Storm Worm-Trojan targets blogs, bulletin boards and webmail

A variant of the Storm Worm-Trojan, very active in January 2007 during a European storm, installs a component on the local computer that analyzes all network traffic via a layered service provider (LSP) integration and modifies blog postings and comments and webmail-based emails. The posting will include a link to the malicious code and make attepts to propagate itself to other potential victims.

The Storm Worm-Trojan variant is discovered on a web site but can be distributed by other media. The signature-based anti-virus solutions have difficulties to detect and intercept this variant because the package for distribution is continuously being repackaged, a technique called server polymorphism.

30% more spam since last week

MX Lab and many other anti spam service providers noticed an new increase of 30% more spam since last week. Most of this spam is send from the Asia region, more likely from China and South Korea. Sources indicate that a new botnet is currently active in Asia which is responsible for this peak.

Follow

Get every new post delivered to your Inbox.

Join 109 other followers