<<< NEWS FROM THE LAB - Thursday, December 17, 2009 >>> ARCHIVES | SEARCH Merry Christmas, Idiot Posted by Mikko @ 08:20 GMT It's not a huge surprise that we are seeing some malware spam runs where the malicious attachment attempts to portray itself as a Christmas Greeting of some sort.



Here's an example from today (md5: C670165AE6DFA8318F0EA795B1D3AD55). This one is actually a Zapchast (IRC bot variant).



The "Christmas Card" requires it's own "special version" of Flash to be installed — flashplayer2009.exe — which is the malware itself.



Once ready, it will display this friendly message written in Universal Gibberish.







Pay attention to the cheerful filename used for this message — idiot.jpg.



F-Secure Anti-virus detects and removes this as Backdoor.IRC.Zapchast.AVL.









