Incidents

“Format before use” – wasn’t that a thing for floppies?

Some months ago I bought a HDD-based MP3 player from iRiver. When I plugged it into my computer I was hit with an unhappy surprise – a virus was detected.

I did some (re)search and it turned out that iRiver has shipped MP3 players containing the VBS.Saraci virus.

At first only the model I purchased seemed affected. However when I did some checking a few weeks later I saw reports concerning other models as well.

So why I am bringing up old news?

Because yesterday I got an e-mail from a person which stated that another brand of MP3 player named “Denver” also carries this malware, making this ‘old news’ new again. This person purchased the device as a Christmas present.

And what also makes the old news new: this concerns a Flash-based player instead of a HDD-based player.

VBS.Saraci utilizies a vulnerability not present in Windows 2000 or XP. The virus’s most important characteristic in this case is that VBS.Saraci copies itself into the root of every (network)drive as “folder.htt”, just as it was in the case with the above mentioned MP3 players.

This leads me to believe that the players have been tested on infected (pre XP) computer(s), which then in turn infected the MP3 players.

It’s not unlikely that we will see other, perhaps more destructive malware ‘pre installed’ on MP3 players. Therefore I would like to advise everyone to format your (just purchased) MP3 player before plugging it into the computer, as you otherwise might get infected.

“Format before use” – wasn’t that a thing for floppies?

Your email address will not be published. Required fields are marked *

 

Reports

APT trends report Q3 2021

The APT trends reports are based on our threat intelligence research and provide a representative snapshot of what we have discussed in greater detail in our private APT reports. This is our latest installment, focusing on activities that we observed during Q3 2021.

Lyceum group reborn

According to older public researches, Lyceum conducted operations against organizations in the energy and telecommunications sectors across the Middle East. In 2021, we have been able to identify a new cluster of the group’s activity, focused on two entities in Tunisia.

Subscribe to our weekly e-mails

The hottest research right in your inbox