Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Worm War II: NUWAR vs. STRATION?

    Here’s an interesting update regarding the “storm malware” (a.k.a. TROJ_SMALL.EDW and WORM_NUWAR.CQ — I really can’t tell the difference anymore, considering they work together): they’re attacking STRATION.

    In an analysis by Joe Stewart of SecureWorks, it was found out that the P2P botnet created by TROJ_SMALL.EDW has a distributed denial of service (DDoS) functionality that targets specific IP addresses. Among the said addresses are related to the following domains known to be used by certain STRATION variants:

    • adesuikintandefunhandesun.com
    • esunhuitionkdefunhsadwa.com
    • huirefunkionmdesa.com
    • krovalidajop.com
    • shionkertunhedanse.com
    • traferreg.com

    A more detailed analysis can be found here.

    The last time a “worm war” took place (it was NETSKY vs. BAGLE, if my memory serves me right), the “collateral damage” — i.e., customer infections/outbreaks, which also translate to monetary losses — was high. Is history repeating itself? Let’s hope not.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice