Following is part of a spam email sent by the storm worm:
Subject: A Valentine card for you!
From: “Neddie”
Date: Sat, February 14, 2009 5:36 am
Neddie wants to show you an electronic greeting card and wrote to you:
“I Just Called To Say I Love You”
It is waiting for you at our card site, go ahead and see it:
http://oehee.valentinesupersite.com/?cardid=a36c434555dc7c289e165ea050
The greeting card will be stored for you for 14 days.
- HKLM\software\Microsoft\Windows\CurrentVersion\Run:promoreg=[location of the malware]
- HKCU\software\Microsoft\Windows\CurrentVersion:MyID
Because the variants are previously unseen, most of the signature-based Anti-Virus products were not able to detect the worm as of Febuary 16th, 2009 –two days after the new variants were released (see Picture 1). This underscores the difficulty traditional signature-based AV vendors have to face:

As we can see, a large majority of the Anti-Virus products were not able to detect this new storm worm variants more than 48 hours after the initial worm was reported in the wild.
0 comments:
Post a Comment