vbSEO - vBulletin Optimization
 

Go Back   Chargeback Forum > Industry Talk > Fraud News & Events

Notices

Fraud News & Events Fraud related news, updates and events from around the world.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 03-05-2007   #1 (permalink)
hallo
Banned
 
Join Date: Mar 2007
Posts: 10
Rep Power: 0 hallo is on a distinguished road
Default Doomboot.A Trojan horse

Doomboot.A is a new Trojan horse that targets Symbian Series 60 devices. It presents itself as a cracked version of the game Doomboot.A drops corrupted system binaries into the c: drive. When the device is next rebooted, these corrupted files will be loaded instead of the correct ones causing the phone to Doom 2 in order to tempt victims to download and install it. fail to boot correctly.

In addition to system binaries, Doomboot.A also drops the Commwarrior.B worm. This will start attempting to spread automatically using both Bluetooth and MMS simultaneously. Moreover, because of the use of Bluetooth, the phone will run out of battery in about 1 hour. If the phone does run out of power then, as a result of the corrupted files dropped by Doomboot.A, the user will be unable to reboot the device even when connected to the mains or using a fully charged battery.

Once an infected phone has been subject to a reboot attempt the only known way to disinfect the phone is to carry out a hard reset of the device. Unfortunately this will result in the loss of any data the user has stored on the phone as well as in the removal of Doomboot.A.

Installing Doomboot.A does not cause an icon to be added to the device application menu, also CommWarrior.B will not appear within the devices processes list. As a consequence, it may be very difficult for a user to identify that his device is infected.

This Trojan does not exploit any security vulnerabilities within the Symbian OS, relying instead on the device user actively overriding the security features of the OS. The user of the device must actively install the Trojan by accepting multiple prompts, including one that is clearly presented as a security warning.

Impact
Doomboot.A could lead to customer complaints resulting from receipt of unsolicited MMS messages issued from infected devices. For those customers who are infected Commwarrior.B may generate MMS messages that result in additional charges on their bill.

If an infected device is rebooted, the Trojan could lead to revenue loss as the reboot will fail and the customer will not be able to make any further use of their device until they have performed a hard reset. It is also likely that customers whose devices become infected with this malware may call their operators customer services team for advice.

Furthermore, customers who carry out a hard reset of their device as a result of being infected will suffer the inconvenience of losing any data they may have stored on the device.


More Information
http://www.f-secure.com/v-descs/commwarrior_b.shtml

http://zdnet.de/security/infoportal/feed.htm?id=10

http://www.symbian.com/security/malware_advice.html
hallo is offline  
Old 03-07-2007   #2 (permalink)
swapnil90
Senior Member
 
Join Date: Feb 2007
Posts: 255
Rep Power: 2 swapnil90 is on a distinguished road
Default

I recently got an update for this...so i guess i am safe...
swapnil90 is offline  
Closed Thread

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

 
Problem with chargebacks? Call +1 (212) 751-6213 and ask to speak to a chargeback specialist.

Join us on LinkedIn


News, Updates, Alerts & More:

Subscribe in a reader
 
 


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52