Tuesday, January 23, 2007 8:44 AM
cmosby
F-Secure : News from the Lab - Stormy Love
Here is a good example of how futile blocking subject lines of e-mail to block out viruses. One little change and the virus will get right on through. Blocking .exe's is the only smart thing to do.

A list of subjects we've seen so far include:
|
A Bouguet of Love A Day in Bed Coupon A Monkey Rose for You A Red Hot Kiss Against All Odds All That Matters Baby, I'll Be There Back Together Breakfast in Bed Coupon Can't Wait to See You! Cyber Love Dinner Coupon Dream Date Coupon Emptiness Inside Me Fields Of Love For You Full Heart I Believe I Can't Function I Dream of You I Think of You Internet Love It's Your Move
|
Kiss Coupon Love Birds Love You Deeply Made for Each Other Miracle of Love Moonlit Waterfall My Invitation Our Love Our Love is Free Our Two Hearts Passionate Kiss Pockets of Love Puppy Love Red Rose Sending You My Love Showers of Love Someone at Last Soul Partners Summer Love Take My Hand That Special Love The Dance of Love The Long Haul
|
The Love Bugs This Day Forward This Feeling Till Morning's Light Till Morninig's Light The Mood for Love To New Spouse Together Again Together You and I Touched by Love Twice Blest Until the Day We're a Perfect Fit Wild Nights Will you? When I'm With You Worthy of You Wrapped Up Wrapped in Your Arms You are our of this world You Lucky Duck! You Rock Me! You Were Worth the Wait
|
Thanks to Diego who notified us and told us that this list looks very similar to the list of Romantic Cards over at 2000greetings.com and indeed it does.
The list of files is much shorter:
Greeting Postcard.exe
postcard.exe
greeting card.exe
Flash Postcard.exe
flash postcard.exe
We now detect this as Email-Worm.Win32.Zhelatin.a.
Note: For those of you who aren't already filtering EXE's in the e-mail gateway – do it now!
F-Secure : News from the Lab - January of 2007.
Filed under: Security and Anti-Virus, AntiVirus Information, Internet Hacks