« 2005 List of (Known!) OS Vulnerabilities | Main | WMF Exploit Unofficial Patch »

Sunday, January 01, 2006

WMF Exploits via Email

The emails Subject line is: "Happy New Year" and the Body says: "picture of 2006". Included is an attached exploit WMF file named "HappyNewYear.jpg". When the HappyNewYear.jpg is accessed (file opened, folder viewed, file indexed by Google Desktop) it executes and downloads a backdoor trojan from www[dot]ritztours.com. Please add this domain to your hosts file and make sure your Anti-virus is up to date.