Owner of the BFT
Commenting To 
12th-Apr-2007 11:46 am - New worm
Serve
So there is a new virus/worm going around. It's an email that says you've gotten a virus or worm, and to encourage you to open a ZIP file that says it's a patch.

Please, do yourself a favor, and don't open that file.

Trend Micro: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=worm_nuwar.aok

SANS info:
We've received a bunch of emails in the past few minutes indicating the possible presence of a new Worm.

We are being told that it is a "Nuwar/Zhelatin" virus with Virtual Machine detection capabilities.

Apparently it indicates itself as a "Patch" for the "New worm" that is going around (whatever that may be, there are just so many I could choose from!)

The Subject of the email (that we have seen so far) say:
"Worm Alert!"
"Worm Detected"
"Virus Alert"
"ATTN!"
"Trojan Detected!"
"Worm Activity Detected!"
"Spyware Detected!"
"Dream of You"
"Virus Activity Detected!"

It has two attachments, one being an image with 'panic-worded text', and the other is a password protected zip file, whose password is revealed in the image.

The zip file appears to be named "patch-.zip".
Comment Form 
From:
(will be screened)
Help(will be screened)
Identity URL: 
Username:
Password:
Don't have an account? Create one now.
Subject:
No HTML allowed in subject
   Help
Message:

 
Notice! This user has turned on the option that logs your IP address when posting. Help
This page was loaded Jan 7th 2010, 8:02 am GMT.