TeMerc
Topic Starter
Posted on Sunday, December 23rd, 2007
by Jose Nazario
Additional analysis over @ Digital Intelligence and Strategic Operations Group
by Jose Nazario
More Detailed Analysis @ ARBOR NetworksThe Storm Worm is back, this time it’s got a Christmas theme. Who knew that it would take them so long to do this? Here’s a sample mail:
That domain, merrychristmasdude.com, has a bunch of nameservers and a lot of IPs associated with it - Fast Flux!Date: Sun, 23 Dec 2007 21:19:19 -0500
From: geneoldham[at]usmint.treas.gov
To: —
Subject: Find Some Christmas Tail
got a sec?
Winter can be cold. I bet you could use a little something to warm you
up. Take 2 min out of your day. You wont regret it. ;-)
hxxp://merrychristmasdude.com/
An infected host will drop the file:
C:\WINDOWS\disnisa.exe
And store the peerlist in:
C:\WINDOWS\disnisa.config
A pair of randomly chosen ports - one TCP and one UDP - will be opened.
It will lower the firewall and add a registry entry to make sure that firewall permission is permanent.
After that, the usual Storm worm mayhem begins.
AV detection for this sample is pretty modest at this point
Additional analysis over @ Digital Intelligence and Strategic Operations Group