New AIM worm in the wild
isc.sans.org reports that a new AIM worm is in the wild. This particular worm doesn't use exploiting techniques to spread, instead it uses social engineering.
A user migth receive the following AIM message:
"This AIM user has sent you a Greetings Card, to open visit:
someurl.com?my_christmas_card.COM from which the user will download the worm.
The worm is callded SDBot and should be caught by your AV filter.
The .COM can also be .SCR.
So be safe, and always be paranoid when receiving mails with URL or even worse executable files.