Shortly after 0000 GMT 24-DEC-2007 reports came in indicating that the Storm Botnet was sending out another wave of attempts to enlist new members. This version is a Christmas-themed stripshow directing victims to merrychristmasdude.com.
The message comes in with a number of subjects:
Subject: I love this Carol!
The body is something similar to:
do you have a min?
[the domain was interrupted for your protection]
Thanks Kevin for the initial report.
I recommend that you apply blocks on that domain (merrychristmasdude.com) for both outbound HTTP requests and incoming emails.
Kevin Liston (kliston -at- isc.sans.org)
Dec 24th 2007
1 decade ago