Stration worm targets Windows machines

Article

Stration worm targets Windows machines

Bill Brenner, Senior News Writer

Antivirus vendors are warning customers to avoid unsolicited email attachments as another worm takes aim at Windows machines. Some vendors have named the worm Stration, while others are calling it Warezov.

UK-based Sophos said in an advisory

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

that W32.Stration-AN has been "aggressively distributed" by its author since early Monday morning. It travels by email using a variety of fake messages, one of which is an infection warning with the following characteristics:

Subject line: Mail server report.

Message text: "Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support service."

Attached file: Update-KB7859-x86.zip [which contains the file Update-KB7859-x86.exe]

Sophos Senior Technology Consultant Graham Cluley said the worm was "being seen widely" at email gateways Monday morning. "Anyone accessing their email has to learn to resist the temptation of opening unsolicited attachments, and ensure their anti-virus protection is kept fully up-to-date," he said in a statement.

Cluley said the worm may be using the fake security warning to exploit fears over the Internet Explorer VML flaw, which has been the target of multiple attacks in recent days.

"Many Windows users are waiting anxiously for Microsoft to fix the VML flaw in its code, which has been exploited by hackers online," Cluley said. "It's possible that the people behind the Stration worm are playing on the Internet community's heightened concern while they are left unprotected by Microsoft, and may be able to fool innocent users into rushing into running the malicious update."

The lesson, he said, is that users should only expect security updates to come via the vendor's official Web site, not as unsolicited email attachments.

Russian antivirus firm Kaspersky Lab is calling the worm Warezov-AT and labeled it a severe risk in its advisory because it is "spreading rapidly."

"The worm sends itself to addresses harvested from the MS Windows address books," Kaspersky Lab said. "The worm uses its own SMTP library to send infected messages."

Cluley and Mikko Hypponen, chief research officer for Helsinki, Finland-based F-Secure Corp., confirmed by email Monday that Stration and Warezov is the same worm. Like Kaspersky Lab, F-Secure is calling it Warezov.