Security-X

Forum Security-X => News => Discussion démarrée par: chantal11 le avril 09, 2011, 09:57:57

Titre: Program:Win32/Pameseg.P - Give me your credit!
Posté par: chantal11 le avril 09, 2011, 09:57:57
Bonjour,

Citer
We recently examined a sample, detected as Program:Win32/Pameseg.P (SHA1: 089e7ec8ee2ca4be0fff079e39ef26110a8de78e), that appears to be a new version of "LoviVkontakte", an application for the Russian social networking website "vkontakte". This sample asks for money by way of requesting an SMS to a premium number to continue installation. We've seen similar behavior in the past with the malware families Wintrim and Ransom.

With this sample, it became apparent that things were not as they seemed. The file name for the installer was "lovi-v-kontakte-v260.exe", while the current version of the legitimate program is 2.41.
Lire la suite sur Microsoft Malware Protection Center (http://blogs.technet.com/b/mmpc/archive/2011/04/07/give-me-your-credit.aspx)

@+