Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > NUWAR in labor

    Sep4
    5:35 am (UTC-7)   |    by

    NUWAR has spawned yet another variant last Labor Day when email messages purporting to be eCards related to the said holiday circulated. TrendLabs has received samples that have such subjects as “A Labor Day E-Card” or “The Big Labor Day Weekend.”

    The tactic is still the same: a link to the supposed eCard is given, and unsuspecting users who click on the link are redirected to a Web page that displays the following image:

    labor.jpg

    Once the image is clicked, a NUWAR variant detected as WORM_NUWAR.AQK is downloaded onto affected machines. Adding insult to injury is TROJ_TIBS.ANF, which, upon accessing the said page, is downloaded automatically via certain browser vulnerabilities. Both malware are already detected by Trend Micro with the latest pattern file.

    It’s interesting to note that after recent makeovers, the NUWAR/ZHELATIN/Storm family has undergone in the past weeks — from BETA testing software to YouTube — it went back to sending eCard greetings. Then again, given the “success” of the 4th of July greetings a couple of months ago, it looks like it’s banking on the idea that holidays and celebrations in general are tantamount to lax security and increased user gullibility. Which is, admittedly, usally the case…

    Data and initial analysis provided by Robert McArdle of TrendLabs EMEA





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice