New Valentine Scam on the Loose
Monday February 9, 2009 at 8:09 am CST
Posted by Micha Pekrul
Following our warning, last week, of the possible scams related to the approaching Valentine’s Day, it’s no surprise that today we’ve seen another new Valentine theme come up–hosted on the fast-fluxing Waledac botnet. If a user were to follow the link in these spam emails–and please don’t do that!–a web site like the following would appear:

A picture with two adorable Shih Tzu puppies is wishing a Happy Valentine’s Day. The text of the lure is advertizing a “Valentine Devkit” named loveexe.exe or start.exe. And regular readers can guess it already: This is a social-engineering trick to convince users to download the real threat. Don’t click the link to the executable or you will end up with malware.

A close look into the website’s source code doesn’t currently reveal any additional drive-by infections nor downloads (but that can change quickly), as seen in past Waledac (or “Storm”) themes. Coverage of this particular malware variant is in the 5522 DATs, plus blocked by Artemis, plus blocked at the (former Secure) Web Gateway as well.

February 11th, 2009 at 08:00
[...] New Valenine related Scamshttp://www.avertlabs.com/research/blog/index.php/2009/02/09/new-valentine-scam-on-the-loose/http://blog.trendmicro.com/itunes-invoices-and-valentines-ads-conceal-pharma-spam/http://blogs.pcmag.com/securitywatch/2009/02/if_i_gave_you_a_virus_for_vale.php [...]
February 12th, 2009 at 21:31
[...] Valentine’s Day approaches, further warnings of holiday-themed virus attacks continue. McAfee is warning of a “cute puppy” lure to download malware connected to the Waledac botnet (click the [...]
February 19th, 2009 at 07:28
While doing a Google search on this, I came across this site that ran a scan on my PC and proceded to try an install itself.
the link is; 2009021914.baeeeh.bee.pl/waledac_botnet.html
Can anyone explain this link. Thank you for your time.
February 23rd, 2009 at 08:46
[...] the Valentine’s theme, the malware authors behind the Waledac botnet changed their lure to promote free coupons, [...]
December 12th, 2009 at 04:09
[...] the Valentine’s theme, the malware authors behind the Waledac botnet changed their lure to promote free coupons, [...]