This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Another "Storm" Wave

53 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/current/#new_storm_…ivity_spreading
July 29, 2008 - "US-CERT is aware of public reports of a new Storm Worm Campaign. The latest campaign is centered around messages related to the Federal Bureau of Investigation and Facebook. This Trojan horse virus is spread via an unsolicited email message that contains a link to a malicious website. This website contains a link, that when clicked, may run the executable file "fbi_facebook.exe" to infect the user's system with malicious code. Reports, including a posting by Sophos*, indicate the following email subject lines are being used. Please note that subject lines can change at any time.
- F.B.I. may strike Facebook
- F.B.I. watching us
- The FBI's plan to "profile" Facebook
- The FBI has a new way of tracking Facebook
- F.B.I. are spying on your Facebook profiles
- F.B.I. busts alleged Facebook
- Get Facebook's F.B.I. Files
- Facebook's F.B.I. ties
- F.B.I. watching you …"
* http://www.sophos.com/security/blog/2008/07/1599.html

- http://www.f-secure.com/weblog/archives/00001475.html
July 28, 2008

- http://www.virustotal.com/analisis/c167dc2…889ff53f0499231
07.28.2008 - Result: 17/35 (48.57%)

- http://www.fbi.gov/pressrel/pressrel08/stormworm073008.htm
July 30, 2008

:ph34r:
FYI…

- http://blog.trendmicro.com/storm-uses-old-bait/
August 5, 2008 - "The Storm gang is casting its net once again — using “postcards” as bait in a recently discovered spam run… Clicking the link embedded in the message connects the user to the any of the following domains:
* hxxp:// {BLOCKED}cardAdvertising.com/
* hxxp:// {BLOCKED}ettercard.com/
* hxxp:// {BLOCKED}ostcardArt.com/
* hxxp:// {BLOCKED}ostcardmail.com
* hxxp:// {BLOCKED}reetingcard.com/
* hxxp:// {BLOCKED}stcardOnline.com/
* hxxp:// {BLOCKED}ttercard.com/
…When the abovementioned page loads, an auto-redirect occurs after 3 seconds, prompting the user to download a file named postcard.exe… The same file, postcard.exe, is also downloaded if the user clicks on the link save it on the Web page. postcard.exe is detected as TROJ_NUWAR.DDJ… it is plausible that the Storm gang is using this constant change in technique to evade spam and URL filtering blocking. Storm’s has been known to constantly change its employed social engineering technique, the most recent ones being news of terrorists on social networking networks, economic issues, and fake videos of popular celebrities…"

(Screenshots available at the Trendmicro URL above.)

:ph34r: