Original URL: http://www.channelregister.co.uk/2007/12/28/bhutto_murder_malware/
Virus writers are exploiting morbid curiosity about the assassination of former Pakistani Prime Minister Benazir Bhutto's to spread malware.
Surfers searching for video footage of the suicide attack that killed Bhutto and at least 21 others on Thursday are liable to find malware posing as video clips that attempts to trick users into running malign ActiveX controls. The malicious downloaded file is detected by Symantec as the Emcodec-Trojan.
Trend Micro reports that some of the sites that come up in Google search results using the simple search term "Benazir" feature an malicious JavaScript redirect. The malicious script downloads a Trojan which, in turn, downloads more malicious files. This malicious JavaScript is far from restricted to sites referring to Bhutto's assassination but is also "embedded in other Web sites with a broad scope of topics and interests," Trend Micro notes.
Searching for this same malicious JavaScript code URL (the malicious script) yields 4,240 results. Narrowing down the search to also include "benazir" reduces this number to 103 results.
Sites that have been possibly compromised (or that include the malicious JavaScript), including Autoworld, Vino, Dogpile, MSN and BlogSpot, Trend Micro warns. ®
International tradewinds fill Symantec's Q3 sails (24 January 2008)
http://www.channelregister.co.uk/2008/01/24/symantec_q3_2007_earnings/
Polyglot worm spreads over MSN (23 January 2008)
http://www.channelregister.co.uk/2008/01/23/polyglot_msn_worm/
VXers exploit Burma protest to punt Trojan (28 September 2007)
http://www.channelregister.co.uk/2007/09/28/burma_trojan/
Scumbag malware authors exploit Virginia Tech tragedy (19 April 2007)
http://www.channelregister.co.uk/2007/04/19/virginia_tech_malware_attack/
Nuclear war worm fails to explode (8 November 2006)
http://www.channelregister.co.uk/2006/11/08/nuclear_war_worm/
Slobodan Trojan poses as murder pics (15 March 2006)
http://www.channelregister.co.uk/2006/03/15/slobodan_trojan/
For ambulance-chasing bloggers, tragedy equals opportunity (8 July 2005)
http://www.theregister.co.uk/2005/07/08/blog_ambulance_chasers/
Trojan poses as Osama capture pics (3 June 2005)
http://www.channelregister.co.uk/2005/06/03/osama_trojan/
VXers hit new low with tsunami-themed worm (17 January 2005)
http://www.theregister.co.uk/2005/01/17/tsunami_worm/
© Copyright 2008