Malicious message for Heartbleed contains malware

Everyone knows and has read about the OpenSSL bug heartbleed, a critical error in running OpenSSL that allows attackers to read portions of the affected server's memory by revealing user data.

heartbleed

Heartbleed's vulnerability has become a front page all over the world, but some readers do not know its nature, otherwise they would not be the victims of the spam that followed.

The χρησιμοποιούν κάθε ευκαιρία και έτσι αυτή τη φορά να εκμεταλλεύονται το περίφημο Ηeartbleed bug για να τρομάξουν τους and lead them to install an Anti-Heartbleed software on their systems, which is of course malware.

Her researchers αποκάλυψαν μια εκστρατεία το spam που διαδίδεται με την αποστολή μηνυμάτων και προειδοποιούν τους ανυποψίαστους χρήστες ότι τους σύστημα μπορεί ακόμα να “μολυνθεί” από το Ηeartbleed bug (!). Έτσι ζητάει να εκτελέσουν το εργαλείο αφαίρεσης του bug Ηeartbleed (που έρχεται συνημμένο στο μήνυμα) προκειμένου να αφαιρέσουν τον ιό από το σύστημά τους.

Those who do not know that Heartbleed is not a virus or Malware, but a vulnerability of OpenSSL is falling into the spammers' trap.

If someone opens the attachment which appears to be a docx file, an encrypted zip file will also come. When the victim extracts the zip file, it will find an executable .Exe that it thinks is the Heartbleed bug removal tool.

Once the .exe runs it downloads a keylogger to the , without his knowledge, while a progress bar appears with a message stating that the Heartbleed bug was not found and the computer is clean.

The victim feels relieved after knowing that he is not at risk from Heartbleed but at the same time ignoring that there is a keylogger that records that he typed on his computer. The keylogger installed in the background except that it records the keystrokes, gets screenshots and sends the information to the criminals.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).