Storm Worm-Trojan targets blogs, bulletin boards and webmail
February 28, 2007 Leave a Comment
A variant of the Storm Worm-Trojan, very active in January 2007 during a European storm, installs a component on the local computer that analyzes all network traffic via a layered service provider (LSP) integration and modifies blog postings and comments and webmail-based emails. The posting will include a link to the malicious code and make attepts to propagate itself to other potential victims.
The Storm Worm-Trojan variant is discovered on a web site but can be distributed by other media. The signature-based anti-virus solutions have difficulties to detect and intercept this variant because the package for distribution is continuously being repackaged, a technique called server polymorphism.
