Merry Christmas Storm!
Monday, December 24. 2007
Consistent with previous spam runs, the authors of Storm Worm now also adopted the propagation scheme to the upcoming Christmas holidays. The spam mails contain for example the following text:
"This Christmas, we want to show you something you will really enjoy. This might not be fun for the whole family, but I bet you'll like it come one take 2 min and check it out. hxxp:// merrychristmasdude . com/"
Please note: Do not visit this site since it contains several exploit for web browser or common browser plugins.
The website shows "Mrs Clause" and some naughty pictures. The malware binary has the name stripshow.exe and - as usual - the MD5 sum changes every couple of minutes. Quick sandboxing shows that the behavior of the binary is similar to previous versions of Storm. The domain merrychristmasdude.com uses fast-flux: repeated DNS lookups always return different A records for this domain. Thus it seems like there is nothing really new - only the theme used for the propagation mails has changed...
"This Christmas, we want to show you something you will really enjoy. This might not be fun for the whole family, but I bet you'll like it come one take 2 min and check it out. hxxp:// merrychristmasdude . com/"
Please note: Do not visit this site since it contains several exploit for web browser or common browser plugins.
The website shows "Mrs Clause" and some naughty pictures. The malware binary has the name stripshow.exe and - as usual - the MD5 sum changes every couple of minutes. Quick sandboxing shows that the behavior of the binary is similar to previous versions of Storm. The domain merrychristmasdude.com uses fast-flux: repeated DNS lookups always return different A records for this domain. Thus it seems like there is nothing really new - only the theme used for the propagation mails has changed...



