Home→Blog→Virus Watch→June 06 2006→Latest info on the GpCode infections
We have been investigating the source of the recent outbreak of the cyber-blackmail virus GpCode, which is on the loose in the Russian Internet.
Our research shows that the virus was spread in the following manner:
We are writing to you regarding the resume you have posted on the job.ru website. I have a vacancy that is suitable for you. ADC Marketing LTD (UK) is opening an office in Moscow and I am searching for appropriate candidates. I will soon be asking you to come in for an interview at a mutually convenient time.
If you are interested in my offer, please fill out the attached form related to compensation issues and email the results to me.
Sincerely,
Viktor Pavlov
HR manager
[the above is a translation from the Russian]
The attached file is a MS word .doc file named anketa.doc [anketa is the Russian for application form - translator’s note]. Actually, this file contained Trojan-Dropper.MSWord.Tored.a.
The author of GpCode conducted similar mass mailings over several days. S\he also changed the variants of GpCode that were being downloaded from this URL.
Kaspersky Lab is currently working on closing this site down.
Comments
Analysis
Blog
Alerts