Home > Insights > Blogs 

CA Community

This Blog

Malicious Waledac for Your Sweetheart

Published: February 09 2009, 09:07 PM
by Mary Grace Gabriel

We received some new spam emails from Win32/Waledac:

Example spam email sent by Win32/Waledac.AJ 

Example spam email sent by Win32/Waledac.AJ 

http://community.ca.com/blogs/securityadvisor/Grace/waledacaj_email3.gif 

Spam emails could have the following subject lines:

  • <sender name> has sent you a Valentine’s Day E-Card!
  • A Valentine’s Day E-Card from <sender name>
  • Greetings from <sender name>

Clicking on the link leads the user to a seemingly cuddly website like this one:

Adorable dogs misused as bait for Win32/Waledac to spread its malicious executable 

Looking at the website’s source code, we can see that clicking on the image runs an executable:

Source of website indicates the image is linked to the trojan executable 

Currently, the trojan executables are being delivered from these websites:

adorelyric.com
adorepoem.com
adoresong.com
adoresongs.com
bestadore.com
bestlovehelp.com
bestlovelong.com
chatloveonline.com
cherishletter.com
cherishpoems.com
funloveonline.com
lovecentralonline.com
lovelifeportal.com
orldlovelife.com
romanticsloving.com
whocherish.com
worldlovelife.com
worshiplove.com
youradore.com
yourdatabank.com
yourgreatlove.com
yourteamdoc.com

with the following filenames:

Card.exe
cardviewer.exe
devkit.exe
download.exe
ecard.exe
install.exe
lovecard.exe
lovekit.exe
Loveu.exe
Luv.exe
Programm.exe
vcard.exe
viewer.exe

CA detects these files as Win32/Waledac.AJ.

Once running, Waledac may also download a file that appears to be a harmless .JPG (pictured below), but actually comes embedded with a malicious executable that we detect as a Win32/SillyDl trojan.

 Win32/Waledac.AJ can download a .JPG file embedded with a malware executable

For more information on Win32/Waledac.AJ, please see the full analysis in our encyclopedia:
http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77663 

And remember to keep away from these websites, in addition to always updating your security product’s signatures.

Till next time!

Thanks to Meths Ferrer and Zarestel Ferrer for their assistance.

Share this post:  EmailEmail

By: Mary Grace Gabriel
Mary Grace Gabriel is a Research Engineer with CA's Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, Mary's career in computer security started at Trend Micro as an Anti-virus Engineer, and she also worked as Senior Malware Analyst at Anchiva Systems. She...
Read More..

3 people have left comments:

The romantic trojan we’ve been following, Win32/Waledac, did not miss its opportunity to use Valentine

Posted by: CA Security Advisor Research Blog | February 17, 2009 1:03 AM

One more to add to that list.

Our company received spam linking to linkworldnews.com

which had a click here linking to luvu.exe

It also had an iframe in the page that loaded chatloveonline.com which was hidden.

Valentine's Day Cards, Free Valentine's Day eCards, Greeting Cards

Posted by: Nathan | February 17, 2009 1:56 PM

 
 
Page Tools