ESET Threat Blog

Archive for the 'Storm' Category

  •  
by David Harley Senior Research Fellow
November 23, 2011 at 11:50 am

Old hoaxes never die. They just get transplanted to Facebook. Sometimes literally, when a classic email hoax starts to spread with minor emendations through Facebook message or news feeds. In this case, the actual message (at least, as I received it) is still email, but it's been adapted to appeal to the more than 800 million Facebook … Read More…

Comments
0

?>
by Robert Lipovsky Malware Researcher
April 21, 2011 at 12:30 am

One of the most common ways to propagate malware through social engineering is to piggyback it on some attention-catching news event. This can be carried out using a variety of techniques and is certainly nothing new. One infamous example from 2007 was Win32/Nuwar (a/k/a the Storm Worm), which distributed through spam emails with current and/or … Read More…

Comments
1

?>
by David Harley Senior Research Fellow
December 31, 2010 at 12:55 pm

Pierre-Marc tells me that he has received two malware samples that grabbed his attention due to their resemblance to Storm/Waledac.  They use the same kind of distribution mechanism: that is, spam with links to a New Year eCard for New year with titles like "New Year Wishes!" and "You Received an Ecard."  The mail contains … Read More…

Comments
0

?>
by Pierre-Marc Bureau Senior Malware Researcher
February 11, 2009 at 9:56 am

As Valentine’s Day is approaching the criminals behind Win32/Waledac have increased their activity. The Valentine campaign started some time ago but the interesting part is only starting for us.  The Waledac botnet has been using fast flux for some time now.  This means that the IP addresses of the websites used to distribute this malware … Read More…

Comments
0

?>
by David Harley Senior Research Fellow
December 31, 2008 at 1:08 pm

Further to Pierre-Marc’s post on the 25th December about the resemblances between Waledac and Storm, I notice that Steven Adair of Shadowserver has been blogging some very nice notes on much the same topic. Well worth a look.
David Harley
jQuery(document).ready(function($) { window.setTimeout(‘loadLinkedin_321()’,1000);window.setTimeout(‘loadFBLike_321()’,1000);window.setTimeout(‘loadGoogle1_321()’,1000);window.setTimeout(‘loadGBuzz_321()’,1000);window.setTimeout(‘loadTwitter_321()’,1000); }); function loadLinkedin_321(){ jQuery(document).ready(function($) { $(‘.dd-linkedin-321′).remove();$.getScript(‘http://platform.linkedin.com/in.js’); }); } function loadFBLike_321(){ jQuery(document).ready(function($) { … Read More…

Comments
0

?>
by Pierre-Marc Bureau Senior Malware Researcher
January 1, 2009 at 9:35 am

Yesterday, we started to receive reports of emails pretending to carry links to holiday cards.  These emails contain a link that points to a file named ecard.exe.  Of course, this executable is not a seasonal holiday card but malware.  The reason this wave of malware has attracted our attention is that it is very similar … Read More…

Comments
3

?>
Share |
Subscribe by Email
To receive new posts automatically through email, enter your email address:

Delivered by FeedBurner

Blog Search
Archives

Switch to our mobile site