<<<
NEWS FROM THE LAB - Thursday, October 19, 2006
>>>
 

 
The Warezov worm saga continues Posted by Gerald @ 03:37 GMT

Today we received several reports of new a Warezov variant - Warezov.DC - that we detect with Database 2006-10-19_02.

Like the previous variants, it mass-mails a copy of itself and then attempts to download files from the following links:

    www4.vedasetionkderun.com/chr/819/n[removed].exe
    www4.vedasetionkderun.com/chr/819/l[removed].exe
    www6.vedasetionkderun.com/chr/819/n[removed].exe
    www6.vedasetionkderun.com/chr/819/l[removed].exe
    www5.vedasetionkderun.com/chr/819/s[removed].exe

Right now, it is still quiet and slow. We'll see if this will spread furiously like the previous variants.

Updated to Add: This Warezov variant was very active today. Read more details about it here.