Welcome to the SecAware blog

I spy with my beady eye ...

22 Aug 2007

Malware spam spewed forth

Click for a larger image
We've received loads of similar malware spams today, all basically the same structure with minor differences and spelling mistakes (see above).

The links vary but we understand that one (at least) attempts to infect visitors' PCs with a downloader Trojan. Good up to date antivirus software should trap it but do not rely on this as your sole control: it is not recognized by all antivirus programs.

A quick search of my spam/deleted box for emails containing the string "account number" reveals a whole bunch of em received so far today.

Senders include
Bartenders Guide
Cat Lovers
Cool Pics
Dog Lovers
Downloader Heaven
Entertaining Pros
Free Web Tools
Fun World
Funny Files
Game Connect
Internet Dating
Job Search Pros
Mobile Fun
MP3 World
Net Gambler
Office Antics
Online Gamers
Online Hook-Up
Poker World
Pet World
Resume Hunters
Ringtone World
Web Connects
Web Cooking
Wine Lovers

Subject lines include
Dated confirmation
Internal Support
Internal Verification
Internet Techincal Support [sic]
Login info
Login information
Login Verification
Member Confirm
Member Details
Membership Details
Membership support
New member confirmation
New User Details
New User Letter
New User Support
Registration confirmation
Registration Details
Tech Department
Thank you for joining
User Info
User services
User Verification
Welcome new member

There are other variants in circulation too.

The spams are believed to be the result of a new mutant of the Storm worm that has been very active for weeks. SANS Internet Storm Centre has some technical info on it and there's more on F-Secure's blog.

The usual advice "Don't click on dubious links" applies here. Now might be a good time for your security awareness person to inform your fellow employees in calm, helpful tones about the threat. PLEASE do not add to the problem by circulating wild warning emails with "Please tell everyone you know!" or similar - leave the job to the professionals and the news media. Oh and don't forget to check that your antivirus software is updating itself regularly.

*UPDATE* Download a security awareness 'alert' about this, suitable for circulating to your fellow employees. NoticeBored customers: please contact us for the editable MS Word version.

No comments:

Post a Comment