18539 on 21 Sep 2008
‘Incinerated Cash’ Serves As Effective Malware Bait
A million dollars, even when it’s already burnt to a crisp, proves to be irresistible to some people.
Trend Micro has been seeing a large number of users affected by malware distributed through a spammed message that yarns a story of bank robbery video footage, wherein a million dollars supposedly got incinerated.
The news is, of course false, but still seems to entice recipients to attempt to see the bogus video.
Below is a screenshot the pammed message:

The email comes with two attachments: a non-malicious .HTML file (file name in Japanese characters), and Video.rar attachment which is apparently supposed to be the video footage of the robbery. It contains the executable file My.YouTube.Movie.avi.exe, which is detected by Trend Micro as TROJ_DISKEN.K.
But the trouble doesn’t stop there.
TROJ_DISKEN.K downloads TROJ_RENOS.SYM, which in turn installs both JOKE_BLUESCREEN and TROJ_FAKEAV.IE on the victimized systems.
JOKE_BLUESCREEN is a joke program that tricks the user by modifying the system screen saver to one that is similar to a BSOD.
TROJ_FAKEAV.IE on the other hand is a rogue antivirus, thus adding this attack to the string of rogue antivirus-related attacks that have surfaced in the past months.
Trend Micro users are now protected from this attack through the Smart internet security protection Network. Other users are advised to be cautious of unsolicited and unexpected messages.


