Monday, October 22, 2007

Nuwar/Storm Worm update!

The gang behind Storm Worm (a.k.a eCard worm) has once again changed their social engineering tactics and also file names. Now, we get a "Psycho Kitty Card" (whatever that means!) instead of plain old eCards:

When we click on the link, we are presented with a fake web page as usual. Along with this, it plays music too!

And in this iteration of Storm Worm, the drive-by-download is back. The PC will be infected with a variant of Tibs Rootkit just by visiting the page. No need to download or click on anything. Now rootkit files are named as noskrnl.exe, noskrnl.sys and noskrnl.config instead of spooldr.exe, spooldr.sys and spooldr.ini,which were prevalent in older versions. Here are some screenshots showing hidden process, SSDT hooks of the rootkit:


Detections for this Storm Worm variant are pretty good. However, to be on the safer side, delete any of the "Psycho Kitty Card" mails that you might have received!

0 Comments:

Post a Comment

<< Home