Latest news
The Benjamin worm uses Kazaa p2p (peer-to-peer) network to spread. Much like Napster, The Kazaa network allows its participants to exchange files with each other, using dedicated Windows-based software. Kazaa typically has more than one million users online at the same time, exchanging media files with each other.
Benjamin virus only works on Windows workstations which have the Kazaa program installed, When the virus is started, it shows a fake error message to the user:
Access error #03A:94574: Invalid pointer operation
File possibly corrupted.
After this the worm creates hundreds of files to the users hard drive and shares them to other Kazaa users. These files are actually copies of the worm itself, but they have been named to fool people into downloading them. Examples include:
"Deepest Purple-The Very Best of Deep Purple - Smoke on the Water"
"Metallica - Until it sleeps"
"Johann Sebastian Bach - Brandenburg Concerto No 4"
"South Park Vol.3-divx-full-downloader"
"Star wars Episode 1-divx-full-downloader"
"F1 Racing Championship-Games-full-downloader"
"Chessmaster 8000-Games-full-downloader"
The total list of filenames contains over 2000 entries. Apparently this list has been created by monitoring most popular searches being made in the Kazaa network. The size of the shared infected files varies between 200 and 800 kB. These files always .EXE or .SCR extension, but it has often been hidden by prepending dozens of space characters between the filename and the extension.
"Apparently the worm was written to make money for the virus writer", comments Mikko Hypponen, Manager of Anti-Virus Research at F-Secure Corporation. The worm opens a webpage named benjamin.xww.de which contained advertisments. "Now the page has been taken down, but if the virus author got money based on ad views, he might have created some cashflow here".
Benjamin worm was found on Saturday the 18th of May. By Monday the 20th, a typical search in Kazaa network resulted in 20-30 infected files being offered for download, increasing the likelyhood of spreading infections.
F-Secure Anti-Virus detects and stops the Benjamin virus.
Technical description and screenshots of the Benjamin virus are available from:
http://www.F-Secure.com/v-descs/benjamin.shtml


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





