On mySimon: Chinese Laundry Top Over-the-Knee Boots
BNET Business Network:
BNET
TechRepublic
ZDNet

May 19th, 2008

The Storm Worm would love to infect you

Posted by Dancho Danchev @ 2:27 pm

Categories: Botnets, Viruses and Worms

Tags: Storm Worm, Dancho Danchev

The Storm Worm malware is back in the game, with its most recent campaign currently active and trying to entice users into executing iloveyou.exe by spamming them with links to already infected hosts acting as web servers, next to SQL injecting malicious domains into legitimate sites for the campaign to scale faster.

The Storm Worm Malware

What has changed compared to previous campaigns? Storm Worm is back in the SQL injection attack phrase, with tellicolakerealty .cn/ind.php iframe injected at a small of sites for the time being. Moreover, assessing the storm worm infected hosts can only be done if you spoof your user agent to Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1921), otherwise you will get no indication for any kind of malicious activity going on. Furthermore, despite that there are no exploits used at the infected hosts but, a heavily obfuscated HTML/Rce.Gen was detected in their injected domain which would load automatically upon someone visiting an already injected site.

The Storm Worm Malware

These are the most recent detection rates for both, the binary, and the javascript obfuscation :

Javascript obfuscation
Scanners result : 6/32 (18.75%)
HTML/Rce.Gen; Packed.JS.Agent.a

iloveyou.exe
Scanners result : 10/32 (31.25%)
Email-Worm.Win32.Zhelatin.yu; Trojan.Peed.PJ

Compared to the previous event-based social engineering campaigns on behalf of Storm Worm, the latest wave of malware isn’t thematic at all. It remains to be seen whether or not they would start emphasizing on SQL injections to acquire new infected hosts given the success of the copycats and the Asprox botnet, or continue using email as the primary distribution vector.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 23 Talkback(s)
RE: The Storm Worm would love to infect you
What the heck is this article saying? What is an "obfuscated
HTML/Rce.Gen"? What does it mean to "spoof your user
agent to Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
SV1921)"? What... (Read the rest)
Posted by: naomiquinones@... Posted on: 07/09/08 You are currently: a Guest | | Terms of Use
Um... It this page a stormworm vector??  Dreamer.fithp | 05/19/08
Re: Um... It this page a stormworm vector??  ddanchevZDNet Moderator | 05/20/08
RE: The Storm Worm would love to infect you  ddanchevZDNet Moderator | 05/20/08
I could have mentioned Tufte as well  DannyO_0x98 | 05/20/08
confused!  CaptOska | 05/20/08
Re: confused!  ddanchevZDNet Moderator | 05/20/08
RE: The Storm Worm would love to infect you  cwallen19803@... | 05/20/08
RE: The Storm Worm would love to infect you  ddanchevZDNet Moderator | 05/20/08
It may a "learned" post, but it fails in basic communications  dave.mc | 05/20/08
Which scanners detect?  connell@... | 05/20/08
Re: Which scanners detect?  ddanchevZDNet Moderator | 05/20/08
Symantec not getting new samples?  kolvas | 05/20/08
RE: The Storm Worm would love to infect you  phatkat | 05/20/08
RE: The Storm Worm would love to infect you  DCMann | 05/20/08
Ditto - Non-English native speaker Tech Writing is Difficult  david.swift@... | 05/21/08
Made sense to me  notlob | 05/21/08
RE: The Storm Worm would love to infect you  pessimist | 05/20/08
RE: The Storm Worm would love to infect you  TechTeach_z | 05/20/08
The story isn't badly written, just technical  pyrr | 05/22/08
English being the USA's official language  Mahegan | 05/24/08
Translation? Nothing but Jibberish  djMot | 05/27/08
RE: The Storm Worm would love to infect you  lazarusbill@... | 05/29/08
RE: The Storm Worm would love to infect you  naomiquinones@... | 07/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline