Friday, April 13, 2007

Another W32/Nuwar or Zhelatin variant on the loose!

Yesterday and today, several e-mails with love themed subjects were seen in the wild. While some of the subjects are a rehash of previously used subjects such as Sending You My Love, The Dance of Love, and When I'm With You, others are new:
A Dream is a Wish, A Is For Attitude, Eternal Love, Kisses Through E-mail, etc ....
The e-mail messages themselves have no text, instead, they have attached executables with romantic sounding filenames. These included:
Love Card.exe Love Postcard.exe Greeting Card.exe Postcard.exe
All files are detected as a Win32.Zhelatin or W32/Nuwar variant depending on the product you use.
A second run occurred after several hours.
This time, the subjects were security related.
Subjects included:
ATTN! Spyware Alert! Virus Alert! Worm Alert! Worm Detected!
Furthermore, the message body is an image file which advises the receiver to patch their systems. Also included within the image is a password in order to extract the attachment.
The filenames vary but they have the following format:
patch-xxxxx.zip hotfix-xxxxx.zip removal-xxxxx.zip bugfix-xxxxx.zip
The executable contained within the Zip archive has the same name as that of the archive but with an EXE extension.
Please update ASAP as I have seen some products missing some of these variants.