Beware bogus Christmas greeting emails
Beware bogus Christmas greeting emails
R E L A T E D   C O N T E N T
ADVERTISEMENT

Christmas card virus hits one in 10 emails

Zafi-D spreading rapidly around the world

Robert Jaques, vnunet.com 16 Dec 2004
ADVERTISEMENT

The Zafi-D worm (W32/Zafi-D), discovered earlier this week posing as a Christmas greeting, is spreading rapidly around the world.

IT security experts have reported that the virus is currently accounting for around three-quarters of all virus reports, with some estimates suggesting that the infection is present in as many as one in 10 emails.

Zafi-D, which is believed to originate from Hungary, spreads inside bogus Christmas greeting emails. The emails can use a variety of languages including English, French, Spanish and Hungarian.

Embedded inside the email is a lewd animated GIF graphic of two 'smiley' faces, which may fool some users into believing that the attached virus is a joke.

"More than one in 10 emails travelling across the internet at the moment is infected with Zafi-D," warned Graham Cluley, senior technology consultant for Sophos.

"Although antivirus protection is available, there must be many home users who have been complacent and are allowing their PCs to belch out more and more infected emails.

"Everyone should consider putting in place automatic antivirus updates, and a policy of blocking dangerous attachments at the email gateway."

Zafi-D attempts to disable antivirus and firewall protection software on infected computers. The worm also tries to open a backdoor on affected PCs, and to download further malicious code from the internet.

"The danger is that infected PCs could come under the control of remote hackers [who] could use the infected PCs to do whatever they want: destroy data, steal information or launch spam campaigns and distributed denial-of-service attacks," said Cluley.

"Computer users who are not properly protected would be completely oblivious to what was happening under their noses."

The festive virus attacks are not confined to Zafi-D, according to PandaLabs. The company has detected the appearance of variants H, I and J of the Atak worm, which also spread in messages that pass themselves off as Christmas greetings.

The newly intercepted variants of the Atak worm are very similar to each other, differing only in aspects like the size of the file attached to infected email messages. However, due to a programming error, Atak.J cannot send itself out.

The Atak mutants reach computers in email messages with the subject 'Merry X-Mas!' or 'Happy New Year!'. The message text reads: 'Happy New year and wish you good luck on next year!' or 'Mery Chrismas & Happy New Year! 2005 will be the beginning!'

The attachment is always compressed as a zip file and contains a file that could be called bat, com, pif or scr. If the user runs this file, the worms create copies of themselves in the Windows system directory under the name 'dec25.exe'.

At the same time, they use their own SMTP engine to send themselves to all the addresses they find in files with certain extensions stored on the affected computer.

"We are witnessing an attempt to saturate users' inboxes with a huge number of virus-infected Christmas greetings. We don't know if it is organised or not," said Luis Corrons, head of PandaLabs.

"This is obviously a significant threat to computers that are not properly protected, as the probability of being hit is very high, especially considering that, at this time of the year, it is not unusual to receive a large amount of emails of this kind."

Information on the above viruses, including removal tools, can be downloaded from Panda Software here, and from Sophos here.

See also:

Top 10 viruses and hoaxes in JanuaryMass-mailer refuses to go away during relatively quiet month  01 Feb 2005
Virus carried spam Trojan16 year-old Brit receives six-month suspended sentence for Randex worm  21 Dec 2004
Dave MartinEmployees are the biggest threat to security, especially at Christmas  16 Dec 2004
Nothing festive about this Zafi D variantWhere's the early bird when you need it?  14 Dec 2004
Promise of nude pics carries nasty surpriseGlamour model virus launches DoS attack against Chechen rebel websites  10 Dec 2004
Criminal gangs now using professional programmersLock up your bank accounts  07 Dec 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities