Share

Aditya K Sood

Job title:
Founder , SecNiche Security

Areas of expertise:
Penetration testing, reverse engineering, security research

Biography:
Aditya K Sood is a Sr. Security Researcher at Vulnerability Research Labs (VRL), COSEINC. He has been working in the security filed for the past 7 years. He is also running an independent security research arena, SecNiche Security. He is an active speaker at security conferences and already has spoken at EuSecWest, Xcon, Troopers, Owasp, Xkungfoo, CERT-IN etc. He has written a number of whitepapers for Hakin9, Usenix, Elsevier and BCS. He has released a number of advisories to forefront companies. Besides his normal job routine he loves to do a lot of web based research and designing of cutting edge attack vectors.

Tag Cloud

Bloggers

Blog

Beware of MySpace JPG File Downloader - GTALK Messenger Infection

The malware infection attack surface is increasing day by day. Recently, some of the infected machines with different malware classes such as file downloader are using GTALK for downloading JPG based files from the internet.

Actually this file is not a JPG file but a zipped file that contains an executable or com file. The infection process has been noticed in victim machines which are facing system errors related to generic host process. This service host process is killed by an infection agent in the system. Very quickly, the infection starts rising. If a victim is using GTALK , he starts receiving rogue messages to download files from the internet. This is an alias to drive-by download technique used by attackers to load content into victim machines from different domains.

The snapshot is provided as

This is a caution not to visit this link or extract the files in your system. Protection is within your control. Apply it.

Posted 15/12/2009 by Aditya K Sood

Tagged under:Malware,Messenger

Comment on this blog

You must be registered and logged in to leave a comment about this blog.