E-mail with an April Fool's Day theme is serving up the latest round of Storm worm attacks.
April Fool's Storm Worm Attack Hits
A new Storm worm with an April Fool's Day theme is targeting the Web, according to security software firm PC Tools.
"The Storm worm gang has done it again. This time e-mails are being circulated, which are associated with the April Fool's Day theme," said PC Tools chief threat officer, Kurt Baumgartner.
The e-mail messages contain links that direct users to Web sites that contain malware. Once the files are downloaded and executed on the computer it sets a firewall exception rule and then attempts to 'phone home' using various outgoing ports.
According to Baumgartner, the packer and major sections of executable code have changed significantly, indicating that it could be another variant and AV detection for this threat is close to nonexistent.
"The most effective way users can protect against these new threats is with antimalware products that use behavioral technology. Traditional AV products, which use signature detection are simply not equipped with this behavioral technology and the threat is currently evading those users' defenses," he said.
"Always exercise caution and don't just click on random links sent to your account via e-mail. Exercise even more caution when that random link is attempting to download a file to your system," adds Baumgartner.
Wednesday, April 2, 2008
Storm Worm is Back
Posted by
Ran Werkheiser
at
07:36
0
comments
Labels: april fools, Storm, worm
Thursday, February 14, 2008
Storm Worm Reappears this Valentine
Security vendor McAfee warns of a Valentine come-on that downloads a virus instead of a greeting.
Storm Worm Reappears as Malicious Valentine
Carrie-Ann Skinner, PC Advisor
A Valentine's themed outbreak of the Storm worm has been detected.
Around the world, malicious e-mail messages are being received that contain a link that directs users to a website where they can supposedly download a Valentine's card, but in fact are infected with the Storm bug. The virus mirrors the fake Christmas and New Year messages seen in previous months.
According to Greg Day, security analyst at McAfee, the virus will try to steal personal information from your PC, bring down its security defenses and use your PC to send out millions of junk emails.
"There are about 10 million PCs worldwide infected with the Storm worm. These threats have suddenly spiked from 0 percent of all spam emails to 1.5 percent and they are continuing to rise as we draw closer to Valentine's Day and more people are fooled into downloading the malicious file," he commented.
"With all the hype that surrounds Valentine's Day, it was only to be expected that they (the people behind Storm) would use a similar tactic and exploit people's eagerness to receive Valentine's cards," added Diego d'Ambra of email-security company SoftScan.
source: PCWorld
Thursday, December 27, 2007
Storm Worm Changes Tactic
Storm Botnet changes the message it sends to unsuspecting victims, prefering to exploit the new year celebration instead.
Storm Botnet Drops Strippers Lure, Switches to New Year's
Just a day after unleashing spam featuring Christmas strippers, the Storm botnet switched gears yesterday and began duping users into infecting their own PCs by bombarding them with messages touting the new year, said security researchers.
According to U.K.-based Prevx Ltd. and Symantec Corp. in Cupertino, Calif., the botnet of Storm Trojan-compromised computers started sending spam with subject headings such as "Happy 2008!" and "Happy New Year!" late on Christmas Day. The messages try to persuade recipients to steer for the Uhavepostcard.com Web site to download and install a file tagged "happy2008.exe," said researchers at both firms.
However, the file is actually a new variant of the Storm Trojan.
Marco Giuliani of Prevx reported that the company had seen two general variants by early Wednesday. "The first has been online for about 10 hours, and we've seen 166 different repacked versions of it," said Giuliani in a posting to the Prevx company blog. The Storm code has been repacked every few minutes using a polymorphic-like technique since Monday, when the botnet started spreading stripper spam. Frequent repacking is a trick malware authors use to deceive signature-based antivirus software.
The Storm botnet's herders are also using fast-flux DNS (Domain Name System) tactics to keep the Uhavepostcard.com site operational, said Symantec. Fast flux, which the Storm botnet did not originate but has often used, is another antisecurity strategy; it involves rapidly registering and de-registering addresses as part of the address list for either a single DNS server or an entire DNS zone. In both cases, the strategy masks the IP address of the malware site by hiding it behind an ever-changing array of compromised machines acting as proxies.
