myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron at myITforum.com

Sharing Security Developments, and Best Practices for corporate and home users

New Storm Worm - China/Beijing Earthquake Theme

This new variant disquises itself as a news flash to tempt users into selecting a hostile URL with a .cn domain

The email tries to convince users to download a dangerous malware object called beijing.exe

McAfee Information (DAT 5321)
http://vil.nai.com/vil/content/v_140835.htm

New Storm Worm - China/Beijing Earthquake Theme
http://www.f-secure.com/weblog/archives/00001457.html
http://www.sophos.com/security/analyses/viruses-and-spyware/w32nuware.html
http://www.theregister.co.uk/2008/06/19/bogus_beijing_quake_malware_ruse/

QUOTE: One of the trademarks of the Storm gang's 18 month lifespan has been that they're very creative and current when it comes to their social engineering techniques, e.g. 1, 2, 3, et cetera. The latest variant is e-mail that arrives to your inbox reporting a violent earthquake in Beijing.

Samples of the bogus alert doing the rounds, featuring subject lines such as "Million dead in Chinese quake", link to a website on a .cn domain. This site claims a quake measured in at 9.0* on the Richter scale has caused millions of casualties while throwing preparations for the games into turmoil. The page contains links to a supposed video that actually downloads the Nuwar-E worm onto the Windows boxes of marks credulous enough to fall for the ruse.

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems