[113724] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: SkypeSetup Rogue Download

daemon@ATHENA.MIT.EDU (Rubens Kuhl)
Sun Apr 19 23:32:39 2009

In-Reply-To: <961312.26185.qm@web1213.biz.mail.gq1.yahoo.com>
Date: Mon, 20 Apr 2009 00:32:21 -0300
From: Rubens Kuhl <rubensk@gmail.com>
To: Mari Nichols <mari@imarsolutions.com>
Cc: Nanog Nanog <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

Could be a local trojan inserting bogus entries on the hosts file,
could be DNS poisoning on one particular resolver, or an infection on
the distribution source.


Rubens



On Sun, Apr 19, 2009 at 5:55 PM, Mari Nichols <mari@imarsolutions.com> wrot=
e:
> I believe the file is originating directly from Skype. =A0Our writer
> stated that he had tried download.com's version and it was clean
> against VT. =A0I'm on ISC handler duty today, just wondering if anyone
> had seen this happening.
>
> Mari Nichols
> HoD
>
>
>
>
> ________________________________
> From: Paul Ferguson <fergdawgster@gmail.com>
> To: Mari Nichols <mari@imarsolutions.com>
> Sent: Sunday, April 19, 2009 4:31:06 PM
> Subject: Re: SkypeSetup Rogue Download
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On Sun, Apr 19, 2009 at 12:55 PM, Mari Nichols <mari@imarsolutions.com>
> wrote:
>
>> Has anyone seen anything like this?
>>
>> http://www.virustotal.com/analisis/f58203f8d5cb98628eaa785e27c9e059
>>
>
> Hi,
>
> Could you provide the URL where that file is located?
>
> Thanks,
>
> - - ferg
>
> -----BEGIN PGP SIGNATURE-----
> Version: PGP Desktop 9.5.3 (Build 5003)
>
> wj8DBQFJ64oEq1pz9mNUZTMRAs4MAJ9x8vwDJzMEnci72jEK7hNEd2NmdQCfRUgE
> B4Se4ZXdcTaoT4h1SHfmC4Q=3D
> =3DwXNG
> -----END PGP SIGNATURE-----
>
>
>
> --
> "Fergie", a.k.a. Paul Ferguson
> Engineering Architecture for the Internet
> fergdawgster(at)gmail.com
> ferg's tech blog: http://fergdawg.blogspot.com/
>


home help back first fref pref prev next nref lref last post