Sunday, December 31, 2006

Several Millions 'Happy New Year' worms spammed!

At this time, I have received tons of reports of people having seen variants of the email containing the postcard.exe attachment as previously reported. Some AV vendors call it W32/Nuwar@mm . I even received a video from a reader Didier Stevens trying to look at it here (a YouTube Video).
The variants may be changing the subject lines, but are definitely changing the executable name. Reported name variants are "greeting card.exe", "greeting postcard.exe" and "GreetingCard.exe". A list of lines and variants were provided by some readers and vendors. This is a good start, but most likely partial: Annual Fun Forecast! Baby New Year! Best Wishes For A Happy New Year! Fun 2007! Fun Filled New Year! Happiness And Continued Success! Happiness And Success! Happiness In Everything! Happy 2007! Happy New Year! Happy Times And Happy Memories! May Your Dreams Come True! New Hopes And New Beginnings! New Year... Happy Year! Promises Of Happy Times! Raising A Toast To Happy Times! Scale Greater Heights! Sparkling Happiness And Good Times! Warm New Year Hug! Warmest Wishes For New Year! Welcome 2007! Wish You Smiles And Good Cheer! Wishing You Happiness! Wishing You Happy New Year!
Some of the variants are even not detected yet if you are using the normal update procedure from several AV vendors... I hope you will not be infected next year with any of these ... A Real Happy New Year from me to all of you!

PS: At this moment the spamming of Tibs/Nuwar/Luder just suddenly stopped. The question is for how long.