December 26, 2007
Storm Worm Continues Mutating for Holidays
The Storm worm, which has been plaguing PC users for much of 2007, is not going down without a fight.
The Storm worm, a trojan that has been luring PC users into the Storm botnet for much of 2007, has been resurgent this holiday season. Since Monday, the worm has been sending Christmas-themed spam designed to lure new victims into downloading the malicious executable from MerryChristmasdude dot com (address mangled for safety).
In just the last day, the worm has switched to sending New Year's-themed spam. The worm has been using some sophisticated techniques to avoid detection and thwart anti-virus efforts. It has been repacking itself every few minutes to fool signature-based anti-virus software. The New Year's spam is now directing users' systems to download malicious code from Uhavepostcard dot com, a site kept viable by a fast-flux DNS technique that hides it behind an ever-changing series of proxy machines.
For more information, see Symantec.com and the Internet Storm Center.