RSS feed of Security Labs Alerts from M86 Security

YouTube Storm Again

 

August 31, 2007

Today, the Storm Trojan spam has morphed back to its YouTube video theme, continuing a trend of almost daily changes. The subject and content is a purported YouTube video. 

 

 

The subect lines are numerous and use outrageous and fun themes.  Here are some sample subjects:

are you kidding me? lol
Dude dont send that stuff to my home email...
Dude your gonna get caught, lol
HAHAHAHAHAHA, man your insane!
I cant belive you did this
LMAO, your crazy man
LOL, dude what are you doing
man, who filmed this thing?
oh man your nutz
OMG, what are you thinking


Like last time, the body of the message is HTML and supposedly containing a link to a YouTube video.  In fact, the actual link in the HTML contains the an IP address leading off to a website that contains an official-looking YouTube image. 

 

 

However, the website contains malicous code which may exploit vulnerabilities in your browser, or prompt you to download malicious files.  In this case the file is called 'video.exe'.


As before, be wary of clicking on links in any unsolicited email, and in light of these recent storm messages, be doubly suspicious of any links with an IP address.

MailMarshal customers should note the current SpamCensor is detecting these messages as spam and no further action is necessary.


Last Reviewed: September 4, 2007