaceTime Security Labs
Search SpywareGuide Greynets Database & Site
Security Email Alerts & Updates
Search the Blog
 
Recent Posts
Categories
Monthly Blog Archives
Links
Subscribe
Subscribe to this blog's feed
About the Blog
About SpywareGuide Greynets Blog
Link to Us
Link to SpywareGuide.com

« New MSN Virus In The Wild | Main | Skype Spammers Promoting Rogue Antispyware Tool »

  • New Skype Worm On The Loose

As mentioned on the Official Skype Blog, there is indeed a new worm in the wild - someone, somewhere came up with w32/Ramex.A as a name but I thought "Bubbles" was more appropriate, as you'll see.

Everything starts with a user downloading this file:

http://blog.spywareguide.com/upload/2007/09/skyper1-thumb.jpg
Click to Enlarge

Presented as an imagefile in the infection message, it's actually an .scr file - and no, that's not good.

skyper2.jpg


This file has been compressed to perfection:

http://blog.spywareguide.com/upload/2007/09/skyper6-thumb.jpg
Click to Enlarge

....yep, that's 2k infection file. Yet there's a whole lot of trouble in such a small package:

http://blog.spywareguide.com/upload/2007/09/skyper5-thumb.jpg
Click to Enlarge

...as you can see, the Worm tries to fool you into thinking someone really is on the other end by sending you what looks like fragments of a continuing conversation, finishing with a supposedly accidental sending of an image you're "not supposed to see".

Got to love that social engineering.

Here's a sample of some of the infection messages sent by the worm:

http://blog.spywareguide.com/upload/2007/09/skyper3-thumb.jpg
Click to Enlarge


But why did we call it "bubbles"? Easy, this is what you see when you attempt to open the .scr for the first time:

http://blog.spywareguide.com/upload/2007/09/skyper4-thumb.jpg
Click to Enlarge

Apparently, not everyone sees the bubbles when they run this file. I bet they really feel like they're missing out...

Research Summary Write-Up: Chris Boyd, Director of Malware Research
Technical Research: Chris Mannon, FSL Senior Threat Researcher

  • TrackBack

TrackBack URL for this entry:
http://blog.spywareguide.com/mt/mt-tb.cgi/212


  • Comments

Can this work affect Macs as well, or just windows based machines.


Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)


Site EULA | Site Map | Contact Us | About Us | Site and Spyware FAQ | Advertise | RSS Feeds  | Link To Us | SpywareGuide JapanJapanese

© Copyright 2006, FaceTime Communications, Inc. All rights reserved.