Storm worm resurfaces, tries love angle again

By Tom Espiner, ZDNet UK
Wednesday, June 04, 2008 08:35 AM

After a hiatus, the gang behind the Storm worm is attempting to exploit people's curiosity about a fictional love interest to tempt users into downloading the malware, according to security training organization the Sans Institute.

Donald Smith, a security expert from the Sans Institute, warned late Tuesday that a Storm worm download site had been detected by security researcher 'DavidF'. A link that contained the site's IP address was being spammed out in e-mail messages, wrote Smith in a blog post.

He noted that spam is being sent with the message: "'Crazy in love with you' hxxp://122.118.131.58". Smith wrote: "I checked that site and could only find an index.html, lr.gif and loveyou.exe."

Smith said that index.html encourages visitors to run the 'loveyou' executable by asking: "Who is loving you? Do you want to know? Just click here and choose either 'open' or 'run'." Loveyou.exe is a version of the Storm worm, also known as Trojan.Peacomm.D by Symantec and Troj/Dorf-AP by Sophos. Smith recommended IT professionals block the IP address until it gets "cleaned up".

The unknown gang behind the Storm botnet tried a similar technique in January in the run up to Valentine's Day. At the time, Sophos warned that the gang was using a social-engineering technique in an attempt to trick users into clicking on a link in a 'Valentine's Day' e-mail.

Storm worm attacks then dropped off, leading some security vendors to report that the influence of Storm worm was waning. However, in May, Symantec researchers warned they had identified a number of nascent Storm worm hosting domains using fast-flux techniques to mask their URLs.

The original Storm worm code, which appeared on 2007, Jan. 19, derived its name from the fact that the first spam linking to the malware coincided with a severe winter storm in Europe.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Never use dynamic variable names

Internet Security

How to dynamically name variables is a common subject of programming questions. That's a great way to create security problems, though.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Are telcos new drivers of outsourcing industry?

Blog thumbnail

The recent TPI Index from TPI highlighted an interesting trend where a few very large Telco-to-Telco contracts--instances where one telecommunications carrier outsources its network operations requirements to another telecommunications service..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web