The notorious Russian Business Network malware hosting network has become infamous for using fast flux to hide the Internet location of its servers, making it difficult for security researchers, Internet service providers or law enforcement officials to track the group's cybercrimes
source: www.computerworld.com
Wednesday, December 26, 2007
Storm Worm Strikes Again
The Storm botnet delivers unwanted Christmas presents.
Storm Worm Tempts With Christmas Strip Show
The criminals behind the Storm botnet waited until the last minute, but they've finally started delivering unwanted Christmas presents.
Starting Monday, Storm-infected machines began sending out Christmas-themed spam in yet another attempt to trick victims into downloading malicious software. In this case, the site is named Merrychristmasdude.com, and the malware is a variation of the Storm Trojan horse program that has been plaguing systems around the world since January.
The e-mails contain titles such as "Find Some Christmas Tail," "Warm Up this Christmas" and "Mrs. Clause Is Out Tonight!"
One message reads "Yo, I am pretty sure this is up your alley, from the things you have told me before. This will be the best 2 min you spend this holiday. hehe."
Once the user clicks on the link to Merrychristmasdude.com, he is taken to a Christmas-themed Web site with photos of scantily clad women and offered a free download. That download is a malicious program, called Email-Worm.Win32.Zhelatin.pd by F-Secure, that connects to a P-to-P (peer-to-peer) network and begins downloading even more malware.
Storm's creators have built up networks of infected PCs -- called botnets -- over the past year by using a combination of sophisticated hacking tricks to avoid detection and by spamming potential victims with clever and timely e-mail messages. The network is called Storm because its original messages offered victims video of the deadly storms that battered Europe a year ago, but has also perfected the tactic of sending out holiday-themed messages.
Security experts estimate that the Storm has infected more than 15 million computers over the past year, although the current size of the network is much smaller than that.
This latest variant is being blocked by some antivirus vendors, including Kaspersky, Microsoft and Symantec, according to a technical write-up of the Christmas outbreak.
The SANS Internet Storm Center recommends that administrators block Web and e-mail access to the Merrychristmasdude.com domain.
source: www.pcworld.com
Posted by
Ran Werkheiser
at
07:51
0
comments
Labels: botnet, online security, Storm, worm
Thursday, October 25, 2007
The Storm Worm Botnet
What's the most powerful computer in the world? The IBM's BlueGene/L supercomputer? Sort of.
The Storm of the Century
The world is abuzz with a new threat that's spreading over the Internet. The Storm Worm has infected more than a million computers and now created a vast network of computers, or botnet (robot network), with the power to dwarf the world's fastest supercomputer, the IBM BlueGene/L. With the power of millions of computer, amounting to a million CPUs and petabytes of RAM, the worm could knock could easily knock out a website or a server at the command of a single individual (bot herder).
The Storm worm infects computers by tricking the users into running the worm. It arrives as a harmless spam email attachment. However, the contents of the email message may contain a message that compels the user into opening the attachment. This is also why the worm was called the Storm worm. When the worm first appeared, the email message it contained was about a storm in Europe, with a 'video' attachment for the said event. The recipient of the email may open the attachment, hoping to see clips of the storm's devastation, but instead launching the virus.
Perhaps the most notable trait of the worm is that it changes the email message it sends. For example, the worm sent out email spams containing advertisements for a anonymous-surfing internet browser called Tor, which is a genuine web browser. The worm sent an email that used actual text and images from the actual Tor website. However, clicking the download link and installing the program downloaded (tor.exe) will install Storm. It also used to send fake e-greeting cards, and during the peak season of football, sent email containing the team's football scores as the attachment.
Once the Storm infected the computer, it defends itself. If the Storm is scanned or gets detected, it sends a message to some, or even all, of the botnet to send garbage to the victim. The stream of garbage is often enough to knock a website offline or take down the victim's internet connection. This is called DDoS, or Distributed Denial-of-Service attack. It's even sneaky when it does that, as the flood of garbage is sent not from within the network or the same IP address. That will make the attack look like it came from somewhere else.
The Storm became so popular it even has a video in YouTube. Comments from the site even said the worm came from aliens and extraterrestrial life.
My advice, always have a good antivirus and firewall installed in your computer. Also, refrain from using older software, like Internet Explorer, Adobe Reader, or even WinZip, as the worm exploits the vulnerabilities in these old programs.
Story:
Copyright 2007 Sonicsoft Corporation
All Rights Reserved
Posted by
Ran Werkheiser
at
07:03
0
comments