NEWS FROM THE LAB - Thursday, April 19, 2007

Warezov Back in Action? Posted by Francis @ 05:42 GMT

It's been awhile since the last attack of the Warezov gang. But it seems now they're back in action.

Here's a sample screenshot of the e-mail of the new Warezov that is being spammed:

Warezov.NF E-mail

The zip file attachment contains an executable file that uses a text file icon as a decoy:

Warezov.NF Attachment

Once the malware has executed, it will pop-up the following message box:

Warezov.NF Error

This executable file is a downloader for its other components. The link is encrypted with a simple XOR.

Warezov.NF Download

For system administrators, you may want block network traffic from the following malicious link:


Our detection for this variant is Email-Worm:W32/Warezov.NF and it is included since database update 2007-04-19_02.