No April Fools'--Storm worm is back

By Robert Vamosi, CNET News.com
Tuesday, April 01, 2008 10:32 AM

Don't click on that silly April Fools' Day e-mail, says one security expert.

In a blog, Arbor Networks' Jose Nazario reports that within the last 24 hours he's seeing new releases of the Storm worm designed to take advantage of the first day of April. This new spam campaign is a lure to infect new computers that will become part of the larger Storm worm botnet.

The e-mail body is spartan: the words "Doh! April Fools" followed by a numeric URL. If a user clicks on that URL, the default Internet browser will open to a page with a cartoon character. A download is supposed to start within five seconds and, according to the message: "If your download does not start, click here and then press 'Run'."

The compromised computer will then install the downloaded file as C:\WINDOWS\aromis.exe. Nazario reports that the botnet file opens the firewall using the netsh firewall set command, makes a lot of outbound connections, then listens on a random UDP port.

This article was first published as a blog on CNET News.com.


See also:  Hacking
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Fix numbers that deviate from your numbered list format

Microsoft Office Suite

Here's how you can eliminate the paragraph formatting to make the number match the others.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attacks
  3. black
  4. cards
  5. data
  6. dns
  7. e-mail
  8. facebook
  9. flaw
  10. flaws
  11. fraud
  12. google
  13. hits
  14. iphone
  15. london
  16. mac
  17. malware
  18. microsoft
  19. over
  20. patch
  21. researcher
  22. researchers
  23. security
  24. spam
  25. trojan
  26. uk
  27. us
  28. users
  29. warns
  30. worm

Why is Asia not open to open source?

Blog thumbnail

One of the main draws--and selling point--of open source technology is its much celebrated developer ecosystem. But, according to an industry expert, this community spirit seems to be lacking in..... by Eileen Yu

Read more »