sudosecure.net

              is anything truly secure…

Storm revists love theme and postcard.exe

Posted by jeremy on July 24th, 2008

I guess the Amero and the Domain Name outages just weren’t working out for the Storm Authors, as they have shifted back to an old theme. The message is simple:

You’ve got an animated postcard from someone who loves you.
Click here to save the postcard.

Nothing new here as they have played the “love” theme before. The “ind.php” javascript obfusticated exploit serving file is still included as an iframe redirect, so be-aware of this. My only major concern with this new/revisited campaign is the new binary has a very little Antivirus Vendor detection rate: Result: 8/35 (22.86%). I have not seen any new domain names or spam associated with this change, but my guess is tonight when I take a deeper look at it in the lab I will be greeted with these changes.

  • Share/Bookmark

3 Responses to “Storm revists love theme and postcard.exe”

  1. New Storm Campaign and Domains | BjOG - Bjou's Blog, that is! Says:

    [...] Now I am not a tracker of storm campaigns nor binaries, I am just a casual binary analyst, but today while running a storm gateway for research purposes, I found some new domains going along with the revisited love theme and its postcard.exe. [...]

  2. bjou Says:

    There’s new domains now. Waiting for insight into the spam messages :)
    http://bjou.homeunix.net/blog/2008/08/new-storm-campaign-and-domains/

  3. jeremy Says:

    Thanks for the info… I will capture the spam tonight in the lab to follow up. Thanks again.

    –jeremy

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>