Great Deal from Dell™
Close Me

Great Deal from Dell™
Dell™ Inspiron™ 1420 - Powered by Intel® Core™2 Duo processor
+ FREE Upgrade to 3GB Memory

 
 
Friday, 05 December 2008 08:40 AM
 
 
 
 
1395 visitors online
Main Menu
Home
News
Forums
Links
Contact Us
Search
Advertising
Guides
Reviews
Demographics
Administrator
Lowyat Pricelists






nokia
sony


Advertisements



Symbian Worm on the loose
(3 votes)
by Nigel Yap   
Thursday, 24 January 2008 07:09 PM

ImageFortiGuard Global Security Research Team discovered a new SymbianOS Worm actively spreading on various mobile phone networks. The worm, deemed SymbOS/Beselo.A!worm is able to run on several Symbian S60 enabled devices. These devices include, but may not be limited to, Nokia 6600, 6630, 6680, 7610, N70 and N72 phones.

After an installation phase, the worm engages in a propagation routine: phone numbers located in the contact list of the devices are harvested, and targeted by viral MMS carrying a SIS-packed (Symbian Installation Source) version of the worm. However, the SIS file does not bear a .sis file extension -- rather, it is disguised as a multimedia file with an evocative name: either Beauty.jpg, Sex.mp3 or Love.rm.  

Users may know they have been infected if they see unrecognized sent messages in their MMS outboxes. FortiClient Mobile automatically detects and removes the Beselo worm. For users without FortiClient Mobile who believe they may be infected, please contact your mobile carrier or phone manufacturer for technical support in manually removing the virus.  

Read on for more info on the worm. 

Unlike Microsoft Windows, SymbianOS types files based on their contents and not their extensions, so it is worth noting that recipients of infected MMS would still be presented with an installation dialogue upon "clicking" on the attachment. Therefore, users could easily be deceived by the extension and unknowingly install the malicious piece of software.

In addition to harvesting the numbers stored in the phone address book as mentioned above, the Beselo worm sends itself to generated numbers as well. Interestingly, all those numbers are located in China and belong to the same mobile phone operator. Some of those numbers have been verified to belong to actual customers, rather than being premium service numbers. The whys and hows of such a routine are still under investigation.

Albeit the prevalence of this mobile malware incident is still low, the FortiGuard Global Security Research Team will continue to monitor the situation and update the description with new findings as needed.

Comments

Name: Spider Comment:
it's more sound like the [B]ComWarrior virus [/B]which does the same funtion and it also send via Bluetooth with out any notice
blue-smiley
Rated Article:
Posted: 2008-01-25 15:36:16
IP Logged as: 203.214.176.16 HomePage: http:// Browser: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.1) Report This Comment

Name: fatty Comment:
Haha, its targeting perverts eh... clownclown
Rated Article:
Posted: 2008-01-24 22:04:15
IP Logged as: 218.111.187.252 HomePage: http:// Browser: Opera/9.25 (Windows NT 5.1; U; en) Report This Comment

Comment on this article


Your Name:

Your Email Address:

Your Homepage:

Rate this article:
Poor Great

Comment:
BOLD "QUOTE" UNDERLINE

< Prev   Next >
 
Top! Top!