FYI…

- http://isc.sans.org/diary.html?storyid=2586
Last Updated: 2007-04-08 22:00:44 UTC …(Version: 5)
"If you're still not blocking EXEs on your email gateway, chances are your users are getting flooded by the latest scam at the moment. We're receiving reports of a "movie.exe" 95c563731b7828d6e98eae81ee08869f making the rounds, attached to emails with very "clickable" subject lines like "USA Just Have Started World War III" / "Missle Strike: The USA kills more then 20000 Iranian citizens" / "Israel Just Have Started World War III" / "USA Missile Strike: Iran War just have started". You get the drift - the kind of friendly headlines you would expect to get on a peaceful Easter sunday…
Update 2000 UTC: Filenames "video.exe", "click here.exe", "clickme.exe", "readme.exe" and "read more.exe" are also used, and occasionally it is neither the USA nor Israel, but Iran who has started World War III. Lovely.
Other MD5: 4a32764f9165980e255a80ee63edf402 …
Update 2200 UTC: AV coverage starting to become available, W32/Tibs.ET@mm (Fortinet) Email-Worm.W32.Zhelatin.cq (Kaspersky/F-Secure) W32.Dref.AF (Sophos) Of course also worth mentioning is Symantec, who caught it early on, by detecting the packer: Trojan.Packed.13."
> > http://www.f-secure.com/weblog/archives/ar…7.html#00001164
April 8, 2007 - 21:31 GMT ~ "A large amount of malicious email has been sent with subjects suggesting a missile strike to civilian targents in Iran:
"USA Just Have Started World War III"
"Missle Strike: The USA kills more then 20000 Iranian citizens"
"Israel Just Have Started World War III"
"USA Missile Strike: Iran War just have started"
A malicious executable with "video.exe", "movie.exe" etc. is attached. The files are detected at the moment with update 2007-04-08_02 as: Email-Worm.Win32.Zhelatin.cq *"
* http://www.f-secure.com/v-descs/email-worm…elatin_cq.shtml

Not so funny.php
- http://isc.sans.org/diary.html?storyid=2585
Last Updated: 2007-04-08 16:29:01 UTC
"…I came across an exploit which tried to download a binary called "funny.php", it sure felt enough like a glitch in the matrix to make me look back through my logs. And indeed, there's been another funny.php, from the same server in Malaysia, almost a month ago. And another, five days ago from a server in Germany. The EXEs the exploit tries to retrieve varies (of course) but the exploit pattern is always the same. The first file, commonly included per IFRAME, contains a file part named "in.php?adv=1". This file contains an encoded blob of JavaScript, which is not reliably detected by AV (from the scanners I have at hand to verify, only Kaspersky, FSecure and McAfee seem to recognize it at all). Once manually decoded, AV detection improves somewhat, but is still leaky. The decoded blob reveals a bunch of "friendly" little code snippets:
1. Exploit-Byteverify (a quite wizened Java exploit)
2. An Exploit for MS06-014, with the code lifted almost in verbatim off the corresponding Metasploit Module.
3. A copy of the MS06-057 WebViewFolderIcon.SetSlice exploit, artfully rendered to avoid detection.
If either of these is successful, the exploit downloads and runs the mentioned "funny.php?adv=1" files, which invariably turn out to be Trojan Downloaders or worse. The funny.php thingies are apparently refreshed frequently enough to keep AV coverage low to nonexistent…"

.