Symantec Blogs: Security ResponseSyndicate content

Nicolas Falliere | September 13th, 2007
0 comments

Peacomm samples - the so-called Storm worm- started sending unusual spam yesterday. For once, the mail did notcontain a hard-coded IP address linking to fake videos, pseudo Torclients or NFL "tracker programs". The spam advertises a website,http://www.vs-amounts.net:

From: xxx@yyy.com
To: victim@domain.com
Subject: Cold Hard Cash!

Seeking highly motivated individuals interested in a unique opportunity in financial services.

Building an exciting career where you determine your own hours and compensations.

http://www.vs-amounts.net/

Hmm. Already this looksvery suspicious, but let's check that link anyway. The site hostsphpbb, a popular open-source PHP-based Bulletin Board, and opensdirectly to the following announcement message:

OK...