Home > Security News > Stration worm targets Windows machines
Security News:
EMAIL THIS

Stration worm targets Windows machines

By Bill Brenner, Senior News Writer
25 Sep 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Antivirus vendors are warning customers to avoid unsolicited email attachments as another worm takes aim at Windows machines. Some vendors have named the worm Stration, while others are calling it Warezov.

UK-based Sophos said in an advisory that W32.Stration-AN has been "aggressively distributed" by its author since early Monday morning. It travels by email using a variety of fake messages, one of which is an infection warning with the following characteristics:

Subject line: Mail server report.

Message text: "Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support service."

Attached file: Update-KB7859-x86.zip [which contains the file Update-KB7859-x86.exe]

Sophos Senior Technology Consultant Graham Cluley said the worm was "being seen widely" at email gateways Monday morning. "Anyone accessing their email has to learn to resist the temptation of opening unsolicited attachments, and ensure their anti-virus protection is kept fully up-to-date," he said in a statement.

Cluley said the worm may be using the fake security warning to exploit fears over the Internet Explorer VML flaw, which has been the target of multiple attacks in recent days.

"Many Windows users are waiting anxiously for Microsoft to fix the VML flaw in its code, which has been exploited by hackers online," Cluley said. "It's possible that the people behind the Stration worm are playing on the Internet community's heightened concern while they are left unprotected by Microsoft, and may be able to fool innocent users into rushing into running the malicious update."

The lesson, he said, is that users should only expect security updates to come via the vendor's official Web site, not as unsolicited email attachments.

Russian antivirus firm Kaspersky Lab is calling the worm Warezov-AT and labeled it a severe risk in its advisory because it is "spreading rapidly."

"The worm sends itself to addresses harvested from the MS Windows address books," Kaspersky Lab said. "The worm uses its own SMTP library to send infected messages."

Cluley and Mikko Hypponen, chief research officer for Helsinki, Finland-based F-Secure Corp., confirmed by email Monday that Stration and Warezov is the same worm. Like Kaspersky Lab, F-Secure is calling it Warezov.

Tags: Malware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Malware, Viruses, Trojans and Spyware
ISP shutdown latest cat-and-mouse game with hackers
How to get rid of malware, botnets on a hospital IT network
How can search results lead to malware?
Should a national cybersecurity strategy include offensive botnets?
How to prevent mobile phone spying
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Zotob  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts