Posted on Sunday, December 23rd, 2007
by Jose Nazario

The Storm Worm is back, this time it’s got a Christmas theme. Who knew that it would take them so long to do this? Here’s a sample mail:

Date: Sun, 23 Dec 2007 21:19:19 -0500
From: geneoldham[at]usmint.treas.gov
To: —
Subject: Find Some Christmas Tail

got a sec?

Winter can be cold. I bet you could use a little something to warm you
up. Take 2 min out of your day. You wont regret it. ;-)
hxxp://merrychristmasdude.com/

That domain, merrychristmasdude.com, has a bunch of nameservers and a lot of IPs associated with it - Fast Flux!

An infected host will drop the file:
C:\WINDOWS\disnisa.exe
And store the peerlist in:
C:\WINDOWS\disnisa.config

A pair of randomly chosen ports - one TCP and one UDP - will be opened.

It will lower the firewall and add a registry entry to make sure that firewall permission is permanent.

After that, the usual Storm worm mayhem begins.

AV detection for this sample is pretty modest at this point

More Detailed Analysis @ ARBOR Networks

Additional analysis over @ Digital Intelligence and Strategic Operations Group