Spammers use YouTube to spread Storm worm

By Liam Tung, ZDNet Australia
27 August 2007 01:49 PM
Tags: storm, security, worm, f-secure, youtube, site, spam, trick

In yet another twist to the Storm worm menace, spammers are using a fake YouTube site to trick users into downloading malicious code which could turn their PCs into bots.

In line with the trend for virus writers to use Web sites hosting malicious code to infect vulnerable PCs, the latest effort to spread the Storm worm attempts to hijack the YouTube name to cause infections. Using a site which carries YouTube branding, those behind the attack hope to capitalise on the popularity of the video sharing Web site to trick unwary users.

Those who fall for the trick are directed to a site which includes a link to a downloadable video file carrying the Storm worm.

Using typical social engineering techniques, an e-mail containing a link to the fake YouTube site is distributed as spam, with the message: "Man you have got to tell me where you picked her up. I saw this on the web. It has to be you. Check it out yourself at..."

F-Secure's chief research officer, Mikko Hypponen, has been monitoring the so-called Storm/Zhelatin Gang thought to be behind the worm. He recently created an online video showing how the gang uses different exploits created for vulnerabilities unique to various browsers -- depending on the browser being employed, different files are sent to the user's PC.

The Storm worm was first reported in January , delivered via an executable e-mail attachment disguised as an e-greeting card. In recent months, however, spammers have changed their approach by attempting to trick users into clicking on links directing them to malware-infected sites.

Managed security vendor SecureWorks recently speculated the massive rise in occurrences of the Storm worm could be the precursor to a DoS attack on government or corporate Web sites.

Advertisement

Talkback 3 comments

    where is the fake site? ewok Chubacca -- 27/08/07

    Where is the fake site would like to have a look at it & see what the worm looks like

    Possible FAKE site. (WARNING!!) Rusty M. -- 28/08/07 (in reply to #320085094)

    http://68.51.135.63/ is MOST LIKELY one of these fake sites. I have been receiving these in the spam section of my online email service. The message is written to look like a link to YouTube, HOWEVER, when I run my cursor over the site name, the URL which posts in the bottom section of my screen is the above http: 68.51.135.63/ I NEVER trust sites that I am not familiar with.

    looks like you're right Anonymous -- 28/08/07 (in reply to #320085127)

    A simple page stating that your download will start in 15 seconds, or "click here" to start it immediately.

    Downloads "video.exe" to your computer. When opened in a hex editor, the first line is "This program cannot be run in DOS mode.

    Appears to be some poor script kiddies work.

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured