ThreatFire Research Blog Home
 
 
« Fake alert for Spyware.CyberLog-X
Chartreuse pill »

Storm’s premature invitation

Some things arrive way too early. This time, it’s the Storm worm.

The Storm gang is starting early on the Valentine’s day theme, and we are receiving emails from these affectionate souls, trying to deliver “withlove.exe“, and other malicious vday themed executable names to our systems.

This campaign includes familiar and consistent characteristics. An email will arrive with a cute statement related to the theme, inviting a user to visit a hyperlink containing an ip address. The destination web site will attempt to exploit the visitor’s system, and if it can’t, the page provides a download link for the executable:

The authors of this one must be planning on some Valentine’s day Mexican cuisine. We’ve seen it dropping files like “burito.ini” and “burito5e84-1216.sys”, before killing AV products and adding the victim host to its huge botnet.

Last year’s massive Storm outbreak pushed romantic subject lines such as “Sending You My Love” and “You’re the One”. While “With love”, “I Would Dream”, and “Memories of You” isn’t all that much of a change, it’s a small twist. Nicolas Albright made a fairly safe prediction that this upcoming holiday would be the next target:
“The DISOG team is placing bets on the next rouse. I say adult rated material for February 14th (St. Valentines Day).”

I’m sure he’ll have another interesting post about this variant.

This entry was posted on Tuesday, January 15th, 2008 at 12:05 pm and is filed under Bot, Storm, Worm. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

One Response to “Storm’s premature invitation”

  1. mattky says:
    February 5, 2008 at 10:15 pm

    I recieved an email from tina.fowler@pdainc.com titled “The Rose”, because it is a valid company I opened it.IT read “sending you ALL my love” followed by a click on address that showed a lacy heart.
    Is this a worm of some sort or a legit email from this person?

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).