April Storm

April Fools' Day emails contain new variant of infamous worm.

Security researchers report a new wave of spam emails being sent out. The emails, which use subject lines such as 'Gotcha! April Fool!' or 'Surprise! The joke's on you.', contain a small piece of text, an image as well as a link to an IP-based URI where the recipient is supposed to download the 'joke'. Instead of a joke, they will download a rather humourless .exe file which contains a new version of the Storm worm.

cyber-defence-summit

The Storm worm, which is also dubbed 'Nuwar' or 'Dorf', was first seen in the early days of 2007 and has been active ever since. The Storm botnet is believed to contain millions of infected computers.

A quantitative assessment of the Storm web threat during 2007 will be presented by Trend Micro's Raimund Genes, Anthony Arrott and David Sancho at VB2008 in Ottawa this October. VB2008 takes place 1-3 October 2008 in Ottawa, Canada, registration for VB2008 has now opened.

More on the current wave of Storm emails can be found at Sophos here and at Trend Micro here.

In the meantime, possibly inspired by Storm's botherders, more positive news can be found at F-Secure here and at Sophos here.

1 April 2008

Tags: april fools' day, spam, storm, worm.   

 del.icio.us  digg this! digg this

1 comment

Don't browsers these days give three red-flashing 'this could well be a virus!'-warning screens when you try to download a .exe file? They should. And as a non-sysadmin user in a corporate environment, one should just not be able to do that at all.

by M. Klein, 08 April 2008, 00:23

Comments are closed.

Quick Links

Poll
The Japanese government is reported to have commissioned a 'defensive virus'. Is 'defensive' malware ever a good idea?
Yes
No
I don't know
Leave a comment
View 11 comments

99 Subscription Promo

Malware Prevalence
Autorun |#######|
Encrypted/Obfuscated |#####|
Heuristic/generic |#####|
Sality |####|
Zbot |####|
 View this month's full report

Virus Bulletin currently has 224,229 registered users.